by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-25389 affects the WordPress plugin EventPrime – Events Calendar, Bookings and Tickets (slug: eventprime-event-calendar-management) in versions up to and including 4.2.8.3. Because this is an unauthenticated information exposure issue, an...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WooCommerce Wholesale Lead Capture Plugin for WooCommerce (slug: woocommerce-wholesale-lead-capture) has a Critical vulnerability (CVE-2026-27540) that can be exploited over the internet with no login required. The CVSS score is 9.8...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-27540 affects the Wholesale Lead Capture Plugin for WooCommerce (slug: woocommerce-wholesale-lead-capture) in versions <= 1.17.8. Because the issue is unauthenticated, an attacker does not need a login account to attempt exploitation over...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-27542 is a Critical vulnerability (CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) impacting the Wholesale Lead Capture Plugin for WooCommerce (WordPress plugin slug: woocommerce-wholesale-lead-capture) in versions <= 1.17.8....
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-27541 is a High-severity privilege escalation issue (CVSS 7.2; CVE record) affecting Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices (plugin slug: woocommerce-wholesale-prices) in versions up to and including 2.2.1....
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Conditional CAPTCHA (slug: wp-conditional-captcha) is affected by CVE-2026-1369, a Medium-severity open redirect vulnerability (CVSS 5.3; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). This issue is unauthenticated, meaning an attacker does not need a...
Recent Comments