2026-05-21Urgent: Broken Access Control in CF7 WOW Styler (≤1.7.6) — What WordPress Site Owners Need to Know and Do NowRead article →
2026-05-21Urgent: Account Switcher Plugin (<= 1.0.2) — Broken Authentication (CVE‑2026‑6456) and What You Must Do NowRead article →
2026-05-21Sensitive Data Exposure in Mail Mint Plugin (≤1.19.5) — What WordPress Site Owners Need to KnowRead article →
2026-05-21SQL Injection in Infility Global (≤ 2.15.16) — What WordPress Site Owners Must Do NowRead article →
2026-05-21CVE-2026-6555 — Unauthenticated Arbitrary File Upload in ProSolution WP Client (<= 2.0.0)Read article →
2026-05-21AcyMailing <= 10.8.2 — Broken Access Control (CVE-2026-5200): What WordPress Site Owners Must Do NowRead article →
2026-05-20Why the NPM ‘HAX CMS’ DoS Advisory Matters to WordPress Sites — Practical Guidance from WP‑FirewallRead article →
2026-05-20Urgent: SQL Injection in ‘Read More & Accordion’ WordPress Plugin (<= 3.5.7) — What Site Owners Must Do NowRead article →
2026-05-20Urgent: Privilege Escalation in @budibase/backend-core — What WordPress Site Owners Need to Know and Do NowRead article →
2026-05-20Urgent: CVE-2026-6397 — Stored XSS in Sticky plugin (≤ 2.5.6) — What WordPress site owners must do nowRead article →
2026-05-20Urgent: CSRF → Stored XSS in Amazon Scraper plugin (≤ 1.1) — What WordPress site owners must do nowRead article →
2026-05-20Urgent: Broken Access Control in Xpro Elementor Addons (≤ 1.5.0) — What WordPress Site Owners Need to Do NowRead article →