Attack Vectors Profile Builder Pro versions before 3.14.0 are affected by a High-severity vulnerability (CVE-2026-27413, CVSS 7.5) that can be exploited without authentication. In practical terms, this means an external attacker can target a vulnerable website over...
Our Blog
Helping Businesses Run Better Websites — One Article at a Time
Contact Form by Supsystic Vulnerability (Medium) – CVE-2025-52753
Attack Vectors CVE-2025-52753 is a medium-severity (CVSS 6.1) reflected cross-site scripting (XSS) issue affecting the WordPress plugin Contact Form by Supsystic (slug: contact-form-by-supsystic) in versions up to and including 1.7.36. The attack is typically...
Capella | Restaurant WordPress Vulnerability (High) – CVE-2025-69370
Attack Vectors CVE-2025-69370 is a High-severity vulnerability (CVSS 8.1, vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) affecting the Capella | Restaurant WordPress theme (capella) in versions <= 2.5.5. The issue is unauthenticated, meaning an attacker does...
ArtPlacer Widget Vulnerability (Medium) – CVE-2026-24555
Attack Vectors CVE-2026-24555 is a Medium-severity Stored Cross-Site Scripting (XSS) issue affecting the ArtPlacer Widget WordPress plugin (slug: artplacer-widget) in versions up to and including 2.23.2. The vulnerability can be exploited by an authenticated user with...
BOX NOW Delivery Vulnerability (Medium) – CVE-2026-24571
Attack Vectors CVE-2026-24571 is a Medium-severity authorization issue (CVSS 4.3) affecting the BOX NOW Delivery WordPress plugin (box-now-delivery) in versions up to and including 3.0.2. The risk is triggered when an attacker already has a valid login (for example, a...
Notifications for Forms & WordPress Actions Vulnerability (Medium) …
Attack Vectors CVE-2025-68020 affects the WANotifier / Notifications for Forms & WordPress Actions plugin (slug: notifier) in versions up to and including 2.7.13. The issue is a missing authorization (capability) check, which means an attacker does not need an...
WPFore Subscribers