2026-06-09Urgent: CVE-2026-8977 — Stored XSS in WP GDPR Cookie Consent (<= 1.0.0) — What WordPress Owners Must Do Right NowRead article →
2026-06-09Urgent: CVE-2026-7556 — Unauthenticated Stored XSS in FV Flowplayer Video Player Plugin (≤ 7.5.49.7212) — What WordPress Site Owners Must Do NowRead article →
2026-06-09Urgent: CVE-2026-10580 — Broken Access Control in Hippoo Mobile App for WooCommerce (<= 1.9.4)Read article →
2026-06-09Urgent: CSRF in “AJAX Report Comments” Plugin (<= 2.0.4, CVE‑2026‑8902) — What WordPress Site Owners Must Do TodayRead article →
2026-06-09Urgent: Authenticated Contributor Stored XSS in ePaperFlip Publisher (CVE-2026-7662) — What Every Site Owner Must DoRead article →
2026-06-09Urgent: Authenticated Contributor Stored XSS in TinyMCE Shortcode Addon (≤ 1.0.0) — What WordPress Site Owners and Developers Must Do NowRead article →
2026-06-09Urgent: Authenticated (Author) Stored XSS in MailerPress (≤ 2.0.4) — What WordPress Site Owners and Admins Must Do NowRead article →
2026-06-09Urgent security advisory — CVE-2026-10553: Cross‑Site Request Forgery (CSRF) in jQuery Hover Footnotes (<= 1.4)Read article →
2026-06-09Urgent Security Advisory: CVE-2026-8909 — CSRF in WpMobi plugin (≤ 0.0.3) and Practical Mitigations for WordPress SitesRead article →
2026-06-09Unauthenticated Stored XSS in “All In One WP Security & Firewall” (≤ 5.4.7) — What Site Owners Must Know and How WP-Firewall Protects YouRead article →
2026-06-09Unauthenticated Stored XSS in ‘Integration for Freshsales’ Plugin (≤ 1.0.15): Risk, Response & How WP-Firewall Protects YouRead article →
2026-06-09Unauthenticated IDOR in 6Storage Rentals (CVE-2026-9185): What WordPress Site Owners Must Do NowRead article →