by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors This medium-severity vulnerability (CVSS 4.3) affects the Auto Post to Social Media from Social Champ WordPress plugin (also referred to as “SocialChamp with WordPress”) in versions up to and including 1.3.5. The primary attack path is Cross-Site...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-2504 is a Medium-severity vulnerability (CVSS 4.3) affecting Dealia – Request a quote (slug: dealia-request-a-quote) in versions <= 1.0.7. The practical risk scenario is an authenticated attacker who already has a low-privilege WordPress...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-2718 affects the Dealia – Request a Quote WordPress plugin (slug: dealia-request-a-quote) in versions up to and including 1.0.8. This is a Medium-severity issue (CVSS 6.4, vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N). The attack...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors WP eCommerce (slug: wp-e-commerce) versions up to and including 3.15.1 are affected by a High-severity vulnerability (CVSS 8.1) identified as CVE-2026-1235. The primary exposure is that the issue is described as unauthenticated, meaning an attacker does...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2025-14892 is a Critical (CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) vulnerability affecting the Prime Listing Manager WordPress plugin (prime-listing-manager) in all versions up to and including 1.1. The primary attack path is simple...
by Ivan Sorkin | Feb 25, 2026 | Plugins
Attack Vectors CVE-2026-22354 is a High-severity vulnerability (CVSS 7.5; CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) affecting the WordPress plugin Banner Management, Product Slider, Product Carousel for WooCommerce (slug: banner-management-for-woocommerce) in...
Recent Comments