2026-06-01Urgent: DeMomentSomTres Shortcodes (<= 1.1.1) — Authenticated Contributor Stored XSS (CVE-2026-8885) — What WordPress Site Owners Need to KnowRead article →
2026-06-01Urgent: Cross-Site Scripting (XSS) in WordPress Favicon Plugin (≤1.3.46) — What Site Owners Must Do Right NowRead article →
2026-06-01Urgent: Arbitrary File Deletion in WebinarIgnition Plugin (< 4.08.253) — What WordPress Site Owners Must Do NowRead article →
2026-06-01Urgent Security Advisory: Arbitrary File Upload (CVE-2026-9009) in Crawlomatic Multisite Scraper Post Generator — What WordPress Site Owners Must Do NowRead article →
2026-06-01QuickWebP Arbitrary File Deletion (CVE-2026-42756) — What WordPress Site Owners Must Do NowRead article →
2026-06-01HT Contact Form <= 2.8.2 — Unauthenticated Stored XSS via File Upload Field (CVE-2026-7052) — What WordPress Site Owners & Developers Must Do NowRead article →
2026-06-01CVE-2026-9599 (Tectite Forms <= 1.3) — What WordPress Site Owners Must Know and How to Protect Their SitesRead article →
2026-06-01CVE-2026-8422: CSRF in “Remove meta boxes per user role” (≤ 1.01) — What WordPress site owners must do nowRead article →
2026-06-01CSRF in Laiser Tag (≤1.2.5) — What WordPress Site Owners Must Know and How WP‑Firewall Protects YouRead article →
2026-06-01Broken Authentication in “Backup and Staging by WP Time Capsule” (≤ 1.22.25) — What WordPress Owners Must Do NowRead article →
2026-06-01Broken Access Control in Slider Revolution (CVE-2026-9050) — What WordPress Site Owners Must Do NowRead article →