by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors My Album Gallery (slug: my-album-gallery) versions <= 1.0.4 are affected by CVE-2026-22485, a High severity issue (CVSS 8.1, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). This vulnerability can be exploited by an authenticated user with...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-2289 is a Medium severity Stored Cross-Site Scripting (XSS) issue (CVSS 4.4) affecting the Taskbuilder – Project Management & Task Management Tool With Kanban Board WordPress plugin (slug: taskbuilder) up to version 5.0.3. The attack...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-22479 is a Medium severity vulnerability (CVSS 5.3, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) affecting Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress (slug: easy-post-submission) in versions...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors The WordPress plugin My auctions allegro (slug: my-auctions-allegro-free-edition) is affected by a Medium-severity vulnerability (CVSS 6.1) identified as CVE-2026-22491. It is a Reflected Cross-Site Scripting (XSS) issue impacting versions up to and...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-22520 is a Medium-severity (CVSS 6.1) Reflected Cross-Site Scripting (XSS) issue affecting the Handmade Framework WordPress plugin (handmade-framework) in versions up to and including 3.9. This vulnerability can be exploited by an...
by Ivan Sorkin | Mar 12, 2026 | Plugins
Attack Vectors CVE-2026-2466 affects the DukaPress WordPress plugin (versions <= 3.2.4) and is rated High severity with a CVSS 7.2 score (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N). The issue is an unauthenticated stored cross-site scripting (XSS) vulnerability,...
Recent Comments