Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Volodymyr Kolesnykov

#19939of 56,335
14.4Total CVSS
Vulnerabilities · 2
High
2
PT-2026-54499
7.2
2026-07-01
WordPress · Webauthn Provider For Two Factor · CVE-2026-11883
**Name of the Vulnerable Software and Affected Versions** WebAuthn Provider for Two Factor WordPress plugin versions prior to 2.5.6 **Description** An issue exists where the plugin fails to correctly validate the second-factor authentication response. This allows an attacker who has already obtained a user's password to bypass the two-factor authentication requirement by submitting a malformed request. **Recommendations** Update the plugin to version 2.5.6 or later.
PT-2026-53940
7.2
2026-06-30
WordPress · Webmention · CVE-2026-10513
**Name of the Vulnerable Software and Affected Versions** Webmention versions prior to 5.8.1 **Description** Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping of user-supplied Microformat 2 (MF2) author properties. An unauthenticated attacker can inject arbitrary web scripts via the `avatar` and `url` author metadata processed by the unauthenticated webmention REST endpoint. These scripts are rendered directly into HTML value attributes by the edit-comment-form template without the use of `esc attr()` or `esc url()` functions. The injected scripts execute when a privileged user, such as a moderator or administrator, opens the affected comment edit screen. **Recommendations** Update Webmention to a version later than 5.8.0.