Search
Find merged stories by title or summary.
CVE-2026-1256 - YS LeadGen – Popups, Opt-ins & Lead Capture = 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input
CVE ID : CVE-2026-1256 Published : Sept. 19, 2026, 9:16 a. m. • 11 hours, 40 minutes ago Description : The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2. 1. 4 due to missing capability checks on popup management actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary popups and inject malicious JavaScript that executes when the popup is displayed, leading to Stored XSS. Severity: 6.4 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a vulnerability in PTC’s Windchill and FlexPLM platforms, which manufacturers and engineering companies use to manage product and design data. CVE-2026-12569 (CVSS score of 9. 3) is a critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM. An attacker can exploit this vulnerability through the deserialization of untrusted data. The flaw impacts all CPS versions and Windchill and FlexPLM releases prior to 11. 0 M030. In June, the U. S.
You've reached the end of current stories for this search.
