2026-06-01Broken Access Control in Slider Revolution (CVE-2026-9048) — What WordPress Site Owners Need to Do NowRead article →
2026-06-01Authenticated Author Arbitrary File Upload in GutenBee (≤2.20.1) — What WordPress Site Owners Must Do NowRead article →
2026-06-01Authenticated (Author) Stored XSS in “Auto Image Attributes From Filename With Bulk Updater” (≤ 4.9) — What WordPress Site Owners Need to Know and Do NowRead article →
2026-06-01ACF (<= 6.8.1) Broken Access Control — What WordPress Site Owners Must Do NowRead article →
2026-05-22When a WordPress Vulnerability Alert Appears: A Practical, Expert Guide from the WP‑Firewall TeamRead article →
2026-05-22Urgent: What WordPress Site Owners Must Do After a Recent Login-Related Vulnerability AlertRead article →
2026-05-22Broken Access Control in “Location Weather” WordPress Plugin (CVE-2026-7249) — What Site Owners Need to Know and Do Right NowRead article →
2026-05-21WordPress Zoho ZeptoMail plugin (≤ 3.2.9) — Broken Access Control (CVE‑2025‑67972): What site owners must know and do nowRead article →
2026-05-21Urgent: Unauthenticated SQL Injection in Creative Mail <= 1.6.9 — What WordPress Site Owners Must Do NowRead article →
2026-05-21Urgent: Kirki Plugin (≤ 6.0.6) Arbitrary File Read & Deletion (CVE-2026-8073) — What WordPress Site Owners Must Do NowRead article →
2026-05-21Urgent: CVE-2026-4885 — Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro (≤ 7.1.70) — What Site Owners Must Do Right NowRead article →