by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WP Gravity Forms Keap/Infusionsoft (slug: gf-infusionsoft) is affected by an Open Redirect vulnerability in versions <= 1.2.6 (Severity: Medium, CVSS 4.3; CVE-2025-58006). The issue occurs when a redirect URL can be supplied without sufficient...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Premmerce WooCommerce Customers Manager (WordPress plugin slug: woo-customers-manager) is affected by a Medium-severity reflected cross-site scripting (XSS) vulnerability (CVE-2025-13369, CVSS 6.1). The attack is carried out by sending a crafted link...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Premmerce (WordPress plugin slug: premmerce) has a Medium-severity Stored Cross-Site Scripting (XSS) vulnerability (CVSS 6.4, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N) tracked as CVE-2026-0555. It affects versions up to and including 1.3.20. The...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Premmerce Brands for WooCommerce (slug: premmerce-woocommerce-brands) versions up to and including 1.2.13 are affected by a Cross-Site Request Forgery (CSRF) vulnerability rated Medium severity (CVSS 4.3). CSRF attacks don’t typically require the...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-12783 affects Premmerce Brands for WooCommerce (slug: premmerce-woocommerce-brands) in versions up to and including 1.2.13. This is a Medium severity issue (CVSS 4.3, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) involving unauthorized...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors Prodigy Commerce (WordPress plugin slug: prodigy-commerce) is affected by CVE-2026-0926, rated Critical with a CVSS 9.8 score (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue can be triggered without authentication, meaning an external attacker...
Recent Comments