Tag

#WordPress Vulnerability

blogMEDIUM 6.4

Understanding and Defending Against CVE-2026-11996: Stored Cross-Site Scripting in Advanced Popups Plugin

This educational analysis covers CVE-2026-11996, a Stored Cross-Site Scripting (XSS) vulnerability in the Advanced Popups plugin for WordPress. The vulnerability, with a CVSS score of 6.4, allows authenticated attackers with author-level access to inject arbitrary web scripts. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies.

1 source
blogHIGH 7.5

Understanding and Defending Against Local File Inclusion Vulnerability in Eventin WordPress Plugin

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion (LFI) due to a flaw in the 'event_layout' parameter. This allows authenticated attackers with contributor-level access to include and execute arbitrary PHP files on the server. The vulnerability has a CVSS score of 7.5 and is classified under CWE-98.

1 source
articleCRITICAL 10.0

CVE-2026-61962: Unauthenticated Arbitrary Code Execution in WP BASE Booking Plugin

A critical vulnerability (CVE-2026-61962) with a CVSS score of 10 has been discovered in the WP BASE Booking plugin (versions <= 6.3.0). This unauthenticated arbitrary code execution vulnerability allows attackers to execute code remotely without authentication, posing a significant risk to WordPress installations using this plugin. Immediate patching is recommended to prevent potential exploitation.

1 source
newsHIGH 7.5

CVE-2026-13339: CubeWP Framework Plugin Directory Traversal Vulnerability

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30. This allows unauthenticated attackers to read arbitrary files on the server, potentially exposing sensitive information. A CVSS score of 7.5 indicates a high severity vulnerability.

1 source
newsHIGH 8.8

CVE-2026-15155: Authenticated Account Takeover via Email Header Injection in Essential Addons for Elementor

The Essential Addons for Elementor plugin for WordPress is vulnerable to authenticated account takeover via email header injection. An attacker with Contributor-level access can inject a Bcc header into the administrator's password-reset notification email, potentially leading to full administrator account takeover. The vulnerability has a CVSS score of 8.8 and affects all versions up to 6.6.10.

1 source
articleHIGH 8.8

Critical Vulnerability in Swiss Toolkit For WP Plugin: Arbitrary File Upload and Potential RCE

The Swiss Toolkit For WP plugin for WordPress, versions up to and including 1.4.6, is vulnerable to arbitrary file upload due to a flawed file type validation bypass. This allows authenticated attackers with Author-level access to upload arbitrary files, potentially leading to remote code execution if the 'Enhanced Multi-Format Image Support' feature is enabled. The vulnerability has a CVSS score of 8.8, indicating high severity. Immediate patching is recommended.

1 source
blogHIGH 7.5

Understanding and Defending Against CVE-2026-15291: Sensitive Information Exposure in Chat Help Plugin

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure due to missing authentication and authorization checks in its REST API endpoints. This allows unauthenticated attackers to extract sensitive data, including customer information and WordPress account credentials. The vulnerability has a CVSS score of 7.5 and affects all versions up to 3.1.3.

1 source
blogMEDIUM 6.4

Understanding and Defending Against CVE-2026-13335: Stored Cross-Site Scripting in CodePeople Post Map for Google Maps

This educational analysis covers CVE-2026-13335, a Stored Cross-Site Scripting (XSS) vulnerability in the CodePeople Post Map for Google Maps plugin for WordPress. The vulnerability allows authenticated attackers with Contributor-level access to inject arbitrary web scripts, impacting all versions up to and including 1.2.6. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies.

1 source
blogMEDIUM 5.3

Understanding the Risks of CVE-2025-12714: Unauthorized Access in Rank Math SEO Plugin

The Rank Math SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check, allowing unauthenticated attackers to modify plugin settings. This can have severe impacts on SEO rankings and display malicious content. The vulnerability has a CVSS severity score of 5.3.

1 source