by Ivan Sorkin | Mar 19, 2026 | Plugins
Attack Vectors CVE-2026-25452 is a High-severity vulnerability (CVSS 7.2, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) affecting the WordPress plugin Remoji – Post/Comment Reaction and Enhancement (slug: remoji) in versions up to and including 2.2. Because...
by Ivan Sorkin | Mar 19, 2026 | Plugins
Attack Vectors CVE-2025-15363 is a Medium-severity Stored Cross-Site Scripting (XSS) issue (CVSS 6.4) affecting Get Use APIs – JSON Content Importer (slug: json-content-importer) in versions prior to 2.0.10. The attack requires an authenticated WordPress account with...
by Ivan Sorkin | Mar 19, 2026 | Plugins
Attack Vectors CVE-2026-4136 is a Medium-severity unvalidated redirect vulnerability affecting the Membership Plugin – Restrict Content WordPress plugin (slug: restrict-content) in all versions up to and including 3.2.24. The issue can be triggered during the password...
by Ivan Sorkin | Mar 19, 2026 | Plugins
Attack Vectors CVE-2026-3589 is a medium-severity Cross-Site Request Forgery (CSRF) issue affecting the WooCommerce WordPress plugin (versions earlier than 10.5.3). It can be exploited by an unauthenticated attacker if they can trick a logged-in site administrator...
by Ivan Sorkin | Mar 19, 2026 | Plugins
Attack Vectors The Ultra WordPress Admin plugin (Ultra Admin, slug: ultra-admin) is affected by a Medium-severity vulnerability (CVSS 6.1) identified as CVE-2026-22523. It is a Reflected Cross-Site Scripting (XSS) issue impacting versions up to and including 11.7....
by Ivan Sorkin | Mar 19, 2026 | Plugins
Attack Vectors Legacy Admin (WordPress plugin slug: legacy-admin) is affected by a Medium-severity Reflected Cross-Site Scripting (XSS) vulnerability (CVSS 6.1; UI:R) in versions up to and including 9.5, tracked as CVE-2026-22524. The most common attack path is a...
Recent Comments