CVE-2025-68861: When “Logged-In” Is Enough — Plugin Optimizer Breaks WordPress Access Control
Executive Summary (Quick View) What Is CVE-2025-68861? CVE-2025-68861 is a missing authorization vulnerability in the WordPress plugin…
continue reading..
CVE-2025-68706 – One Malicious Web Request Can Crash or Compromise KuWFi Routers
CVE ID: CVE-2025-68706Vulnerability Type: Stack-based Buffer OverflowAffected Component: GoAhead-Webs HTTP daemonAffected Product: KuWFi 4G LTE AC900 RouterAffected…
continue reading..
CVE-2025-13592 vulnerability affecting the Advanced Ads WordPress plugin
CVE-2025-13592 is a high-severity remote code execution (RCE) vulnerability affecting the Advanced Ads WordPress plugin (also known…
continue reading..
Romanian Waters (Apele Române) Ransomware Attack
Systems Impacted The attack disrupted large parts of the organization’s IT infrastructure, including: However, operational technology (OT)…
continue reading..
High-Risk Vulnerabilities in Nagios XI Allow Authenticated Attackers to Access Data and System Files
CVE-2025-67255 Product: Nagios XIAffected Version: 2026R1.0.1 (Build 1762361101)Vulnerability Type: SQL InjectionCVSS v3.1 Score: 8.1Severity: HighAttack Vector: NetworkAuthentication…
continue reading..
CVE-2025-68860 — Critical Authentication Bypass in WordPress Mobile Builder Plugin
Name: CVE-2025-68860 Type: Authentication Bypass (using alternate path or channel) Severity: Critical — CVSS v3.1 Base Score…
continue reading..
CVE-2025-68562: One Upload, Total Takeover: How a MapSVG File Upload Bug Opens the Door to Web Shell Attacks
Overview CVE ID: CVE-2025-68562Affected Product: MapSVG (RomanCode WordPress plugin)Affected Versions: All versions up to and including 8.7.3Severity:…
continue reading..
CVE-2025-15212 — SQL injection in code-projects Refugee Food Management System 1.0
CVE-2025-15212 is a SQL injection vulnerability affecting Refugee Food Management System (version 1.0) distributed on code-projects. The…
continue reading..
CVE-2025-15284: When a Safety Limit Isn’t a Safety Limit — Breaking qs Array Parsing
CVE ID: CVE-2025-15284Severity: HIGHCVSS Score: 7.5Impact: Availability (Denial of Service) Exploitability Summary This vulnerability allows attackers to…
continue reading..
