Skip to content
Threat Feed

Vendor

Wordfence

6 briefs RSS
medium advisory

Media Library Assistant WordPress Plugin vulnerable to CSRF (CVE-2026-6075)

The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery (CVE-2026-6075) due to missing nonce verification, allowing unauthenticated attackers to trick an administrator into performing unauthorized bulk actions.

Media Library Assistant plugin for WordPress <= 3.35 wordpress csrf plugin
2r 1t 1c
medium advisory

HBook WordPress Plugin Stored XSS Vulnerability (CVE-2026-8143)

The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters (CVE-2026-8143) in versions up to 2.1.6, potentially leading to arbitrary script execution in the administrator's browser.

HBook plugin wordpress xss plugin
2r 1t 1c
high advisory

CVE-2026-9010 - WordPress Boost Plugin Time-Based SQL Injection

The Boost plugin for WordPress is vulnerable to time-based SQL Injection (CVE-2026-9010) via the 'current_url' and 'user_name' parameters in versions up to 2.0.3, allowing unauthenticated attackers to extract sensitive information from the database due to insufficient input sanitization.

Boost plugin for WordPress <= 2.0.3 cve sqli wordpress
1r 1t 1c
high threat

InfusedWoo Pro WordPress Plugin Arbitrary File Read Vulnerability (CVE-2026-6514)

The InfusedWoo Pro plugin for WordPress is vulnerable to arbitrary file read in versions up to 5.1.2, allowing unauthenticated attackers to make web requests to arbitrary locations, potentially querying and modifying information from internal services.

InfusedWoo Pro cve wordpress plugin arbitrary file read ssrf
2r 1t 1c
critical threat

CVE-2026-6271: WordPress Career Section Plugin Arbitrary File Upload Vulnerability

The Career Section plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.7 due to missing file type validation in the CV upload handler, potentially leading to remote code execution.

Career Section plugin arbitrary file upload remote code execution wordpress plugin
2r 1c
medium advisory

LatePoint WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7448)

The LatePoint WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'first_name' parameter, affecting versions up to 5.5.0, allowing unauthenticated attackers to inject malicious scripts.

LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.0 wordpress xss cve-2026-7448
2r 1t 1c