Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hasyros

#28846of 57,311
9.5Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-97719
2.7
2026-09-24
WordPress · Events Manager · CVE-2026-93661
**Name of the Vulnerable Software and Affected Versions** Events Manager versions prior to 7.4.5 **Description** An Insecure Direct Object Reference (IDOR) exists where the plugin fails to prevent a ticket-update request from replacing the identifiers of the ticket it was authorized against. This allows a user with permissions to manage tickets for a single event to overwrite and reassign any ticket on the site to their own event. **Recommendations** Update to version 7.4.5 or later.
PT-2026-93280
6.8
2026-09-16
WordPress · Wp Import Export Lite · CVE-2026-76555
**Name of the Vulnerable Software and Affected Versions** WP Import Export Lite WordPress plugin versions prior to 3.9.33 **Description** Insufficient validation of user-supplied file paths allows users with import permissions to disclose sensitive files from the server, including those located outside the web root. The process involves reading a file and copying it into a publicly accessible directory. Additionally, the affected code path modifies and relaxes the file-system permissions of any provided path, regardless of whether the copy operation is successful. **Recommendations** Update WP Import Export Lite WordPress plugin to version 3.9.33 or later.