CVE-2026-7613 is a stored cross-site scripting issue in the Cost of Goods by PixelYourSite WordPress plugin, affecting versions up to and including 1.2.12. Because the flaw is reachable through the csvdata[0][cost_of_goods_value] parameter and can be triggered by unauthenticated input, site owners should treat it as a high-priority web application risk.
The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3. This vulnerability allows unauthenticated attackers to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure. The vulnerability is due to insufficient escaping on user-supplied parameters an [truncated]
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme contai [truncated]