Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tarcísio Luchesi

#22498of 54,922
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-61526
4.3
2026-07-20
WordPress · Kirki · CVE-2026-12724
**Name of the Vulnerable Software and Affected Versions** Kirki WordPress plugin versions prior to 6.0.12 **Description** Unauthenticated users can inject arbitrary HTML into password-reset emails sent to registered users. This occurs because the plugin fails to sanitize or escape the email subject and body values provided in a request before including them in the HTML message, which could facilitate phishing attacks. **Recommendations** Update Kirki WordPress plugin to version 6.0.12 or later.
PT-2026-52809
6.5
2026-06-26
Wpmanageninja Llc · Fluent Booking · CVE-2026-57638
Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.