2026-05-15Urgent: Protect Your Sites from the Smartcat Translator for WPML Broken Access Control (CVE-2026-4683)Read article →
2026-05-15Urgent: Directory Traversal (CVE-2026-6403) in Quick Playground <= 1.3.3 — What WordPress Site Owners Must Do NowRead article →
2026-05-15Urgent Security Advisory: Privilege Escalation in Frontend Admin by DynamiApps (CVE‑2026‑6228) — What WordPress Site Owners Must Do NowRead article →
2026-05-15Critical Analysis: Stored XSS in Advanced Custom Fields — Font Awesome Field (CVE-2026-6415)Read article →
2026-05-15Broken Authentication in “Receive Notifications After Form Submitting” (Form Notify for Any Forms) — What Site Owners Must Do NowRead article →
2026-05-14Urgent: CVE-2026-5396 — Fluent Forms (<= 6.1.21) Authenticated Subscriber Authorization BypassRead article →
2026-05-14Urgent: Burst Statistics (WordPress) — Broken Authentication (CVE‑2026‑8181) and How to Protect Your Site NowRead article →
2026-05-14Urgent: Broken Access Control in InfusedWoo Pro (≤ 5.1.2) — What WordPress Site Owners and Developers Must Do NowRead article →
2026-05-14Urgent Security Bulletin — Broken Access Control in FOX Currency Switcher (≤ 1.4.5): What WordPress Site Owners Must DoRead article →
2026-05-14Urgent Security Alert: Broken Access Control in InfusedWoo Pro (<= 5.1.2) — What WordPress Site Owners Must Do NowRead article →
2026-05-14Urgent Security Advisory: SQL Injection in NEX‑Forms (CVE‑2026‑7046) — What WordPress Site Owners Must Do NowRead article →
2026-05-14Unauthenticated Stored XSS in ManageWP Worker (≤ 4.9.31): What WordPress Site Owners Must Do NowRead article →