2026-05-12Critical: Reflected Cross-Site Scripting (XSS) in AzonPost <= 1.3 (CVE‑2026‑7437) — What WordPress Site Owners Need to Know and Do NowRead article →
2026-05-12Broken Access Control in “Rate Star Review” (<= 1.6.4): What Site Owners Must Do Right NowRead article →
2026-05-12Broken Access Control in GWD Conex (<= 2.9): What WordPress Site Owners Must Do NowRead article →
2026-05-12Authenticated Subscriber SQL Injection in “Eight Day Week Print Workflow” Plugin (<= 1.2.6)Read article →
2026-05-12Authenticated Contributor Stored XSS in WP SEO Structured Data Schema (CVE-2026-3604) — What WordPress Site Owners Need to KnowRead article →
2026-05-12Authenticated (Contributor) Stored XSS in BJ Lazy Load (≤ 1.0.9) — What WordPress Site Owners Must Do NowRead article →
2026-05-11What to do about CVE-2026-6913: Authenticated (Contributor) Stored XSS in Shortcodely (<= 1.0.1) — A WP‑Firewall Security GuideRead article →
2026-05-11Urgent: What WordPress Site Owners Must Know About the Fancy Image Show (≤ 9.1) Stored XSS (CVE-2026-5340)Read article →
2026-05-11Urgent: Broken Access Control in Forms Rb Plugin (≤ 1.1.9) — What WordPress Site Owners Must Do Right NowRead article →
2026-05-11Urgent Security Advisory: Authenticated (Contributor) Stored XSS in ‘Advanced Social Media Icons’ (<= 1.2) — How to Protect Your WordPress SitesRead article →
2026-05-11Broken Access Control in HEL Online Classroom (<= 1.0.3) — What WordPress Site Owners Must Know and How to Protect Their LMS ContentRead article →