WhisperX tag archive

#plugin-vulnerability

This page collects WhisperX intelligence signals tagged #plugin-vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-05-06 22:31:39 · GitHub Issues

1. CVE-2025-12368: Unpatched Stored XSS in Sermon Manager Shortcode Exposes WordPress Sites to Browser Attacks

A confirmed stored cross-site scripting vulnerability in the Sermon Manager WordPress plugin remains without an upstream patch, leaving websites vulnerable to authenticated attacks that execute malicious code in every visitor's browser. CVE-2025-12368 carries a CVSS score of 6.4 (Medium), but security researchers have ...

The Lab · 2026-05-07 05:31:38 · GitHub Issues

2. WordPress Plugin Flaw Exposes Admin Security Notices to Any Subscriber-Level User

A critical access control failure in a WordPress plugin allows any authenticated user with Subscriber privileges to retrieve all admin-level notices, including those containing sensitive security information. The vulnerability, cataloged as [VULN-1-001], exposes plugin vulnerability alerts, failed login summaries, data...

The Lab · 2026-05-13 16:48:27 · Mastodon:hachyderm.io:#infosec

3. Avada Builder Flaws Expose One Million WordPress Sites to File Read and SQL Injection Attacks

Wordfence threat intelligence researchers have disclosed critical security vulnerabilities in the Avada Builder WordPress plugin, a widely deployed page builder tool, potentially exposing approximately one million WordPress installations to remote attacks. The flaws combine an arbitrary file read vulnerability and a SQ...