A vulnerability has been found in wpdevteam BetterDocs Plugin up to 4.6.0 on WordPress and classified as critical. This vulnerability affects unknown code of the component Multilingual Handler. Performing a manipulation of the argument lang results in sql injection.
This vulnerability is reported as CVE-2026-15104. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability, which was classified as problematic, was found in sovlix GoodMeet Plugin up to 1.1.8 on WordPress. This affects the function reset_credential of the component Credential Management. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2026-6440. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in room34 ICS Calendar Plugin up to 12.0.9 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. This manipulation of the argument htmltagtitle causes cross site scripting.
This vulnerability is registered as CVE-2026-9838. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as problematic was found in prasunsen Hostel Plugin up to 1.1.7 on WordPress. Affected by this vulnerability is the function wphostel-book of the component Shortcode Handler. The manipulation of the argument text results in cross site scripting.
This vulnerability is cataloged as CVE-2026-3907. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in fahadmahmood Easy Upload Files During Checkout Plugin up to 3.0.1 on WordPress. Affected is the function ufdc_custom_init of the component File Deletion Handler. The manipulation of the argument eufdc-delete leads to missing authorization.
This vulnerability is listed as CVE-2026-6802. The attack may be initiated remotely. There is no available exploit.
A vulnerability described as problematic has been identified in arraytics Eventin Plugin up to 4.1.15 on WordPress. This impacts an unknown function of the component FAQ Content Handler. Executing a manipulation of the argument etn_faq_content can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-12924. The attack can be launched remotely. No exploit exists.
A vulnerability marked as problematic has been reported in looswebstudio Highlighting Code Block Plugin up to 2.2.0 on WordPress. This affects an unknown function of the component Admin Settings Handler. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-12108. The attack can be initiated remotely. There is not any exploit available.
A vulnerability labeled as problematic has been found in wplegalpages Cookie Banner for GDPR CCPA Plugin up to 4.3.6 on WordPress. The impacted element is an unknown function of the component Cookie Consent Handler. Such manipulation of the argument scan_id leads to sql injection.
This vulnerability is referenced as CVE-2026-14475. It is possible to launch the attack remotely. No exploit is available.
A vulnerability identified as critical has been detected in priyanshuchaudhary FlowForms Plugin up to 1.1.1 on WordPress. The affected element is the function update_form of the component Form Update Handler. This manipulation of the argument form_id causes improper control of resource identifiers.
The identification of this vulnerability is CVE-2026-12400. It is possible to initiate the attack remotely. There is no exploit available.
A former ransomware negotiator was sentenced to nearly six years for secretly helping BlackCat extort victims while betraying his clients. A U.S. court sentenced former ransomware negotiator Angelo Martino, 41, to 70 months in prison for conspiring with the BlackCat ransomware gang. While negotiating on behalf of five victims, he secretly shared confidential information about […]