Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
189 articles

#WordPress

All CosmicBytez Labs articles tagged #WordPress, across news, security advisories, how-to guides, and projects.

  • SecurityAug 30, 2026

    Sigma Forms Pro WordPress Plugin: Unauthenticated RCE via File Upload (CVE-2026-14494)

    CVE-2026-14494 (CVSS 9.8) lets unauthenticated attackers upload PHP webshells through Sigma Forms Pro's default form templates. No patch yet.

  • SecurityAug 30, 2026

    Unauthenticated Privilege Escalation to Admin in WooCommerce Plugin (CVE-2026-15369)

    CVE-2026-15369 (CVSS 9.8) lets unauthenticated attackers self-assign the Administrator role during WooCommerce checkout in Addify's plugin.

  • SecurityAug 30, 2026

    MyHome Core WordPress Plugin: Auth Bypass Enables Admin Takeover (CVE-2026-15980)

    CVE-2026-15980 (CVSS 9.8) lets unauthenticated attackers forge activation tokens to hijack WordPress accounts via MyHome Core.

  • NewsAug 29, 2026

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    Five critical flaws in WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP enable auth bypass, takeover, and RCE.

  • NewsAug 29, 2026

    Critical GiveWP Flaw Lets Hackers Run Server Commands

    CVE-2026-82222 chains PHP object injection and an auth-bypass bug in GiveWP, letting attackers run OS commands on 100,000+ WordPress donation sites.

  • SecurityAug 29, 2026

    Uix UserCenter WordPress Plugin: Hardcoded Signing Key Enables Unauthenticated Account Takeover

    CVE-2026-16259 (CVSS 9.8) lets attackers hijack any account on sites running Uix UserCenter — no login needed, and no fix exists yet.

  • SecurityAug 29, 2026

    Total Processing Card Payments for WooCommerce: Unauthenticated SSRF Enables Payment Verification Forgery

    CVE-2026-16947 (CVSS 9.1) lets attackers redirect payment verification requests and forge success responses on WooCommerce stores.

  • SecurityAug 29, 2026

    Icollect Data Collection & Publishing Plugin: Hardcoded Secret Enables Unauthenticated Arbitrary File Read

    CVE-2026-77012 (CVSS 9.3) lets unauthenticated attackers read server files via a WordPress plugin's default publishing secret.

  • SecurityAug 28, 2026

    CVE-2026-32479: Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro

    Critical unauthenticated SQL injection (CVSS 9.3) in the WordPress plugin Visitor Traffic Real Time Statistics Pro ≤ 11.17. Patch to 11.18.

  • SecurityAug 28, 2026

    CVE-2026-32566: Unauthenticated Privilege Escalation in ACPT (Pro) Custom Post Types Plugin

    Critical unauthenticated privilege escalation (CVSS 9.8) in WordPress plugin ACPT (Pro) ≤ 2.0.63. No official patch yet — Patchstack has a mitigation rule.

  • NewsAug 26, 2026

    Critical Avada WordPress Theme Flaw Enables Zero-Click RCE

    Wordfence's AI agent chained six flaws in the Avada theme into an unauthenticated RCE, patched in Avada 7.16.1 for 1M+ sites.

  • SecurityAug 26, 2026

    Critical TranslatePress Flaw Exposes 400,000+ WordPress Sites to Account Takeover

    CVE-2026-19632 leaks a plaintext admin password-reset key via an unauthenticated AJAX action in TranslatePress, enabling full site takeover.

  • SecurityAug 25, 2026

    WordPress Jawn Theme Unauthenticated Privilege Escalation

    CVE-2026-78477 allows unauthenticated attackers to escalate to WordPress administrator in Jawn theme versions up to 1.4.2, CVSS 9.8 critical.

  • SecurityAug 23, 2026

    CVE-2026-0551: PHP Object Injection in PPWP – Password Protect Pages WordPress Plugin

    PPWP WordPress plugin up to 1.9.18 allows contributor-level PHP object injection via deserialization, enabling RCE on affected sites.

  • SecurityAug 23, 2026

    CVE-2026-16149: Security Hardener WordPress Plugin Bypasses All REST API Authorization

    Security Hardener plugin up to 2.4.4 overwrites REST endpoint permissions via rest_endpoints filter, bypassing all registered auth callbacks.

  • SecurityAug 22, 2026

    CVE-2026-78003: Critical SSRF via Path Traversal in Mailgun for WordPress Plugin

    A critical SSRF vulnerability (CVSS 9.8) in Mailgun for WordPress ≤ 2.2.0 lets unauthenticated attackers make server-side requests via path traversal.

  • SecurityAug 21, 2026

    CVE-2026-16576: Dokan WooCommerce Plugin Privilege Escalation to RCE

    A missing capability check in the Dokan multivendor WooCommerce plugin allows Shop Managers to install arbitrary plugins, leading to full site compromise.

  • NewsAug 20, 2026

    Critical Elementor Pro Bug Exposes WordPress Sites to RCE Attacks

    CVE-2026-32475 (CVSS 9.0): Unauthenticated attackers can upload PHP webshells via a loop desync flaw in Elementor Pro's file upload field.

  • SecurityAug 20, 2026

    Critical Unauthenticated RCE in JetEngine WordPress Plugin (CVE-2026-66613)

    A CVSS 9.8 unauthenticated remote code execution flaw in JetEngine plugin <= 3.8.14 lets attackers fully compromise WordPress sites.

  • SecurityAug 20, 2026

    Critical SQL Injection in Maps Marker Pro WordPress Plugin (CVE-2026-73183)

    An unauthenticated SQL injection flaw (CVSS 9.3) in Maps Marker Pro <= 4.32 exposes WordPress databases to full read and write access.

  • SecurityAug 20, 2026

    CVE-2026-75860: WordPress JSON Options Plugin Unauthenticated Options Update (CVSS 9.8)

    Critical WordPress plugin flaw lets unauthenticated attackers update arbitrary options, enabling privilege escalation and full site takeover.

  • SecurityAug 19, 2026

    Critical PHP Object Injection in FundEngine Plugin (CVE-2026-32470)

    An unauthenticated PHP Object Injection flaw (CVSS 9.8) in FundEngine <= 1.7.9 allows remote attackers to execute arbitrary code without credentials.

  • SecurityAug 19, 2026

    Critical File Upload RCE in Templatiq WordPress Plugin (CVE-2026-32474)

    CVE-2026-32474 allows Contributor-level users to upload arbitrary files in Templatiq <= 0.2.5, enabling remote code execution. CVSS score: 9.9.

  • NewsAug 17, 2026

    Forminator WordPress Plugin Flaw Enables Unauthenticated RCE via PHP Upload

    CVE-2026-15748 (CVSS 9.8) in Forminator Forms allows unauthenticated PHP webshell uploads for full RCE on 600,000+ WordPress sites. Patch to 1.56.2 now.

  • SecurityAug 17, 2026

    WordPress ARForms Plugin Critical PHP Object Injection — CVE-2024-13784

    A critical unauthenticated PHP object injection flaw in the ARForms WordPress plugin (CVSS 9.8) allows arbitrary code execution via deserialization.

  • SecurityAug 16, 2026

    CVE-2026-14498: Query Wrangler WordPress Plugin Exposes Sites to RCE

    A high-severity RCE flaw (CVSS 8.8) in the Query Wrangler WordPress plugin lets authenticated attackers inject and execute arbitrary PHP via a missing capability check.

  • SecurityAug 16, 2026

    CVE-2026-14524: Critical Unauthenticated File Deletion in ProSolution WP Client

    A CVSS 9.1 flaw in ProSolution WP Client lets unauthenticated attackers delete arbitrary files on WordPress servers, potentially wiping installations.

  • SecurityAug 16, 2026

    CVE-2026-15002: Stored XSS in Autopay WooCommerce Plugin for WordPress

    CVE-2026-15002 is a stored XSS flaw (CVSS 7.2) in the Autopay WooCommerce plugin, letting attackers inject persistent scripts via the CSS editor POST parameter.

  • SecurityAug 16, 2026

    CVE-2026-15142: Real Estate Manager Pro Privilege Escalation via Capability Confusion

    CVSS 7.5 flaw in Real Estate Manager Pro for WordPress lets attackers escalate privileges by exploiting an attachment ID and user ID confusion bug.

  • SecurityAug 16, 2026

    CVE-2026-16142: TrueBooker WordPress Plugin Unauthenticated Account Takeover

    A CVSS 9.8 flaw in TrueBooker for WordPress allows unauthenticated attackers to take over any user account via a vulnerable AJAX handler.

  • SecurityAug 16, 2026

    CVE-2026-18438: Templately WordPress Plugin RCE via File Upload

    CVSS 8.8 flaw in Templately for WordPress lets authenticated subscribers execute arbitrary code via a filename validation bypass in file upload.

  • SecurityAug 16, 2026

    CVE-2026-18855: WordPress Link Library Plugin Arbitrary File Deletion

    Critical CVSS 9.1 flaw in WordPress Link Library plugin allows unauthenticated attackers to delete arbitrary server files, risking full site takeover.

  • SecurityAug 16, 2026

    CVE-2026-19598: WordPress Pods Plugin Privilege Escalation via Authorization Bypass

    CVSS 9.8 flaw in WordPress Pods plugin lets unauthenticated users escalate privileges via a flawed AJAX authorization router in versions up to 3.3.9.

  • SecurityAug 15, 2026

    CVE-2026-14484: WordPress RapiSafe Plugin Arbitrary File Deletion

    Critical unauthenticated arbitrary file deletion in WordPress RapiSafe plugin v1.0.4 and below allows attackers to delete any file on the server.

  • SecurityAug 15, 2026

    CVE-2026-15162: WordPress Object Sync for Salesforce — SQLi via REST API

    High-severity unauthenticated SQL injection in Object Sync for Salesforce plugin allows attackers to extract data via a misconfigured REST API push endpoint.

  • SecurityAug 15, 2026

    CVE-2026-15303: WordPress 6Storage Rentals Authentication Bypass

    Critical authentication bypass in 6Storage Rentals WordPress plugin v2.27.0 allows unauthenticated users to create privileged accounts via exposed AJAX handler.

  • SecurityAug 15, 2026

    CVE-2026-15341: WordPress User Session Synchronizer — Account Takeover

    Critical auth bypass in User Session Synchronizer plugin v1.4.0 lets unauthenticated attackers hijack any WordPress account via session sync on every request.

  • SecurityAug 14, 2026

    CVE-2026-12949: Critical Account Takeover in WordPress Wishlist Member Plugin

    Critical CVSS 9.8 flaw in WordPress Wishlist Member plugin allows unauthenticated account takeover in versions up to 3.34.1.

  • SecurityAug 14, 2026

    CVE-2026-15413: WordPress 'Link Factory' Plugin Is an Intentional Backdoor (CVSS 10.0)

    The Link Factory WordPress plugin is a supply-chain backdoor. Operator-controlled REST API lets attackers run arbitrary commands. Remove it immediately.

  • SecurityAug 14, 2026

    CVE-2026-28154: Reflected XSS in WooCommerce WordPress Themes

    High-severity reflected XSS in Samex and M.Anh WooCommerce themes allows attackers to inject malicious scripts via crafted URLs.

  • SecurityAug 13, 2026

    CVE-2026-14182: WooCommerce Email Verification Bypass Allows Account Takeover

    A CVSS 9.8 type juggling flaw in Customer Email Verification for WooCommerce lets unauthenticated attackers take over any customer account.

  • SecurityAug 12, 2026

    CVE-2026-18961: WordPress VentraConnect Plugin Authentication Bypass

    High-severity auth bypass in the VentraConnect Social Login plugin allows unauthenticated attackers to take over any WordPress account.

  • NewsAug 11, 2026

    BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

    Cybersecurity researchers have uncovered a supply chain compromise targeting WordPress plugin vendor BdThemes, where attackers poisoned JSON configuration files to silently create rogue administrator accounts — without touching a single line of source code.

  • SecurityAug 10, 2026

    CVE-2026-14206: HT Contact Form WordPress Plugin Exposes Visitor PII to Unauthenticated Attackers

    The HT Contact Form plugin before 2.9.3 allows any unauthenticated user to read saved form drafts containing visitor names, emails, and physical addresses via a completely unprotected API endpoint.

  • SecurityAug 7, 2026

    CVE-2026-14205: WP Events Manager Plugin Allows Fraudulent Paid Event Bookings via Payment Bypass

    A critical improper authentication vulnerability in WP Events Manager for WordPress allows unauthenticated attackers to register for paid events without payment by manipulating the quantity parameter. Fixed in version 2.2.5.

  • SecurityAug 7, 2026

    CVE-2026-14364: TrueBooker WordPress Plugin Account Takeover via Password Reset Bypass

    A critical unauthenticated account takeover vulnerability in the TrueBooker Appointment Booking plugin for WordPress allows attackers to reset any user's password, including administrators, without verification. CVSS 9.8.

  • SecurityAug 7, 2026

    CVE-2026-14365: TrueBooker WordPress Plugin Authorization Bypass Enables Unauthenticated Password Change

    A second critical flaw in the TrueBooker Appointment Booking WordPress plugin allows unauthenticated attackers to change the password of any user, including administrators, due to missing authorization checks. CVSS 9.8.

  • SecurityAug 7, 2026

    ARVE WordPress Plugin Backdoor Grants Instant Admin Access to ~20,000 Sites

    A supply chain attack introduced a backdoor into ARVE – Advanced Responsive Video Embedder version 10.8.7, enabling any attacker to gain full WordPress admin access with a single HTTP request. Wordfence PRISM detected the compromise within two hours. The plugin has been removed from WordPress.org.

  • SecurityAug 7, 2026

    CVE-2026-28005: Critical Privilege Escalation in Kadence WooCommerce Email Designer

    A critical unauthenticated privilege escalation flaw (CVSS 9.8) in Kadence WooCommerce Email Designer <= 1.5.19 allows attackers to gain admin access with no credentials.

  • SecurityAug 7, 2026

    CVE-2026-28139: Critical PHP Object Injection in Ajax Search Lite

    A CVSS 9.8 unauthenticated PHP object injection flaw in Ajax Search Lite <= 4.14.4 exposes 80,000+ WordPress sites to potential remote code execution via POP chain gadgets.

  • SecurityAug 6, 2026

    CVE-2026-12713: Critical SQL Injection in WPCargo Track & Trace Plugin

    An unauthenticated SQL injection vulnerability (CVSS 9.1) in the WPCargo Track & Trace WordPress plugin before version 8.0.4 allows attackers to read and manipulate database contents without any credentials.

  • SecurityAug 2, 2026

    CVE-2026-13339: CubeWP Framework WordPress Plugin Directory Traversal (CVSS 7.5)

    A high-severity directory traversal vulnerability in the CubeWP Framework plugin for WordPress allows unauthenticated attackers to read arbitrary files on the server, potentially exposing credentials, configuration data, and sensitive application secrets.

  • SecurityAug 2, 2026

    CVE-2026-15964: WordPress SSO Plugin Critical Authentication Bypass

    The Single Sign On For TNG plugin for WordPress contains a critical authentication bypass (CVSS 9.8) allowing unauthenticated attackers to reset any user's password via a vulnerable AJAX handler. All versions up to 2.0.0 are affected.

  • SecurityAug 2, 2026

    CVE-2026-16144: Kali Forms WordPress Plugin Remote Code Execution

    The Kali Forms Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution (CVSS 8.1) in all versions up to 2.4.20. Insufficient validation of the thisPermalink field allows attackers to overwrite a trusted callable and execute arbitrary code.

  • SecurityAug 2, 2026

    CVE-2026-18352: WordPress User Access Manager Directory Traversal

    The User Access Manager plugin for WordPress (up to v2.3.15) is vulnerable to unauthenticated directory traversal via the 'uamgetfile' parameter, allowing attackers to read arbitrary files on the server.

  • SecurityAug 2, 2026

    CVE-2026-8457: WooCommerce Social Login Authentication Bypass (CVSS 9.8)

    A critical authentication bypass vulnerability in the WooCommerce - Social Login WordPress plugin allows unauthenticated attackers to log in as any registered user by exploiting a missing JWT signature verification in the Apple login handler.

  • SecurityAug 1, 2026

    CVE-2026-15414: WooCommerce Subscriptions Plugin Privilege Escalation (CVSS 8.8)

    A high-severity privilege escalation vulnerability in the Subscriptions for WooCommerce plugin allows authenticated users to elevate their role to administrator by manipulating membership plan metadata.

  • SecurityAug 1, 2026

    CVE-2026-3141: WordPress FormGent Plugin Unauthorized File Deletion (CVSS 9.1)

    A critical unauthenticated file deletion vulnerability in the FormGent WordPress plugin allows attackers to delete arbitrary files without authentication, potentially leading to full site compromise.

  • SecurityJul 31, 2026

    CVE-2026-15397: Missing Authorization in Subscriptions for WooCommerce Plugin

    A missing authorization vulnerability in the Subscriptions for WooCommerce plugin allows authenticated users with minimal privileges to perform unauthorized actions on WordPress sites running versions up to 2.0.0.

  • SecurityJul 30, 2026

    CVE-2025-10656: WooCommerce Plugin Missing Authorization Allows Unauthenticated Admin Account Creation

    A critical missing authorization vulnerability in the Spreadsheet Price Changer for WooCommerce plugin allows unauthenticated attackers to create admin accounts on affected WordPress sites, scoring a near-perfect CVSS 9.8.

  • SecurityJul 30, 2026

    CVE-2026-16610: Critical RCE in WordPress Admin & Site Enhancements Pro Plugin

    A CVSS 9.8 unauthenticated remote code execution vulnerability in the Admin and Site Enhancements (ASE) Pro WordPress plugin allows attackers to execute arbitrary code via a publicly accessible nonce bypass in the recursive_html function.

  • SecurityJul 29, 2026

    CVE-2026-13423: Streamit WordPress Theme Allows Unauthenticated Arbitrary PHP Function Execution

    The Streamit WordPress theme through version 4.5.0 exposes an unauthenticated AJAX route with no authorization or nonce verification, letting any anonymous visitor call arbitrary PHP functions with attacker-controlled arguments — a critical CVSS 9.8 flaw.

  • SecurityJul 28, 2026

    CVE-2026-14545: TrueBooker WordPress Plugin Lets Anyone Take Over Admin Accounts

    An unauthenticated password reset flaw in TrueBooker (before v1.2.4) lets any attacker set an arbitrary password on any WordPress account — including administrators — and take full control of the site.

  • SecurityJul 28, 2026

    CVE-2026-59527: Critical SQL Injection in MapSVG WordPress Plugin

    A CVSS 9.3-rated unauthenticated SQL injection vulnerability in the MapSVG WordPress plugin (versions up to 8.14.0) allows remote attackers to read and manipulate the underlying database without any login credentials.

  • NewsJul 27, 2026

    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    Attackers are actively chaining CVE-2026-60137 and CVE-2026-63030 just three days after disclosure, targeting one of the largest attack surfaces on the internet.

  • SecurityJul 27, 2026

    CVE-2026-12394: MemberGlut Plugin Lets Anyone Register as WordPress Admin

    A critical privilege escalation flaw in the MemberGlut WordPress plugin allows unauthenticated users to register with any role — including administrator — leading to full site compromise.

  • SecurityJul 27, 2026

    CVE-2026-13332: Masteriyo LMS Allows Unauthenticated Force-Logout of Any User

    A critical unauthenticated AJAX vulnerability in the Masteriyo LMS WordPress plugin allows attackers to terminate any user's session — including administrators — without any credentials.

  • SecurityJul 27, 2026

    CVE-2026-13597: WeChat QR Login WordPress Plugin Authentication Bypass

    A critical authentication bypass in the WeChat QR login WordPress plugin allows unauthenticated attackers to forge login events for any account — the webhook signature check always passes and login codes are leaked in responses.

  • SecurityJul 27, 2026

    CVE-2026-13714: Realtyna IDX Plugin Unauthenticated File Upload via Hardcoded Credentials

    A critical CVSS 9.8 unauthenticated arbitrary file upload vulnerability in the Realtyna Organic IDX + WPL Real Estate WordPress plugin (before v5.3.0) exploits hardcoded credentials shipped identically across all installations.

  • SecurityJul 27, 2026

    CVE-2026-14289: FacturaONE WooCommerce Plugin Allows Unauthenticated File Write

    A critical unauthenticated arbitrary file write vulnerability in the FacturaONE para WooCommerce con VeriFactu plugin (before v5.37) allows attackers to write arbitrary files due to an empty cryptographic key in the default unconfigured state.

  • SecurityJul 26, 2026

    CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)

    A high-severity PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress allows authenticated attackers with Subscriber-level access to inject PHP objects and potentially achieve remote code execution via a POP chain in versions up to 6.2.6.

  • SecurityJul 25, 2026

    CVE-2026-10818: WPForms Pro Arbitrary File Upload — Unauthenticated RCE

    A high-severity vulnerability in WPForms Pro allows unauthenticated attackers to upload malicious files and achieve remote code execution. File type...

  • SecurityJul 24, 2026

    CVE-2026-12877: Critical SQL Injection in WordPress Project Management Plugin

    An unauthenticated SQL injection flaw with a CVSS score of 9.1 affects the Project Management, Bug and Issue Tracking Plugin for WordPress before version...

  • SecurityJul 24, 2026

    GoDAM WordPress Plugin Arbitrary File Upload — CVE-2026-14282

    A critical unauthenticated arbitrary file upload vulnerability in the GoDAM WordPress media library plugin allows attackers to upload malicious files and...

  • SecurityJul 24, 2026

    WordPress Helpdesk Plugin Unauthenticated Code Injection — CVE-2026-15011

    A critical unauthenticated PHP code injection vulnerability in the Customer Support Ticket System & Helpdesk WordPress plugin allows attackers to execute...

  • SecurityJul 24, 2026

    CVE-2026-15981: WordPress SAML SSO Authentication Bypass (CVSS 9.8)

    A critical authentication bypass in the WordPress SAML Single Sign On plugin allows unauthenticated attackers to log in as any user, including...

  • SecurityJul 23, 2026

    CVE-2026-14291: WordPress Security Ninja Premium 2FA Authentication Bypass

    The Security Ninja Premium WordPress plugin before version 5.290 contains a critical authentication flaw that allows attackers to bypass two-factor...

  • SecurityJul 22, 2026

    CVE-2026-65048: Ninja Forms Unauthenticated Stored XSS via Repeatable Fieldset

    A CVSS 9.3 critical stored XSS vulnerability in the Ninja Forms WordPress plugin affects versions 3.10.4 through 3.14.9. The flaw requires no...

  • SecurityJul 22, 2026

    CVE-2026-65049: Ninja Forms Multisite Flaw Enables Network-Wide Data Deletion

    A CVSS 9.3 critical incorrect authorization vulnerability in Ninja Forms 3.14.8 and prior for WordPress Multisite allows a subsite administrator to...

  • NewsJul 21, 2026

    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    Attackers are exploiting two chained critical WordPress vulnerabilities that enable unauthenticated remote code execution. A public exploit has triggered...

  • SecurityJul 21, 2026

    CVE-2026-13439: WordPress Easy Form Builder Unauthenticated Privilege Escalation (CVSS 9.8)

    A critical unauthenticated privilege escalation vulnerability in the Easy Form Builder by WhiteStudio WordPress plugin allows attackers to reset admin...

  • NewsJul 20, 2026

    Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

    A single request shouldn't be able to do this much. This week delivered pre-authenticated WordPress RCE, dual SonicWall zero-days exploited since June, a...

  • SecurityJul 20, 2026

    CVE-2026-10081: Unlimited Elements for Elementor Stored XSS via Google Reviews

    A stored cross-site scripting vulnerability in the Unlimited Elements for Elementor WordPress plugin (before 2.0.11) allows unauthenticated attackers to...

  • SecurityJul 20, 2026

    CVE-2026-13147: Kirki WordPress Plugin SSRF Allows Unauthenticated Internal Network Scanning

    A server-side request forgery vulnerability in the Kirki Customizer Framework WordPress plugin before 6.0.12 allows unauthenticated attackers to make the...

  • NewsJul 18, 2026

    WordPress Core "wp2shell" RCE Flaws Get Public Exploits — Patch Now

    Public exploits have been released for the critical wp2shell remote code execution vulnerabilities in WordPress Core, putting millions of sites at...

  • NewsJul 17, 2026

    New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

    A critical unauthenticated remote code execution vulnerability in WordPress core affects all 6.9 and 7.0 installations. WordPress force-pushed emergency...

  • SecurityJul 17, 2026

    CVE-2026-15103: WPFunnels Plugin Privilege Escalation via Unauthenticated REST Endpoint

    A high-severity privilege escalation flaw in WPFunnels for WordPress allows attackers to update arbitrary site options via an unvalidated REST callback,...

  • SecurityJul 17, 2026

    CVE-2026-15982: WordPress Aimogen Pro Plugin Privilege Escalation (CVSS 9.8)

    Critical privilege escalation in the Aimogen Pro WordPress plugin (all versions up to 2.8.4) — missing capability check on AI function allows any...

  • SecurityJul 16, 2026

    CVE-2026-12492: WooCommerce OTP Login Plugin Auth Bypass — Full Admin Takeover

    The Happy Coders OTP Login for WooCommerce plugin before 2.8 allows unauthenticated attackers to bypass OTP verification and log in as any WordPress user,...

  • SecurityJul 16, 2026

    CVE-2026-15013: WordPress SAML SSO Plugin — Algorithm Confusion Auth Bypass

    The miniOrange SAML Single Sign On plugin for WordPress through version 5.4.3 allows unauthenticated attackers to log in as any user via an RSA-to-HMAC...

  • NewsJul 15, 2026

    We Built a Vulnerability Vending Machine: AI Tokens In, Zero-Days Out

    Security firm Intruder built an AI-powered system that combines code slicing with large language models to automatically discover complex software...

  • SecurityJul 13, 2026

    CVE-2026-11964: WordPress User Registration Plugin PayPal Webhook Bypass

    The User Registration & Membership WordPress plugin before 5.2.2 fails to verify PayPal webhook signatures, allowing unauthenticated attackers to forge...

  • NewsJul 11, 2026

    Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

    The Australian Cyber Security Centre has issued an alert about a coordinated global campaign actively exploiting unpatched vulnerabilities in WordPress,...

  • SecurityJul 11, 2026

    CVE-2026-12761: miniOrange WordPress Social Login Auth Bypass Enables Full Admin Takeover

    A critical authentication bypass chain in the miniOrange Social Login and Register WordPress plugin allows unauthenticated attackers to crack a trivially...

  • SecurityJul 11, 2026

    CVE-2026-13353: WordPress WP Ultimate CSV Importer RCE via MappedFields Parameter

    A critical CVSS 8.8 remote code execution vulnerability in WP Ultimate CSV Importer allows unauthenticated attackers to execute arbitrary PHP code on...

  • NewsJul 10, 2026

    Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

    An unprotected 800MB server left open for three weeks exposed the full toolkit of a webshell access brokerage operation targeting 1.4 million domains....

  • SecurityJul 10, 2026

    CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload

    A critical unauthenticated arbitrary file upload vulnerability in the Super Forms plugin for WordPress (CVSS 9.8) allows attackers to upload and execute...

  • SecurityJul 10, 2026

    CVE-2026-15158: WordPress Blocksy Companion Arbitrary File Upload (CVSS 9.8)

    A critical arbitrary file upload vulnerability in the Blocksy Companion WordPress plugin (versions up to 2.1.46) allows unauthenticated attackers to...

  • SecurityJul 10, 2026

    CVE-2026-15282: WordPress Instant Appointment Plugin Critical File Upload

    A critical unauthenticated arbitrary file upload flaw (CVSS 9.8) in the Instant Appointment WordPress plugin allows attackers to upload and execute...

  • SecurityJul 8, 2026

    CVE-2026-12153: WP Learn Manager Plugin — Unauthenticated Authorization Bypass Allows Plugin Installation

    A critical CVSS 9.8 authorization bypass in the WP Learn Manager WordPress plugin allows unauthenticated attackers to install and activate arbitrary...

  • SecurityJul 8, 2026

    CVE-2026-14487: WordPress Simple Coherent Form Plugin — Critical Unauthenticated File Deletion

    A critical CVSS 9.1 vulnerability in the Simple Coherent Form WordPress plugin allows unauthenticated attackers to delete arbitrary files on the server,...

  • SecurityJul 8, 2026

    CVE-2026-9701: WordPress Eventer Plugin — Insecure Password Reset Enables Account Takeover

    A critical CVSS 9.8 vulnerability in the Eventer WordPress plugin exposes plaintext password reset keys in user meta, allowing unauthenticated attackers...

  • SecurityJul 6, 2026

    CVE-2024-6228: WordPress WANotifier Plugin Local File Inclusion

    A local file inclusion vulnerability in the WANotifier WordPress plugin (before v2.6) allows any authenticated subscriber-level user to include and...

  • SecurityJul 4, 2026

    CVE-2026-4321: Critical SQL Injection in Raera Destekz Plugin (No Patch Available)

    A CVSS 9.8 critical SQL injection in the Destekz plugin by Raera - Ankara Web Design allows unauthenticated remote attackers full database access. The...

  • SecurityJul 3, 2026

    CVE-2026-9725: Critical WordPress WooCommerce Plugin File Deletion

    A CVSS 9.1 critical unauthenticated arbitrary file deletion vulnerability in the Printcart Web to Print Product Designer for WooCommerce plugin affects...

  • SecurityJul 1, 2026

    CVE-2026-12923: YouTube Showcase WordPress Plugin Arbitrary Function Call

    A high-severity arbitrary function call vulnerability in the YouTube Showcase plugin allows authenticated attackers to invoke arbitrary PHP functions via...

  • SecurityJul 1, 2026

    CVE-2026-9711: Critical SQL Injection in EventON WordPress Plugin (CVSS 9.8)

    A critical unauthenticated SQL injection vulnerability in the EventON WordPress Virtual Event Calendar Plugin affects versions up to 5.0.11, exposing...

  • SecurityJun 30, 2026

    CVE-2026-12073: ProfileGrid WordPress Plugin Critical Privilege Escalation

    A critical CVSS 9.8 vulnerability in the ProfileGrid WordPress plugin allows unauthenticated attackers to take over any user account and escalate...

  • SecurityJun 30, 2026

    CVE-2026-57331: Critical Arbitrary File Deletion in Paid Videochat Turnkey Site

    A CVSS 9.9 critical vulnerability in the Paid Videochat Turnkey Site WordPress plugin allows authenticated performer-role users to delete arbitrary files...

  • SecurityJun 28, 2026

    CVE-2026-8095: WordPress Frontend File Manager Plugin Allows Arbitrary File Deletion

    A high-severity authenticated file deletion vulnerability in the nmedia Frontend File Manager Plugin for WordPress allows subscribers to delete any file...

  • SecurityJun 27, 2026

    CVE-2026-12415: WordPress Invoice Generator Privilege Escalation (CVSS 9.8)

    A critical unauthenticated privilege escalation flaw in the WordPress Invoice Generator plugin allows any attacker to take over administrator accounts via...

  • SecurityJun 27, 2026

    CVE-2026-54820: Critical SQL Injection in JetBooking WordPress Plugin

    A critical unauthenticated SQL injection vulnerability (CVSS 9.3) in the JetBooking WordPress plugin affects all versions up to 4.0.4.1, potentially...

  • NewsletterJun 23, 2026

    June 23 Digest: FortiBleed, Klue/Salesforce Supply Chain, Squidbleed, GitHub Actions Fix

    A Russian IAB harvests 110M credentials from FortiGate firewalls; the Icarus group drains hundreds of Salesforce orgs via Klue OAuth tokens; a 29-year-old...

  • NewsJun 22, 2026

    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

    Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack, with attackers injecting backdoor code into Pro plugin releases...

  • NewsJun 21, 2026

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    Active exploitation of CVE-2026-4020 in the Gravity SMTP WordPress plugin has generated over 17 million malicious requests, allowing unauthenticated...

  • NewsJun 19, 2026

    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

    In a major Operation Endgame action, law enforcement and private partners seized 106 SocGholish command-and-control servers and domains, with...

  • NewsJun 19, 2026

    Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

    A joint law enforcement operation led by Dutch authorities and including partners from Canada, Germany, and the US has disrupted SocGholish malware...

  • SecurityJun 19, 2026

    CVE-2026-7515: BetterDocs Pro WordPress Plugin — Unauthenticated Local File Inclusion

    A critical Local File Inclusion vulnerability in the BetterDocs Pro WordPress plugin (up to v3.8.0) allows unauthenticated attackers to include and...

  • NewsJun 18, 2026

    Police Cleans Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp

    International law enforcement cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish...

  • NewsJun 18, 2026

    ShapedPlugin Update Flow Hacked to Infect WordPress Sites

    Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the...

  • SecurityJun 17, 2026

    CVE-2026-49772: The Events Calendar Blind SQL Injection (CVSS 9.3)

    A critical blind SQL injection vulnerability in The Events Calendar WordPress plugin by StellarWP affects versions 6.15.12 through 6.16.2, allowing...

  • SecurityJun 17, 2026

    CVE-2026-49774: RD Station WordPress Plugin Remote Code Injection (CVSS 9.9)

    A critical code injection vulnerability in the RD Station WordPress plugin allows unauthenticated remote code execution through Remote File Inclusion,...

  • SecurityJun 17, 2026

    CVE-2026-52715: GEO my WordPress Unauthenticated SQL Injection (CVSS 9.3)

    A critical unauthenticated SQL injection vulnerability in GEO my WordPress versions 4.5.5 and earlier allows attackers to extract database contents...

  • NewsletterJun 17, 2026

    June 17 Digest: Teams C2 Evasion, Copilot Data Theft, iRhythm Breach, cPanel KEV

    DragonForce hides C2 inside Microsoft Teams relay traffic; a SearchLeak attack weaponizes M365 Copilot for one-click data exfiltration; iRhythm confirms...

  • NewsJun 16, 2026

    'Lorem Ipsum' Malware Pivots to ClickFix Delivery via WordPress

    New analysis reveals the 'Lorem Ipsum' malware campaign has adopted ClickFix social engineering as its primary delivery mechanism, leveraging compromised...

  • SecurityJun 16, 2026

    CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload

    WordPress CP Polls plugin version 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through...

  • SecurityJun 16, 2026

    CVE-2026-27053: Critical PHP Object Injection in Broadcast Live Video Plugin

    A critical unauthenticated PHP Object Injection vulnerability in the Broadcast Live Video WordPress plugin (versions < 7.1.3) carries a CVSS score of 9.8...

  • SecurityJun 16, 2026

    CVE-2026-39574: Critical SQL Injection in InPost Gallery WordPress Plugin

    A critical unauthenticated SQL injection vulnerability (CVSS 9.3) in the InPost Gallery WordPress plugin allows attackers to extract sensitive database...

  • SecurityJun 16, 2026

    CVE-2026-6933: Unauthenticated RCE in Premmerce Dev Tools WordPress Plugin

    A high-severity unauthenticated remote code execution vulnerability (CVSS 8.8) in Premmerce Dev Tools for WordPress allows attackers to execute arbitrary...

  • SecurityJun 15, 2026

    CVE-2026-8935: WP Maps Pro Unauthenticated Admin Account Creation (CVSS 9.8)

    A critical unauthenticated vulnerability in the WP Maps Pro WordPress plugin before 6.1.1 allows any visitor to create an administrator account and...

  • SecurityJun 14, 2026

    CVE-2026-5513: Bookly WordPress Plugin Stored XSS via Cookie

    The Bookly scheduling plugin for WordPress contains a stored cross-site scripting vulnerability in versions up to 27.2, allowing unauthenticated attackers...

  • SecurityJun 12, 2026

    CVE-2026-47365: WordPress Toolkit Argument Injection in cPanel & WHM

    A critical CVSS 9.9 argument injection vulnerability in WordPress Toolkit before 6.11.0 allows remote authenticated users to bypass cross-tenant...

  • SecurityJun 11, 2026

    CVE-2025-6254: WordPress Doctreat Core Plugin Privilege Escalation (CVSS 9.8)

    A critical unauthenticated privilege escalation vulnerability in the Doctreat Core WordPress plugin allows attackers to register with elevated roles,...

  • NewsJun 6, 2026

    Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

    Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, enabling them to take complete control of…

  • SecurityJun 6, 2026

    CVE-2026-7537: MDJM Event Management WordPress Plugin Arbitrary File Upload

    A high-severity arbitrary file upload vulnerability in the MDJM Event Management plugin for WordPress allows authenticated attackers to upload malicious files…

  • SecurityJun 6, 2026

    CVE-2026-7654: PHP Object Injection RCE in WordPress Admin Columns Plugin (≤ 7.0.18)

    A high-severity PHP Object Injection vulnerability in the Admin Columns WordPress plugin (versions up to 7.0.18) allows authenticated attackers to achieve…

  • SecurityJun 6, 2026

    CVE-2026-9851: WordPress Booking Package Plugin Privilege Escalation via Account Takeover

    A high-severity privilege escalation vulnerability in the Booking Package WordPress plugin allows unauthenticated or low-privileged attackers to take over…

  • SecurityJun 5, 2026

    CVE-2026-49777: CVSS 10 Flaw in WooCommerce Product Slider Pro Enables Malware Implantation

    A maximum-severity input validation vulnerability in Product Slider Pro for WooCommerce allows attackers to implant malicious software. Affects all versions…

  • NewsJun 3, 2026

    Critical Kirki Flaw Exploited to Hijack WordPress Admin Accounts

    Hackers are actively exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the widely-used Kirki Customizer Framework plugin for…

  • SecurityJun 2, 2026

    CVE-2026-8206: Kirki WordPress Plugin Critical Privilege Escalation via Account Takeover

    The Kirki Freeform Page Builder plugin for WordPress (versions 6.0.0–6.0.6) allows unauthenticated attackers to take over any user account during password…

  • SecurityJun 2, 2026

    CVE-2026-8293: Really Simple Security WordPress Plugin 2FA Authentication Bypass

    The Really Simple Security WordPress plugin before 9.5.10.1 fails to enforce the second-factor challenge on two REST API endpoints, allowing attackers with a…

  • NewsMay 31, 2026

    WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

    Hackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin that allows unauthenticated attackers to create rogue…

  • SecurityMay 30, 2026

    CVE-2026-4290: WP Travel Pro Arbitrary User Deletion via Broken REST API Access Control

    A critical CVSS 9.1 access control flaw in the WP Travel Pro WordPress plugin allows unauthenticated attackers to delete any user account — including...

  • SecurityMay 30, 2026

    CVE-2026-7459: WordPress Simple History Plugin Account Takeover

    A broken authentication check in the Simple History WordPress plugin (versions up to 5.26.0) allows Subscriber-level users to take over any WordPress...

  • SecurityMay 30, 2026

    CVE-2026-7465: RCE in Spectra Gutenberg Blocks WordPress Plugin (CVSS 8.8)

    A high-severity remote code execution vulnerability in the Spectra Gutenberg Blocks plugin for WordPress allows authenticated Contributor-level attackers...

  • SecurityMay 30, 2026

    CVE-2026-9757: GEO my WP Plugin SQL Injection via Query String Bypass

    The GEO my WP WordPress plugin (versions up to 4.5.5) is vulnerable to unauthenticated SQL injection via the swlatlng and nelatlng parameters, which...

  • SecurityMay 29, 2026

    CVE-2026-3655: OTP Login WordPress Plugin Auth Bypass via Firebase Session Mismatch

    A critical authentication bypass (CVSS 9.8) in the OTP Login With Phone Number WordPress plugin allows unauthenticated attackers to log in as any user due...

  • SecurityMay 29, 2026

    CVE-2026-8732: WP Maps Pro Privilege Escalation via Admin Account Creation

    A critical unauthenticated privilege escalation flaw in WP Maps Pro for WordPress (CVSS 9.8) allows attackers to create administrator accounts without...

  • SecurityMay 22, 2026

    CVE-2026-39531: WP Directory Kit Blind SQL Injection (CVSS

    A critical blind SQL injection vulnerability in the WP Directory Kit WordPress plugin allows unauthenticated attackers to exfiltrate the entire WordPress...

  • SecurityMay 22, 2026

    WP ERP Pro SQL Injection via search_key Parameter

    A CVSS 7.5 SQL injection vulnerability in the WP ERP Pro WordPress plugin (all versions up to 1.5.1) allows unauthenticated attackers to extract sensitive...

  • SecurityMay 21, 2026

    CVE-2026-6279: Avada Builder Unauthenticated RCE via PHP

    A critical CVSS 9.8 vulnerability in the Avada Builder (fusion-builder) WordPress plugin allows unauthenticated attackers to execute arbitrary PHP...

  • SecurityMay 20, 2026

    CVE-2026-7637: WordPress Boost Plugin PHP Object Injection

    The Boost plugin for WordPress versions up to 2.0.3 is vulnerable to PHP Object Injection via deserialization of the STYXKEY-BOOST_USER_LOCATION cookie,...

  • SecurityMay 19, 2026

    CVE-2025-15609: Fortis for WooCommerce Plugin Leaks API

    The Fortis for WooCommerce WordPress plugin before version 1.3.1 exposes sensitive API keys to unauthenticated attackers, enabling unauthorized access to...

  • SecurityMay 17, 2026

    CVE-2026-8719: WordPress AI Engine Plugin Privilege

    A missing WordPress capability check in the AI Engine plugin's MCP OAuth bearer-token path allows any authenticated user to escalate privileges to...

  • NewsMay 16, 2026

    Funnel Builder Flaw Under Active Exploitation Enables

    Attackers are actively exploiting a critical vulnerability in the Funnel Builder WordPress plugin to inject malicious JavaScript into WooCommerce checkout...

  • SecurityMay 16, 2026

    WordPress Form Notify Plugin Auth Bypass via LINE OAuth

    The Form Notify plugin for WordPress is vulnerable to authentication bypass in versions up to and including 1.1.10. Attackers can manipulate...

  • NewsMay 15, 2026

    Avada Builder WordPress Plugin Flaws Allow Site Credential

    Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files...

  • NewsMay 15, 2026

    Funnel Builder WordPress Plugin Bug Exploited to Steal

    A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript into WooCommerce checkout...

  • SecurityMay 15, 2026

    Critical Auth Bypass in InfusedWoo Pro Enables

    A CVSS 9.1 authorization bypass in InfusedWoo Pro for WordPress lets unauthenticated attackers permanently delete arbitrary data across all installations...

  • SecurityMay 13, 2026

    CVE-2026-2993: SQL Injection in AIWU AI Chatbot WordPress

    A high-severity SQL injection vulnerability (CVE-2026-2993) in the AI Chatbot & Workflow Automation by AIWU WordPress plugin allows unauthenticated...

  • SecurityMay 11, 2026

    CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege

    TheCartPress WordPress plugin 1.5.3.6 allows unauthenticated attackers to register new administrator accounts by exploiting the AJAX handler with a...

  • SecurityMay 11, 2026

    CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File

    MStore API 2.0.6 for WordPress allows unauthenticated attackers to upload arbitrary PHP files via the REST API config_file endpoint, achieving remote code...

  • SecurityMay 11, 2026

    CVE-2026-6433: WordPress Plugin SQLi Enables

    The Custom css-js-php WordPress plugin through version 2.0.7 fails to sanitize user input before using it in a SQL query, and passes the result to dynamic...

  • SecurityMay 3, 2026

    CVE-2026-5324: WordPress Brizy Page Builder Unauthenticated

    The Brizy Page Builder plugin for WordPress contains a critical unauthenticated Stored Cross-Site Scripting flaw in versions up to 2.8.11, enabling...

  • SecurityMay 2, 2026

    CVE-2026-4882: Unauthenticated File Upload in WordPress

    A critical unauthenticated arbitrary file upload vulnerability in the User Registration Advanced Fields plugin for WordPress allows attackers to upload...

  • SecurityMay 2, 2026

    CVE-2026-7458: Authentication Bypass via OTP Flaw in WordPress User Verification Plugin

    A critical authentication bypass in the User Verification by PickPlugins plugin for WordPress allows unauthenticated attackers to bypass OTP verification...

  • SecurityMay 1, 2026

    Critical Authentication Bypass in WordPress Temporary Login

    A critical CVSS 9.8 authentication bypass in the WordPress Temporary Login plugin (versions up to 1.0.0) allows unauthenticated attackers to gain...

  • SecurityApr 30, 2026

    CVE-2026-41940: WebPros cPanel & WHM and WP2 Missing

    WebPros cPanel, WHM, and WP2 (WordPress Squared) contain a critical authentication bypass in the login flow, allowing unauthenticated remote attackers to...

  • SecurityApr 24, 2026

    CVE-2026-39440: FunnelFormsPro WordPress Plugin Remote Code

    A critical code injection vulnerability in the FunnelFormsPro WordPress plugin through version 3.8.1 allows remote code inclusion, enabling attackers to...

  • NewsApr 23, 2026

    Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

    Threat actors are mass-exploiting a critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin, uploading PHP webshells to...

  • SecurityApr 23, 2026

    CVE-2026-3844 — Breeze Cache WordPress Plugin

    A critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin allows attackers to upload arbitrary files to affected servers...

  • SecurityApr 23, 2026

    CVE-2026-4119: WordPress Create DB Tables Plugin

    A critical CVSS 9.1 authorization bypass in the WordPress Create DB Tables plugin (all versions up to 1.2.1) allows unauthenticated users to create or...

  • SecurityApr 18, 2026

    CVE-2026-6518: WordPress CMP Plugin Arbitrary File Upload

    The CMP Coming Soon & Maintenance Plugin for WordPress contains a critical arbitrary file upload flaw that allows subscriber-level authenticated users to...

  • SecurityApr 17, 2026

    CVE-2026-6443: WordPress Accordion Plugin Backdoor in Version 1.4.6

    The Accordion and Accordion Slider WordPress plugin version 1.4.6 was sold to a malicious threat actor who embedded a persistent backdoor, granting...

  • SecurityApr 9, 2026

    CVE-2026-1830: WordPress Quick Playground Plugin RCE via Unauthenticated File Upload

    A critical CVSS 9.8 vulnerability in the Quick Playground WordPress plugin (versions up to 1.3.1) allows unauthenticated attackers to upload arbitrary...

  • SecurityApr 8, 2026

    CVE-2026-4003: WordPress Users Manager PN Plugin Privilege

    A critical privilege escalation vulnerability in the Users Manager – PN WordPress plugin (v1.1.15 and below) allows unauthenticated attackers to update...

  • NewsApr 7, 2026

    Hackers Exploit Critical Flaw in Ninja Forms WordPress

    Attackers are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms File Uploads premium add-on for...

  • NewsletterApr 7, 2026

    Apr 7 Digest: Medusa Ransomware Surge, FBI $21B Record

    Storm-1175 runs sub-24-hour Medusa ransomware campaigns using zero-days; the FBI IC3 reports a record $21 billion in US cybercrime losses for 2025; North...

  • SecurityApr 4, 2026

    CVE-2026-3445: ProfilePress WordPress Plugin Allows

    A high-severity authorization flaw in the ProfilePress WordPress plugin (up to v4.16.11) lets unauthenticated or low-privilege users bypass membership...

  • SecurityApr 4, 2026

    CVE-2026-4896: WCFM WooCommerce Plugin IDOR Allows

    A high-severity Insecure Direct Object Reference vulnerability in the WCFM Frontend Manager for WooCommerce plugin (up to v6.7.25) lets authenticated...

  • SecurityApr 2, 2026

    CVE-2026-1540: Spam Protect CF7 WordPress Plugin PHP Log RCE

    The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows an editor-level attacker to achieve Remote Code Execution by logging a crafted...

  • NewsMar 29, 2026

    File Read Flaw in Smart Slider Plugin Impacts 500K

    A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, allows subscriber-level users to read arbitrary files on the...

  • SecurityMar 28, 2026

    CVE-2025-12886: Oxygen Theme SSRF Allows Unauthenticated

    A Server-Side Request Forgery vulnerability in the Oxygen Theme plugin for WordPress (all versions up to 6.0.8) enables unauthenticated attackers to make...

  • SecurityMar 22, 2026

    CVE-2026-3629: WordPress User Import Plugin Privilege

    The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to 1.29.7, allowing authenticated...

  • SecurityMar 19, 2026

    CVE-2026-25449: Critical Object Injection in Shinetheme

    A CVSS 9.8 deserialization vulnerability in the Shinetheme Traveler WordPress plugin allows unauthenticated remote attackers to inject arbitrary PHP...

  • SecurityMar 11, 2026

    Critical Auth Bypass in Tutor LMS Pro Exposes 30,000+

    The Tutor LMS Pro WordPress plugin's Social Login addon fails to verify OAuth token email matches the login request, allowing unauthenticated attackers to...

  • SecurityMar 7, 2026

    CVE-2026-3589: WooCommerce CSRF Flaw Allows Unauthenticated

    A cross-site request forgery vulnerability in WooCommerce versions 5.4.0 through 10.5.2 allows attackers to abuse the Store API's batch endpoint to...

  • SecurityFeb 12, 2026

    Critical RCE in WPvivid Backup Plugin Threatens 900,000+

    A critical unauthenticated arbitrary file upload vulnerability in the WPvivid Backup & Migration plugin allows remote code execution on over 900,000...

  • SecurityJan 25, 2026

    WordPress Plugin Vulnerability (CVSS 10.0) Under Active

    Maximum severity flaw in Modular DS WordPress plugin allows unauthenticated privilege escalation. All versions through 2.5.1 affected with active...