Tag
#WordPress Plugin Vulnerability
Critical Vulnerability in Masteriyo LMS WordPress Plugin Allows Unauthenticated Session Termination (CVE-2026-13332)
A critical vulnerability (CVE-2026-13332, CVSS 9.1) exists in the Masteriyo LMS WordPress plugin prior to version 2.3.1. This flaw allows unauthenticated attackers to terminate the active sessions of any user, including administrators, via an unauthenticated AJAX action. Immediate patching is recommended to prevent potential exploitation.
Critical SQL Injection Vulnerability in SALESmanago & Leadoo Plugin
A critical SQL injection vulnerability, CVE-2026-54822, has been discovered in the SALESmanago & Leadoo plugin versions up to 3.11.2. This vulnerability has a CVSS score of 8.5, indicating high severity. Although not actively exploited, it poses a significant risk due to its potential for unauthorized data access. Immediate patching to version 3.11.3 or later is recommended.
CVE-2026-9843: Arbitrary File Deletion Vulnerability in Database for Contact Form 7, WPforms, Elementor forms Plugin
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation. This allows unauthenticated attackers to delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.1 and affects all versions up to 1.5.1. Immediate patching is recommended.
CVE-2024-32110: Cross-Site Request Forgery Vulnerability in WpEvently Plugin
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the WpEvently plugin, affecting versions from n/a through 4.1.2. This vulnerability, tracked as CVE-2024-32110, has a severity score of 4.3 and allows attackers to perform Cross-Site Request Forgery attacks.