Skip to content

#wordpress

85 articles

Security Alerts Jun 30, 2026

CVE-2026-12073: The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to...

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to th...

Security Alerts Jun 27, 2026

CVE-2026-12415: The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing...

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1....

Security Alerts Jun 20, 2026

CVE-2019-25763: WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass...

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functio...

Security Alerts Jun 19, 2026

CVE-2026-8713: The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to...

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and includin...

Security Alerts Jun 15, 2026

CVE-2018-25436: WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload...

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-pa...

Security Alerts Jun 15, 2026

CVE-2026-49776: Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress:...

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions....

Security Alerts Jun 15, 2026

CVE-2026-8935: The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which,...

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionall...

Security Alerts Jun 12, 2026

CVE-2026-47365: Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM,...

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI...

Security Alerts Jun 10, 2026

CVE-2026-9067: The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user...

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded f...

Security Alerts Jun 9, 2026

CVE-2017-20251: WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that...

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes throu...

Security Alerts Jun 8, 2026

CVE-2023-54352: Remote code execution in WordPress Seotheme (theme)

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can...

Security Alerts Jun 8, 2026

CVE-2024-58348: Remote code execution in WordPress Background Image Cropper (plugin)

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attacke...

Security Alerts Jun 8, 2026

CVE-2024-58349: Arbitrary file upload in WordPress Travelscape (theme)

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's u...

Security Alerts Jun 5, 2026

CVE-2026-10580: Authentication Bypass in Hippoo Mobile App for WooCommerce (plugin)

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a ...

Security Alerts Jun 5, 2026

CVE-2026-49777: Malicious Code Injection in Product Slider Pro for WooCommerce

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for...

Security Alerts Jun 4, 2026

CVE-2019-25727: Arbitrary file download in WordPress Ad Manager WD (plugin)

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers ...

Security Alerts Jun 4, 2026

CVE-2019-25738: Unauthenticated settings change in WordPress Hybrid Composer (plugin)

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action...

Security Alerts Jun 2, 2026

CVE-2026-42684: Blind SQL Injection in WordPress WP Job Portal (plugin)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a throug...

Security Alerts Jun 2, 2026

CVE-2026-5076: Insecure password reset in WordPress ARMember Premium (plugin)

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset ke...

Security Alerts Jun 2, 2026

CVE-2026-8206: Account takeover in WordPress Kirki (plugin)

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugi...

Security Alerts Jun 1, 2026

CVE-2026-42672: Blind SQL Injection in WordPress WP Directory Kit plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit...

Security Alerts Jun 1, 2026

CVE-2026-42680: Privilege Escalation in WordPress Contest Gallery Pro plugin

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 2...

Security Alerts Jun 1, 2026

CVE-2026-48866: Path Traversal in WordPress Gravity Forms plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a throu...

Security Alerts May 29, 2026

CVE-2026-3655: Authentication Bypass in WordPress OTP Login With Phone Number plugin

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `l...

Security Alerts May 29, 2026

CVE-2026-8732: Privilege Escalation in WordPress WP Maps Pro plugin

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJA...

Security Alerts May 29, 2026

CVE-2026-8809: Privilege Escalation in WordPress Advanced Custom Fields: Extended plugin

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the a...

Security Alerts May 27, 2026

CVE-2026-42727: SQL injection in WordPress Active Products Tables for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Bl...

Security Alerts May 27, 2026

CVE-2026-42731: Privilege escalation in WordPress miniOrange OTP Verification

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a ...

Security Alerts May 27, 2026

CVE-2026-42740: SQL injection in WordPress Tainacan plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a throug...

Security Alerts May 27, 2026

CVE-2026-42747: SQL injection in WordPress Easy Form Builder plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects E...

Security Alerts May 27, 2026

CVE-2026-42748: Web shell upload in WordPress WPify Woo Czech plugin

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1...

Security Alerts May 27, 2026

CVE-2026-42755: SQL Injection in WordPress TableOn plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: f...

Security Alerts May 27, 2026

CVE-2026-42756: Path Traversal in WordPress QuickWebP plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allo...

Security Alerts May 27, 2026

CVE-2026-42757: Path Traversal in WordPress WebinarIgnition plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects Webin...

Security Alerts May 27, 2026

CVE-2026-42758: Privilege Escalation in WordPress WebinarIgnition plugin

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253....

Security Alerts May 27, 2026

CVE-2026-42761: SQL Injection in WordPress Active Products Tables for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Bl...

Security Alerts May 27, 2026

CVE-2026-8760: Authentication Bypass in WordPress Login with OTP plugin

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout ch...

Security Alerts May 22, 2026

CVE-2026-6960: Arbitrary file upload in WordPress BookingPress Pro plugin

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all version...

Security Alerts May 21, 2026

CVE-2026-6279: Unauthenticated RCE in WordPress Avada Builder plugin

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp...

Security Alerts May 20, 2026

CVE-2026-45444: Arbitrary file upload in Gift Cards For WooCommerce Pro (plugin)

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a thr...

Security Alerts May 20, 2026

CVE-2026-6555: Arbitrary File Upload in WordPress ProSolution WP Client (plugin)

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in ...

Security Alerts May 20, 2026

CVE-2026-7284: Privilege escalation in Easy Elements for Elementor (plugin)

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due t...

Security Alerts May 20, 2026

CVE-2026-7637: PHP Object Injection in WordPress Boost (plugin)

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This make...

Security Alerts May 19, 2026

CVE-2026-4883: Arbitrary File Upload in WordPress Piotnet Forms plugin

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including,...

Security Alerts May 19, 2026

CVE-2026-4885: Arbitrary File Upload in WordPress Piotnet Addons for Elementor Pro

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and...

Security Alerts May 17, 2026

CVE-2018-25335: Arbitrary file upload in WordPress Peugeot Music plugin

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. ...

Security Alerts May 15, 2026

CVE-2026-5229: Authentication Bypass in WordPress Form Notify plugin

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which Wo...

Security Alerts May 14, 2026

CVE-2026-6271: Arbitrary File Upload RCE in WordPress Career Section plugin

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This ma...

Security Alerts May 14, 2026

CVE-2026-6510: Privilege Escalation in WordPress InfusedWoo Pro plugin

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capab...

Security Alerts May 14, 2026

CVE-2026-6512: Authorization Bypass in WordPress InfusedWoo Pro plugin

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to...

Security Alerts May 14, 2026

CVE-2026-8181: Authentication bypass in WordPress Burst Statistics (plugin)

Authentication bypass in Burst Statistics WordPress plugin versions 3.4.0 to 3.4.1.1 due to incorrect return-value handling in is_mainwp_authenticated(). Unauthenticated attackers with knowledge of admin username can impersonate that administrator...

Security Alerts May 10, 2026

CVE-2021-47932: Privilege Escalation in WordPress TheCartPress Plugin

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler....

Security Alerts May 10, 2026

CVE-2021-47933: Arbitrary File Upload in WordPress MStore API Plugin

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers ...

Security Alerts May 10, 2026

CVE-2021-47940: Arbitrary File Upload in WordPress Download From Files Plugin

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fil...

Security Alerts May 5, 2026

CVE-2025-13618: Privilege Escalation in WordPress Mentoring Plugin

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can regist...

Security Alerts May 5, 2026

CVE-2026-5294: Missing Authorization RCE in WordPress Geeky Bot Plugin

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. Unauthenticated attackers can install arbitrary plugins and achieve remote code execution....

Security Alerts May 5, 2026

CVE-2026-5722: Authentication Bypass in WordPress MoreConvert Pro plugin

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or re...

Security Alerts May 2, 2026

CVE-2026-4882: Arbitrary file upload in WordPress User Registration Advanced Fields

The User Registration Advanced Fields plugin for WordPress (versions up to and including 1.6.20) allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on the server...

Security Alerts May 2, 2026

CVE-2026-7458: Authentication bypass in WordPress User Verification by PickPlugins

The User Verification by PickPlugins plugin for WordPress (versions up to and including 2.0.46) allows unauthenticated attackers to log in as any user with a verified email by submitting an OTP value of "true"...

Security Alerts May 1, 2026

CVE-2026-7567: Authentication bypass in WordPress Temporary Login plugin

The Temporary Login plugin for WordPress (versions up to and including 1.0.0) contains an authentication bypass in the maybe_login_temporary_user() function. Passing an array instead of a string in the GET parameter lets an attacker log in as an arbitrary user, typically an administrator...

Security Alerts Apr 27, 2026

CVE-2026-22336: SQL injection in WordPress Directorist Booking plugin

The WordPress Directorist Booking plugin before 3.0.2 is vulnerable to SQL injection due to improper neutralization of special elements used in an SQL command...

Security Alerts Apr 27, 2026

CVE-2026-22337: Privilege escalation in Directorist Social Login plugin

The Directorist Social Login plugin before 2.1.4 contains an Incorrect Privilege Assignment flaw that allows an attacker to escalate privileges in WordPress...

Security Alerts Apr 23, 2026

CVE-2026-3844: Arbitrary file upload in Breeze Cache plugin for WordPress

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_gravatar_from_remote function, which may enable remote code execution...

Security Alerts Apr 22, 2026

CVE-2026-1555: Arbitrary file upload in WebStack theme for WordPress

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function, which may enable remote code execution...

Security Alerts Apr 22, 2026

CVE-2026-4119: Authorization bypass in Create DB Tables plugin for WordPress

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_...

Security Alerts Apr 22, 2026

CVE-2026-6235: Authorization bypass in Sendmachine plugin for WordPress

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugi...

Security Alerts Apr 17, 2026

CVE-2026-2262: Sensitive data exposure in WordPress Easy Appointments plugin

The Easy Appointments plugin for WordPress (versions ≤ 3.12.21) exposes sensitive customer data via an unprotected REST API endpoint. Unauthenticated attackers can retrieve names, email addresses, phone numbers, and appointment details...

Security Alerts Apr 17, 2026

CVE-2026-6443: Backdoored Accordion plugin for WordPress

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoo...

Security Alerts Apr 16, 2026

CVE-2026-3596: Privilege escalation in WordPress

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopri...

Security Alerts Apr 16, 2026

CVE-2026-4880: Privilege escalation in WordPress

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication ...

Security Alerts Apr 14, 2026

CVE-2026-4365: Unauthorized data deletion in LearnPress plugin for WordPress

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2...

Security Alerts Apr 10, 2026

CVE-2026-34424: Backdoored Smart Slider 3 Pro plugin for WordPress

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute ...

Security Alerts Apr 9, 2026

CVE-2026-1830: Unauthenticated RCE via REST API in Quick Playground plugin for WordPress

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints tha...

Security Alerts Apr 8, 2026

CVE-2026-2942: Arbitrary file upload in ProSolution WP Client plugin for WordPress

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and includi...

Security Alerts Apr 8, 2026

CVE-2026-3296: PHP Object Injection in Everest Forms plugin for WordPress

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to...

Security Alerts Apr 8, 2026

CVE-2026-3535: Arbitrary file upload in WordPress

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, a...

Security Alerts Apr 8, 2026

CVE-2026-4003: Privilege escalation via user meta update in Users Manager PN plugin for WordPress

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic...

Security Alerts Apr 7, 2026

CVE-2026-0740: Arbitrary file upload in Ninja Forms File Uploads plugin for WordPress

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all v...

Security Alerts Apr 1, 2026

CVE-2025-15484: Authentication bypass in Order Notification for WooCommerce plugin

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write acces...

Security Alerts Mar 15, 2026

CVE-2026-3300: PHP code injection RCE in Everest Forms Pro plugin for WordPress

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_fi...

Security Alerts Mar 14, 2026

CVE-2026-4257: Remote code execution in WordPress

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is d...

Security Alerts Feb 25, 2026

CVE-2026-4484: Privilege escalation in Masteriyo LMS plugin for WordPress

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the ...

Security Alerts Feb 4, 2026

CVE-2026-4001: Critical Vulnerability in WordPress Woocommerce Custom Product Addons Pro - Immediate Update Required

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_c...

Security Alerts Feb 3, 2026

CVE-2026-4283: Critical Vulnerability in WordPress WP DSGVO Tools (GDPR) - Immediate Update Required

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accept...

Security Alerts Jan 7, 2026

CVE-2026-4038: Critical Vulnerability in WordPress Aimogen Pro - Immediate Update Required

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' functi...