| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-24988 | WordPress The Events Calendar Shortcode & Block plugin <= 3.1.1 - Cross Site Scripting (XSS) vulnerability | Brian Hogg | The Events Calendar Shortcode & Block | - | - | 2026-02-03 14:08:37 | Deep Dive |
| CVE-2025-23972 | WordPress Contact Form 7 reCAPTCHA plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) Vulnerability | Brian S. Reed | Contact Form 7 reCAPTCHA | Medium | 4.3 | 2025-07-04 08:42:04 | Deep Dive |
| CVE-2025-32202 | WordPress Insert or Embed Articulate Content into WordPress plugin <= 4.3000000025 - Arbitrary File Upload vulnerability | Brian Batt - elearningfreak.com | Insert or Embed Articulate Content into WordPress | Critical | 9.1 | 2025-04-10 08:09:44 | Deep Dive |
| CVE-2025-23489 | WordPress WP-Announcements plugin <= 1.8 - Reflected Cross Site Scripting (XSS) vulnerability | Brian Messenlehner | WP-Announcements | High | 7.1 | 2025-01-21 17:21:50 | Deep Dive |
| CVE-2025-22572 | WordPress Legacy ePlayer plugin <= 0.9.9 - Cross Site Scripting (XSS) vulnerability | Brian | Legacy ePlayer | Medium | 6.5 | 2025-01-07 14:57:10 | Deep Dive |
| CVE-2023-52201 | WordPress pTypeConverter Plugin <= 0.2.8.1 is vulnerable to SQL Injection | Brian D. Goad | pTypeConverter | High | 7.6 | 2024-01-08 20:09:31 | Deep Dive |
| CVE-2023-50824 | WordPress Insert or Embed Articulate Content into WordPress Plugin <= 4.3000000021 is vulnerable to Cross Site Scripting (XSS) | Brian Batt | Insert or Embed Articulate Content into WordPress | Medium | 6.5 | 2023-12-21 14:42:05 | Deep Dive |
| CVE-2022-3240 | Follow Me Plugin <= 3.1.1 - Cross-Site Request Forgery to Cross-Site Scripting | brian-chappell | Follow Me Plugin | High | 8.8 | 2022-11-15 13:25:57 | Deep Dive |