[email protected]
  • Pricing
  • Checkout
  • My Account
0 Items
WPFore
  • Home
  • Pricing
  • Need Support?
  • Blog
Select Page

SiteOrigin Widgets Bundle Vulnerability (Medium) – CVE-2026-2127

by Ivan Sorkin | Feb 17, 2026 | Plugins

Attack Vectors SiteOrigin Widgets Bundle (slug: so-widgets-bundle) versions 1.70.4 and earlier have a Medium severity issue (CVSS 5.4) that can be abused by someone who already has a login on your site. The risk is specifically tied to authenticated users—including...

Community Events Vulnerability (Medium) – CVE-2026-1649

by Ivan Sorkin | Feb 17, 2026 | Plugins

Attack Vectors CVE-2026-1649 affects the WordPress plugin Community Events (slug: community-events) in versions 1.5.7 and earlier. It is a Medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 4.4) that requires an attacker to already be authenticated with...

WP Event Aggregator: Import Eventbrite events, Meetup events, socia…

by Ivan Sorkin | Feb 17, 2026 | Plugins

Attack Vectors CVE-2026-1941 affects the WordPress plugin “WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into Event Calendar” (slug: wp-event-aggregator) in versions up to and including 1.8.7. It is rated Medium...

Business Directory Plugin – Easy Listing Directories for WordPress …

by Ivan Sorkin | Feb 17, 2026 | Plugins

Attack Vectors CVE-2026-1656 affects Business Directory Plugin – Easy Listing Directories for WordPress (slug: business-directory-plugin) in versions up to and including 6.4.20. Rated Medium severity (CVSS 5.3, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N),...

EventPrime – Events Calendar, Bookings and Tickets Vulnerability (M…

by Ivan Sorkin | Feb 17, 2026 | Plugins

Attack Vectors CVE-2026-1655 is a Medium-severity issue (CVSS 4.3) affecting EventPrime – Events Calendar, Bookings and Tickets (slug: eventprime-event-calendar-management) in versions up to 4.2.8.4. An attacker must be authenticated (Subscriber/Customer level or...

WP-DownloadManager Vulnerability (Low) – CVE-2026-2419

by Ivan Sorkin | Feb 17, 2026 | Plugins

Attack Vectors CVE-2026-2419 affects the WP-DownloadManager WordPress plugin (slug: wp-downloadmanager) in versions 1.69 and earlier. This is a Low severity issue (CVSS 2.7) that requires an authenticated user with Administrator-level access (or higher) to exploit....
« Older Entries
Next Entries »

Recent Posts

  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • Kraken.io Image Optimizer Vulnerability (Medium) – CVE-2023-0619
  • Vantage Vulnerability (Medium) – CVE-2026-5070
  • WP Docs Vulnerability (Medium) – CVE-2026-3878

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024

    Categories

    • Core
    • Plugins
    • Themes
    • Uncategorized
    • WooCommerce
    • WordPress Customization
    • WordPress Maintenance
    • WordPress Performance
    • WordPress Security
    • WordPress Support

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Location

    Vrasida 5, Nicosia, Cyprus.

    (+357) 96384131

    [email protected]

    Follow Us

    • Follow
    • Follow
    • Follow
    • Follow
    • Follow
    • Follow

    Subscription

    Stay in touch and follow our latest developments.

    Success!

    Subscribe