Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-02-27

CVE-2026-28132 - WooCommerce Photo Reviews Theme

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through

THEME WooCommerce Photo Reviews

CVE-2026-28132

MEDIUM CVSS 5.3 2026-02-26
Threat Entry Updated 2024-09-26

CVE-2024-8277 - Woocommerce Photo Reviews Plugin

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly verifying the user's identity. This makes it possible for unauthenticated attackers to log in as user that has dismissed an admin notice in the past 30 days, which is often an administrator. Alternatively, a user can log in as any user with any transient that has a…

PLUGIN Woocommerce Photo Reviews

CVE-2024-8277

CRITICAL CVSS 9.8 2024-09-11
Scroll to top