Website Security
“Unable to Contact Your Store’s REST API”; When Your Security Plugin Is Blocking Your Payment Processor
A payment gateway reporting invalid WooCommerce REST API credentials, even when they test fine, often means Wordfence is silently blocking the provider’s server. Here’s how to find the block in two minutes and fix it for good.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘jsonText’ Block Attribute – CVE-2026-3427 | WordPress Plugin Vulnerability Report
Plugin Name: Yoast SEO – Advanced SEO with real-time guidance and built-in AI Key Information: Software Type: PluginSoftware Slug: wordpress-seoSoftware Status: ActiveSoftware Author: yoastSoftware Downloads: 930,902,675Active Installs: 10,000,000Last Updated: March 22, 2026Patched Versions: 27.2Affected Versions: <= 27.1.1 Vulnerability Details: Name: Yoast SEO <= 27.1.1Title: Authenticated (Contributor+) Stored Cross-Site Scripting via ‘jsonText’ Block AttributeType: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NCVE: CVE-2026-3427CVSS…
The Events Calendar Vulnerability – Missing Authorization to Authenticated (Subscriber+) Data Migration Control – CVE-2025-15043 | WordPress Plugin Vulnerability Report
Plugin Name: The Events Calendar Key Information Software Type: PluginSoftware Slug: the-events-calendarSoftware Status: ActiveSoftware Author: stellarwpSoftware Downloads: 78,686,265Active Installs: 700,000Last Updated: January 22, 2026Patched Versions: 6.15.13.1Affected Versions: ≤ 6.15.13 Vulnerability Details Name: The Events Calendar ≤ 6.15.13 – Missing Authorization to Authenticated Data Migration ControlTitle: Missing Authorization to Authenticated (Subscriber+) Data Migration ControlType: Missing Authorization…
Custom Fonts – Host Your Fonts Locally Vulnerability – Missing Authorization to Unauthenticated Font Deletion – CVE-2025-14351 | WordPress Plugin Vulnerability Report
Plugin Name: Custom Fonts – Host Your Fonts Locally Key Information Software Type: PluginSoftware Slug: custom-fontsSoftware Status: ActiveSoftware Author: brainstormforceSoftware Downloads: 6,158,177Active Installs: 300,000Last Updated: January 22, 2026Patched Versions: 2.1.17Affected Versions: ≤ 2.1.16 Vulnerability Details Name: Custom Fonts – Host Your Fonts Locally ≤ 2.1.16 Title: Missing Authorization to Unauthenticated Font DeletionType: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCVE: CVE-2025-14351CVSS Score: 5.3Publicly…
Essential Addons for Elementor – Popular Elementor Templates & Widgets Vulnerability – Missing Authorization to Unauthenticated Sensitive Information Exposure – CVE-2026-1004 | WordPress Plugin Vulnerability Report
Plugin Name: Essential Addons for Elementor – Popular Elementor Templates & Widgets Key Information Software Type: PluginSoftware Slug: essential-addons-for-elementor-liteSoftware Status: ActiveSoftware Author: wpdevteamSoftware Downloads: 117,159,772Active Installs: 2,000,000Last Updated: January 22, 2026Patched Versions: 6.5.6Affected Versions: ≤ 6.5.5 Vulnerability Details Name: Essential Addons for Elementor ≤ 6.5.5 – Missing Authorization to Unauthenticated Sensitive Information ExposureTitle: Missing Authorization…
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Vulnerability – Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure – CVE-2025-14384 | WordPress Plugin Vulnerability Report
Plugin Name: All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Key Information: Software Type: PluginSoftware Slug: all-in-one-seo-packSoftware Status: PatchedSoftware Author: smubSoftware Downloads: 196,420,959Active Installs: 3,000,000Last Updated: January 16, 2026Patched Versions: 4.9.3Affected Versions: ≤ 4.9.2 Vulnerability Details: Name: All in One SEO – Powerful SEO Plugin to Boost SEO…
LiteSpeed Cache Vulnerability – Unauthenticated Sensitive Information Exposure via Log Files – CVE-2024-44000 | WordPress Plugin Vulnerability Report
Plugin Name: LiteSpeed Cache Key Information: Software Type: Plugin Software Slug: litespeed-cache Software Status: Active Software Author: litespeedtech Software Downloads: 79,208,611 Active Installs: 6,000,000 Last Updated: September 6, 2024 Patched Versions: 6.5.0.1 Affected Versions: <= 6.4.1 Vulnerability Details: Name: LiteSpeed Cache <= 6.4.1 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE: CVE-2024-44000 CVSS Score: 7.5 Publicly Published: September 5, 2024…
Elementor Addon Elements Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Parameters – CVE-2024-4401, CVE-2024-7122 | WordPress Plugin Vulnerability Report
Plugin Name: Elementor Addon Elements Key Information: Software Type: Plugin Software Slug: addon-elements-for-elementor-page-builder Software Status: Active Software Author: webtechstreet Software Downloads: 2,783,086 Active Installs: 100,000 Last Updated: September 14, 2024 Patched Versions: 1.13.6, 1.13.7 Affected Versions: <= 1.13.5, <= 1.13.6 Vulnerability 1 Details: Name: Elementor Addon Elements <= 1.13.5 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-4401 CVSS Score:…