Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tarcísio Luchesi

#23330of 56,330
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-61526
4.3
2026-06-29
WordPress · Kirki · CVE-2026-12724
**Name of the Vulnerable Software and Affected Versions** Kirki WordPress plugin versions prior to 6.0.12 **Description** Unauthenticated users can inject arbitrary HTML into password-reset emails sent to registered users. This occurs because the plugin fails to sanitize or escape the email subject and body values provided in a request before including them in the HTML message, which could facilitate phishing attacks. **Recommendations** Update Kirki WordPress plugin to version 6.0.12 or later.
PT-2026-52809
6.5
2026-06-26
Wpmanageninja Llc · Fluent Booking · CVE-2026-57638
**Name of the Vulnerable Software and Affected Versions** Fluent Booking versions prior to 2.1.1 **Description** Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. This allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which execute when a user accesses the affected page. **Recommendations** Update to a version newer than 2.1.0.