I went for coffee and came back with 6 vulnerabilities in WordPress plugins
Related Vulnerabilities
- CVE-2026-3371: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure MEDIUM
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
- CVE-2026-2305: The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM
- CVE-2026-4895: The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cros MEDIUM
- CVE-2026-23900: Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0 MEDIUM
Related Coverage
Threat Actors