[email protected]
  • Pricing
  • Checkout
  • My Account
0 Items
WPFore
  • Home
  • Pricing
  • Need Support?
  • Blog
Select Page

Media Library Assistant Vulnerability (Medium) – CVE-2026-3072

by Ivan Sorkin | Mar 4, 2026 | Plugins

Attack Vectors Media Library Assistant (slug: media-library-assistant) versions 3.33 and earlier have a Medium-severity vulnerability (CVSS 4.3) that can be abused by any authenticated WordPress user with Subscriber-level access or higher. This matters because...

Apocalypse Meow Vulnerability (Medium) – CVE-2026-3523

by Ivan Sorkin | Mar 4, 2026 | Plugins

Attack Vectors Apocalypse Meow (WordPress plugin) versions 22.1.0 and below contain a Medium-severity SQL Injection vulnerability (CVE-2026-3523, CVSS 4.9) that can be triggered through an AJAX request parameter named type. The key business consideration is that...

OoohBoi Steroids for Elementor Vulnerability (Medium) – CVE-2026-3034

by Ivan Sorkin | Mar 4, 2026 | Plugins

Attack Vectors CVE-2026-3034 affects the WordPress plugin OoohBoi Steroids for Elementor (slug: ooohboi-steroids-for-elementor) in versions 2.1.24 and earlier. It is rated Medium severity (CVSS 6.4), and the attacker must already have a WordPress account with...

Fluent Forms Pro Add On Pack Vulnerability (Medium) – CVE-2026-2899

by Ivan Sorkin | Mar 4, 2026 | Plugins

Attack Vectors CVE-2026-2899 affects the WordPress plugin Fluent Forms Pro Add On Pack (slug: fluentformpro) in versions 6.1.17 and earlier, and is rated Medium severity (CVSS 6.5). The primary attack path is over the public internet via WordPress AJAX endpoints....

Fluent Forms Pro Add On Pack Vulnerability (High) – CVE-2026-2365

by Ivan Sorkin | Mar 4, 2026 | Plugins

Attack Vectors Fluent Forms Pro Add On Pack (slug: fluentformpro) versions 6.1.17 and earlier are affected by a High-severity Stored Cross-Site Scripting (XSS) vulnerability tracked as CVE-2026-2365 (CVSS 7.2). An attacker does not need to be logged in to attempt...

Seraphinite Accelerator Vulnerability (Medium) – CVE-2026-3056

by Ivan Sorkin | Mar 4, 2026 | Plugins

Attack Vectors Seraphinite Accelerator (WordPress plugin) has a Medium-severity vulnerability (CVE-2026-3056, CVSS 4.3) that can be exploited by an authenticated user with Subscriber-level access or higher. In practical terms, this means any account that can log...
« Older Entries
Next Entries »

Recent Posts

  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • Kraken.io Image Optimizer Vulnerability (Medium) – CVE-2023-0619
  • Vantage Vulnerability (Medium) – CVE-2026-5070
  • WP Docs Vulnerability (Medium) – CVE-2026-3878

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024

    Categories

    • Core
    • Plugins
    • Themes
    • Uncategorized
    • WooCommerce
    • WordPress Customization
    • WordPress Maintenance
    • WordPress Performance
    • WordPress Security
    • WordPress Support

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Location

    Vrasida 5, Nicosia, Cyprus.

    (+357) 96384131

    [email protected]

    Follow Us

    • Follow
    • Follow
    • Follow
    • Follow
    • Follow
    • Follow

    Subscription

    Stay in touch and follow our latest developments.

    Success!

    Subscribe