by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors CVE-2025-31877 is a Medium-severity authorization issue (CVSS 4.3) affecting the RestroPress – Online Food Ordering System WordPress plugin (slug: restropress) in versions up to and including 3.2.8. The vulnerability can be exploited remotely over the...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors RestroPress – Online Food Ordering System (WordPress plugin slug: restropress) is affected by a Medium-severity reflected cross-site scripting (XSS) issue (CVSS 6.1, CVE-2025-32553) in versions up to and including 3.2.8.6. This type of attack is...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors Kraken.io Image Optimizer (slug: kraken-image-optimizer) has a Medium-severity vulnerability (CVSS 6.5, CVE-2023-0619) that can be triggered over the network by a logged-in user. The key exposure is that any authenticated account with Subscriber-level...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors CVE-2026-3878 is a Medium severity Stored Cross-Site Scripting (XSS) vulnerability (CVSS 6.4) affecting the WP Docs WordPress plugin (wp-docs) in versions 2.2.9 and below. The issue is exploitable by an authenticated user with Subscriber-level access or...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors The WP Shortcodes Plugin — Shortcodes Ultimate (slug: shortcodes-ultimate) vulnerability (CVE-2026-3885, Medium severity, CVSS 6.4) is exploitable by an authenticated WordPress user with Contributor-level access or higher. The attacker can abuse the...
by Ivan Sorkin | Apr 15, 2026 | Plugins
Attack Vectors CVE-2026-27046 affects StoreCustomizer – A plugin to Customize all WooCommerce Pages (slug: woocustomizer) in versions <= 2.6.3. This is a Medium severity issue (CVSS 4.3, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). The attack scenario...
Recent Comments