Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ritsuy

#20714of 56,330
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-50322
7.1
2026-04-21
WordPress · Collectchat · CVE-2026-40765
**Name of the Vulnerable Software and Affected Versions** collectchat versions prior to 2.5.0 **Description** The Chatbot for WordPress by Collect.chat plugin is subject to Stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server. This occurs due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts execute automatically whenever a user visits the affected page. **Recommendations** Update the plugin to a version newer than 2.4.9.
PT-2025-39062
6.5
2025-09-22
WordPress · Make Column Clickable Elementor · CVE-2025-59592
**Name of the Vulnerable Software and Affected Versions** Make Column Clickable Elementor versions through 1.6.0 **Description** The software contains a flaw related to improper handling of user-supplied data when creating web pages, potentially leading to Cross-site Scripting (XSS). This allows for the injection of malicious scripts into web pages viewed by other users. The issue is a Stored XSS, meaning the malicious script is permanently stored on the target server. **Recommendations** Update Make Column Clickable Elementor to a version later than 1.6.0.