Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lubin Regnault

#20859of 56,331
13.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-63575
6.1
2026-07-23
WordPress · Wp Compress · CVE-2026-9066
**Name of the Vulnerable Software and Affected Versions** WP Compress versions prior to 7.10.04 **Description** Insufficient validation of a query parameter that controls the asset CDN host allows for Reflected XSS (Cross-Site Scripting), a flaw where malicious scripts are reflected off a web application to the victim's browser. The loader injects script elements pointing to an attacker-controlled origin via the `test zone` parameter, enabling the execution of arbitrary JavaScript within the visitor's session on the target site. **Recommendations** Update WP Compress to version 7.10.04 or later. Avoid using the `test zone` parameter in the affected plugin until the update is applied.
PT-2026-50323
7.3
2026-04-21
Dimitri Grassi · Salon Booking System · CVE-2026-40768
**Name of the Vulnerable Software and Affected Versions** Salon booking system versions prior to 10.30.25 **Description** The Salon Booking System – Free Version plugin for WordPress contains an Insecure Direct Object Reference (IDOR) flaw. This occurs due to missing validation on a user-controlled key, allowing unauthenticated attackers to perform unauthorized actions. **Recommendations** Update the plugin to a version newer than 10.30.24.