WebToffee PDF Invoices Vulnerability Exposes Server Files
A vulnerability in WebToffee WooCommerce PDF Invoices can allow Subscriber-level users to read sensitive server files through generated invoices. Stores…
A vulnerability in WebToffee WooCommerce PDF Invoices can allow Subscriber-level users to read sensitive server files through generated invoices. Stores…
A high-severity Security Hardener vulnerability can allow authenticated WordPress subscribers to bypass normal REST API permission checks and create administrator…
A new WPForms Pro vulnerability allows unauthenticated visitors to store malicious JavaScript through public form fields. Administrators reviewing affected entries…
A critical Automation Web Platform vulnerability tracked as CVE-2026-77264 can expose authentication tokens and allow unauthenticated attackers to access WordPress…
A critical Elementor Pro vulnerability tracked as CVE-2026-32475 can allow unauthenticated attackers to bypass file-extension checks and upload executable PHP…
WordPress 7.1 RC4 represents the final testing stage before the stable release. Here is what WordPress administrators, GeneratePress users, plugin…
A serious Forminator vulnerability affecting file-upload handling could expose WordPress websites to malicious uploads and possible compromise. Administrators using Forminator…
A serious Solace Extra vulnerability can allow unauthenticated attackers to permanently delete WordPress content imported through Starter Templates. Administrators running…
The WordPress Contributor Toolkit makes Core testing far easier for beginners by creating a local development environment without Docker, Git,…
A critical User Profile Builder vulnerability can allow unauthenticated attackers to access the WordPress account with user ID 1. Learn…