Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Shivam Kumar

#27372of 55,077
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-51679
5.3
2026-06-24
WordPress · Secufor Oauth · CVE-2026-7617
**Name of the Vulnerable Software and Affected Versions** Secufor OAuth versions prior to 1.0.8 **Description** The Secufor OAuth plugin for WordPress contains an unauthorized access flaw resulting from improper verification of user authorization. This allows unauthenticated attackers to disconnect a WordPress site from its linked Secufor account by clearing the stored login token and user login configuration. **Recommendations** Update the plugin to a version newer than 1.0.7.
PT-2026-20580
4.3
2026-02-19
WordPress · Mailchimp List Subscribe Form · CVE-2025-12172
**Name of the Vulnerable Software and Affected Versions** Mailchimp List Subscribe Form versions prior to 2.0.1 **Description** The Mailchimp List Subscribe Form plugin for WordPress is susceptible to Cross-Site Request Forgery. This is caused by inadequate nonce validation within the `mailchimp sf change list if necessary()` function. An unauthenticated attacker could potentially modify Mailchimp lists by deceiving a site administrator into performing an action, such as clicking a malicious link. **Recommendations** Update Mailchimp List Subscribe Form to version 2.0.1 or later.