Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High0
Medium1
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-01-09

CVE-2025-10406 - Blindmatrix E Commerce Plugin

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks.

PLUGIN Blindmatrix E Commerce

CVE-2025-10406

MEDIUM CVSS 5.5 2025-10-15
Scroll to top