[email protected]
  • Pricing
  • Checkout
  • My Account
0 Items
WPFore
  • Home
  • Pricing
  • Need Support?
  • Blog
Select Page

WP CTA – Call Now Button, Sticky Button & Call to Action Builder Vu…

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2026-22459 is a Medium-severity vulnerability (CVSS 5.3) affecting the WP CTA – Call Now Button, Sticky Button & Call to Action Builder plugin (also marketed as “WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales”) in versions up to and...

Profile Builder Pro Vulnerability (High) – CVE-2026-27413

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors Profile Builder Pro versions before 3.14.0 are affected by a High-severity vulnerability (CVE-2026-27413, CVSS 7.5) that can be exploited without authentication. In practical terms, this means an external attacker can target a vulnerable website over...

Contact Form by Supsystic Vulnerability (Medium) – CVE-2025-52753

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2025-52753 is a medium-severity (CVSS 6.1) reflected cross-site scripting (XSS) issue affecting the WordPress plugin Contact Form by Supsystic (slug: contact-form-by-supsystic) in versions up to and including 1.7.36. The attack is typically...

ArtPlacer Widget Vulnerability (Medium) – CVE-2026-24555

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2026-24555 is a Medium-severity Stored Cross-Site Scripting (XSS) issue affecting the ArtPlacer Widget WordPress plugin (slug: artplacer-widget) in versions up to and including 2.23.2. The vulnerability can be exploited by an authenticated user with...

BOX NOW Delivery Vulnerability (Medium) – CVE-2026-24571

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2026-24571 is a Medium-severity authorization issue (CVSS 4.3) affecting the BOX NOW Delivery WordPress plugin (box-now-delivery) in versions up to and including 3.0.2. The risk is triggered when an attacker already has a valid login (for example, a...

Notifications for Forms & WordPress Actions Vulnerability (Medium) …

by Ivan Sorkin | Apr 15, 2026 | Plugins

Attack Vectors CVE-2025-68020 affects the WANotifier / Notifications for Forms & WordPress Actions plugin (slug: notifier) in versions up to and including 2.7.13. The issue is a missing authorization (capability) check, which means an attacker does not need an...
« Older Entries
Next Entries »

Recent Posts

  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • Kraken.io Image Optimizer Vulnerability (Medium) – CVE-2023-0619
  • Vantage Vulnerability (Medium) – CVE-2026-5070
  • WP Docs Vulnerability (Medium) – CVE-2026-3878

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024

    Categories

    • Core
    • Plugins
    • Themes
    • Uncategorized
    • WooCommerce
    • WordPress Customization
    • WordPress Maintenance
    • WordPress Performance
    • WordPress Security
    • WordPress Support

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Location

    Vrasida 5, Nicosia, Cyprus.

    (+357) 96384131

    [email protected]

    Follow Us

    • Follow
    • Follow
    • Follow
    • Follow
    • Follow
    • Follow

    Subscription

    Stay in touch and follow our latest developments.

    Success!

    Subscribe