[email protected]
  • Pricing
  • Checkout
  • My Account
0 Items
WPFore
  • Home
  • Pricing
  • Need Support?
  • Blog
Select Page

WP Recipe Maker Vulnerability (Medium) – CVE-2026-1558

by Ivan Sorkin | Feb 26, 2026 | Plugins

Attack Vectors WP Recipe Maker (slug: wp-recipe-maker) versions up to and including 10.3.2 contain a Medium-severity vulnerability (CVE-2026-1558, CVSS 5.3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) that can be exploited remotely over the internet. The issue is...

xPromoter Vulnerability (Medium) – CVE-2025-68053

by Ivan Sorkin | Feb 26, 2026 | Plugins

Attack Vectors The xPromoter WordPress plugin (slug: top_bar_promoter) has an authenticated SQL Injection vulnerability affecting versions up to and including 1.3.4 (CVE: CVE-2025-68053). The severity is rated Medium with a CVSS 3.1 score of 6.5...

Custom Field Template Vulnerability (Medium) – CVE-2025-63058

by Ivan Sorkin | Feb 26, 2026 | Plugins

Attack Vectors The vulnerability CVE-2025-63058 affects the WordPress plugin Custom Field Template (slug: custom-field-template) in versions 2.7.6 and earlier. It is rated Medium severity (CVSS 4.3) and is exploitable over the network, meaning an attacker can attempt...

Xpro Addons — 140+ Widgets for Elementor Vulnerability (Medium) – C…

by Ivan Sorkin | Feb 26, 2026 | Plugins

Attack Vectors The WordPress plugin Xpro Addons — 140+ Widgets for Elementor (slug: xpro-elementor-addons) is affected by a Medium-severity vulnerability (CVE-2025-63044, CVSS 6.4) that enables stored cross-site scripting (XSS) by an authenticated user with...

Paid Videochat Turnkey Site – HTML5 PPV Live Webcams Vulnerability …

by Ivan Sorkin | Feb 26, 2026 | Plugins

Attack Vectors CVE-2025-62959 is a High-severity vulnerability (CVSS 7.2) affecting the WordPress plugin Paid Videochat Turnkey Site – HTML5 PPV Live Webcams (slug: ppv-live-webcams) in versions up to and including 7.3.23. It allows authenticated attackers with...

Porto Theme – Functionality Vulnerability (Medium) – CVE-2025-63066

by Ivan Sorkin | Feb 26, 2026 | Plugins

Attack Vectors CVE-2025-63066 is a Medium-severity Stored Cross-Site Scripting (XSS) issue affecting the Porto Theme – Functionality WordPress plugin (slug: porto-functionality) in versions prior to 3.7.3. The attack requires an authenticated WordPress account...
« Older Entries
Next Entries »

Recent Posts

  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • RestroPress – Online Food Ordering System Vulnerability (Medium) – …
  • Kraken.io Image Optimizer Vulnerability (Medium) – CVE-2023-0619
  • Vantage Vulnerability (Medium) – CVE-2026-5070
  • WP Docs Vulnerability (Medium) – CVE-2026-3878

Recent Comments

    Archives

    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024

    Categories

    • Core
    • Plugins
    • Themes
    • Uncategorized
    • WooCommerce
    • WordPress Customization
    • WordPress Maintenance
    • WordPress Performance
    • WordPress Security
    • WordPress Support

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Location

    Vrasida 5, Nicosia, Cyprus.

    (+357) 96384131

    [email protected]

    Follow Us

    • Follow
    • Follow
    • Follow
    • Follow
    • Follow
    • Follow

    Subscription

    Stay in touch and follow our latest developments.

    Success!

    Subscribe