by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors MapSVG (WordPress plugin slug: mapsvg) is affected by CVE-2025-47558, a Medium-severity missing-authorization issue (CVSS 5.3). The vulnerability exists because a function lacks a required capability check in versions up to, but excluding, 8.6.13....
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-22335 is a Medium-severity (CVSS 6.5) SQL Injection vulnerability affecting WooCommerce Frontend Manager – Ultimate (slug: wc-frontend-manager-ultimate) in versions up to 6.7.7. The risk is not limited to anonymous visitors: an attacker needs...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-24553 is a Medium severity vulnerability (CVSS 4.3) affecting Fraud Prevention For WooCommerce and EDD (WordPress plugin slug: woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers) in versions up to and including 2.3.2. The issue...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WishList Member X (WordPress plugin slug: wishlist-member-x) is affected by CVE-2024-37111, a Medium severity issue (CVSS 5.3, vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) impacting all versions prior to 3.26.7. The risk is primarily exposure...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors The Nasa Core plugin (slug: nasa-core) is affected by a Medium-severity (CVSS 6.1) reflected cross-site scripting (XSS) vulnerability in versions below 6.4.4 (CVE-2025-39508). Reflected XSS typically relies on a victim being convinced to interact with a...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WishList Member X (wishlist-member-x) versions up to and including 3.25.1 have a critical vulnerability (CVSS 10.0) that can be exploited without a login. This means an external attacker can target your website directly over the internet. Because this...
Recent Comments