VYPR

24liveblog

by WordPress

CVEs (2)

  • CVE-2026-9183Jun 24, 2026
    risk 0.00cvss epss

    The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block_enqueue_scripts() function being hooked to enqueue_block_editor_assets and, for any non-administrator…

  • CVE-2026-9184Jun 24, 2026
    risk 0.00cvss epss

    The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is…