Vulnerability Research & Analysis
Source-to-sink root cause analyses, CVE disclosures, deserialization gadget chains, and exploit mechanics.
CVE-2026-3359 WordPress Form Maker by 10Web Plugin <= 1.15.42 is vulnerable to a high priority SQL Injection
# Critical SQL Injection (CVE-2026-3359) in WordPress Form Maker by 10Web  ## Overview Published: ...
CVE-2026-2628 WordPress All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability
# WordPress All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability  ## Overvie...
CVE-2026-0702 WordPress VidShop Plugin <= 1.1.4 is vulnerable to a high priority SQL Injection
# CVE-2026-0702 WordPress VidShop Plugin <= 1.1.4 is vulnerable to a high priority SQL Injection  # VidS...
CVE-2026-23550 WordPress Modular DS Plugin <= 2.5.1 is vulnerable to a high priority Privilege Escalation
# CVE-2026-23550 WordPress Modular DS Plugin <= 2.5.1 is vulnerable to a high priority Privilege Escalation  ##...
CVE-2025-13329 File Uploader for WooCommerce
# CVE-2025-13329 File Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-data  # Wo...
CVE-2025-14770 – Unauthenticated SQL Injection via “city” Parameter
 # WordPress Shipping Rate By Cities Plugin ## Overview - CVE ID: CVE-2025-14770 - Affected Plugin: ...