2026-05-13Broken Access Control in Broadstreet Ads (CVE-2025-9988): What WordPress Site Owners Must Do NowRead article →
2026-05-13Broken Access Control in Blog2Social (<= 8.9.0): What WordPress Site Owners Need to Know (and Do Right Now)Read article →
2026-05-13Bold Page Builder (<= 5.6.8) — Authenticated Contributor Stored XSS (CVE-2026-3694) — Risk, Detection & Practical Mitigation with WP‑FirewallRead article →
2026-05-13Authenticated Subscriber SQL Injection in ProfileGrid (CVE-2026-4608): What WordPress Site Owners Must Do NowRead article →
2026-05-13Authenticated Contributor SQL Injection in ‘Unlimited Elements For Elementor’ (≤ 2.0.7): What WordPress Site Owners Must Do NowRead article →
2026-05-13Authenticated (Author+) Path Traversal in Media Sync (<= 1.4.9): What WordPress Site Owners Must Do NowRead article →
2026-05-12Urgent: CVE-2026-4920 — Authenticated (Contributor+) Stored XSS in Next Date Plugin (≤ 1.0)Read article →
2026-05-12Urgent: Broken Access Control (CVE-2026-1934) in Motors – Car Dealership & Classified Listings Plugin (<= 1.4.103)Read article →
2026-05-12Urgent Security Advisory — Stored XSS in the Continually WordPress Plugin (≤ 4.3.1): What Site Owners and Developers Need to Do NowRead article →
2026-05-12Urgent SQL Injection in WordPress AI Chatbot & Workflow Automation (AIWU) <= 1.4.17 — What to do nowRead article →
2026-05-12Understanding and Mitigating the CSRF in Zawgyi Embed (‹= 2.1.1) — A Practical Guide for WordPress Site OwnersRead article →
2026-05-12Reflected XSS in “WP Google Maps Integration” plugin (<= 1.2) — What every WordPress site owner needs to knowRead article →