A Server-Side Request Forgery (SSRF) vulnerability was identified in the bdthemes Instant Image Generator plugin for WordPress, affecting versions from n/a through 2.1.4. This issue allows an attacker to perform Server Side Request Forgery. The vulnerability has a CVSS score of 6.4 and a severity rating of MEDIUM. Administrators and users of the bdthemes Instant Image Generator plugin for WordPress should [truncated]
CVE-2026-52705 is a critical vulnerability (CVSS Score: 9) in the SigmaForms Pro – AI Generated Forms plugin for WordPress, affecting versions up to and including 1.4.5. This vulnerability allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution, data breaches, or other malicious activities. The vulnerability was published on June 17, 2026, and immediately g [truncated]
CVE-2026-40721 is a HIGH severity vulnerability (CVSS Score: 7.5) in Element Pack Pro plugin versions <= 9.0.6. This vulnerability allows for local file inclusion attacks, potentially enabling attackers to access sensitive files on the server. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of Element Pack Pro should update to a patched version to mitigate this risk.
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. Authenticated attackers with Contributor-level access and above may inject arbitrary JavaScript in SVG [truncated]
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget se [truncated]