[email protected]
  • Pricing
  • Checkout
  • My Account
0 Items
WPFore
  • Home
  • Pricing
  • Need Support?
  • Blog
Select Page

Theater for WordPress Vulnerability (Medium) – CVE-2025-69343

by Ivan Sorkin | Mar 5, 2026 | Plugins

Attack Vectors Medium severity vulnerability CVE-2025-69343 affects the Theater for WordPress plugin (slug: theatre) in versions <= 0.19. It is a Stored Cross-Site Scripting (XSS) issue that can be exploited by an authenticated user with Subscriber-level access or...

Responsive Lightbox & Gallery Vulnerability (High) – CVE-2025-15386

by Ivan Sorkin | Mar 5, 2026 | Plugins

Attack Vectors Responsive Lightbox & Gallery (slug: responsive-lightbox) versions prior to 2.6.1 are affected by a High-severity vulnerability (CVSS 7.2) tracked as CVE-2025-15386. The issue is an unauthenticated stored cross-site scripting (XSS) weakness, meaning...

ListingPro Plugin Vulnerability (Medium) – CVE-2026-28122

by Ivan Sorkin | Mar 5, 2026 | Plugins

Attack Vectors ListingPro Plugin (slug: listingpro-plugin) versions up to and including 2.9.8 are affected by a Medium-severity reflected cross-site scripting (XSS) issue (CVE-2026-28122, CVSS 6.1). The most common way this type of vulnerability is exploited is...

WP Attractive Donations System – Easy Stripe & Paypal donations Vul…

by Ivan Sorkin | Mar 5, 2026 | Plugins

Attack Vectors The vulnerability in WP Attractive Donations System – Easy Stripe & Paypal donations (versions up to and including 1.25) is a High-severity, unauthenticated SQL Injection (CVE-2026-28115, CVSS 7.5). “Unauthenticated” means an attacker may not...

AllInOne – Banner Rotator Vulnerability (Medium) – CVE-2026-28112

by Ivan Sorkin | Mar 5, 2026 | Plugins

Attack Vectors AllInOne – Banner Rotator (slug: all-in-one-bannerRotator) versions up to and including 3.8 are affected by a Medium-severity Reflected Cross-Site Scripting (XSS) issue (CVE-2026-28112, CVSS 6.1). In practical terms, an attacker can craft a...

LambertGroup – AllInOne – Banner with Playlist Vulnerability (Mediu…

by Ivan Sorkin | Mar 5, 2026 | Plugins

Attack Vectors CVE-2026-28110 is a Medium severity (CVSS 6.1) Reflected Cross-Site Scripting (XSS) vulnerability affecting the WordPress plugin LambertGroup – AllInOne – Banner with Playlist (slug: all-in-one-bannerWithPlaylist) in versions up to and...
« Older Entries
Next Entries »

Recent Posts

  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • Kraken.io Image Optimizer Vulnerability (Medium) – CVE-2023-0619
  • Vantage Vulnerability (Medium) – CVE-2026-5070
  • WP Docs Vulnerability (Medium) – CVE-2026-3878

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024

    Categories

    • Core
    • Plugins
    • Themes
    • Uncategorized
    • WooCommerce
    • WordPress Customization
    • WordPress Maintenance
    • WordPress Performance
    • WordPress Security
    • WordPress Support

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Location

    Vrasida 5, Nicosia, Cyprus.

    (+357) 96384131

    [email protected]

    Follow Us

    • Follow
    • Follow
    • Follow
    • Follow
    • Follow
    • Follow

    Subscription

    Stay in touch and follow our latest developments.

    Success!

    Subscribe