2026-05-04Cross-Site Request Forgery (CSRF) chained to Stored Cross‑Site Scripting (XSS) in addfreespace <= 0.1.3 — What WordPress Site Owners Must Know and DoRead article →
2026-05-04Broken Access Control in Royal Elementor Addons (CVE-2026-4024) — What WordPress Sites Need to Know and Do NowRead article →
2026-05-04Broken Access Control in FundPress (≤ 2.0.8) — What WordPress Site Owners Must Do NowRead article →
2026-05-04Broken Access Control in Amelia (<= 2.1.2) — What WordPress Site Owners Must Do NowRead article →
2026-05-04Authenticated Contributor Stored XSS in Jeg Elementor Kit (≤3.1.0) — What WordPress Site Owners Need to KnowRead article →
2026-05-03Urgent: Path Traversal Vulnerability in WP Customer Area (<= 8.3.4) — What WordPress Site Owners Must Do NowRead article →
2026-05-03Unauthenticated Reflected XSS in “News & Blog Designer Pack” (<= 3.4.9) — What WordPress Site Owners Must Do NowRead article →
2026-05-03Recent researcher-reported WordPress vulnerabilities: What site owners must do nowRead article →
2026-05-03Critical Advisory: Reflected XSS in “Auto-Install Free SSL” WordPress Plugin (≤ 4.5.0) — What Site Owners Must Do NowRead article →
2026-05-02Urgent: New WordPress Login Vulnerability Disclosure — What Site Owners Must Do NowRead article →