by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-3657 is a High severity vulnerability (CVSS 7.5) affecting My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) (slug: mystickymenu) in versions up to and including 2.8.6. The issue can be exploited remotely by...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-3226 affects the LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (slug: learnpress) in versions 4.3.2.8 and below. This is a Medium severity issue (CVSS 4.3) that can be exploited by an authenticated user with...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors The WordPress plugin Name Directory (slug: name-directory) contains a High severity vulnerability (CVSS 7.2) identified as CVE-2026-3178. It is an unauthenticated stored cross-site scripting (XSS) issue, meaning an attacker does not need a login to...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-3231 is a High severity Stored Cross-Site Scripting (XSS) vulnerability affecting Checkout Field Editor (Checkout Manager) for WooCommerce (slug: woo-checkout-field-editor-pro) in versions <= 2.1.7 (CVSS 7.2, vector:...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-3492 affects the Gravity Forms plugin (gravityforms) in versions up to and including 2.9.28.1 and is rated Medium severity (CVSS 6.4). The issue is an authenticated (Subscriber+) stored cross-site scripting (XSS) vulnerability triggered through...
by Ivan Sorkin | Mar 11, 2026 | Plugins
Attack Vectors CVE-2026-1993 is a High-severity (CVSS 8.8) privilege escalation issue affecting ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) (slug: google-analytics-dashboard-for-wp) in versions 7.1.0 through 9.0.2. The attack...
Recent Comments