Critical WPLP Cookie Consent Vulnerability Under Attack
A critical WPLP Cookie Consent vulnerability allows unauthenticated attackers to upload arbitrary files to vulnerable WordPress websites. Site owners running…
A critical WPLP Cookie Consent vulnerability allows unauthenticated attackers to upload arbitrary files to vulnerable WordPress websites. Site owners running…
A critical GiveWP vulnerability tracked as CVE-2026-82222 can allow unauthenticated attackers to reach remote code execution through unsafe PHP object…
A high-severity Formidable Charts vulnerability can allow unauthenticated attackers to read sensitive server files on certain WordPress installations. CVE-2026-15990 affects…
A new WPForms Pro vulnerability allows unauthenticated visitors to store malicious JavaScript through public form fields. Administrators reviewing affected entries…
A critical Automation Web Platform vulnerability tracked as CVE-2026-77264 can expose authentication tokens and allow unauthenticated attackers to access WordPress…
A serious Solace Extra vulnerability can allow unauthenticated attackers to permanently delete WordPress content imported through Starter Templates. Administrators running…
A critical User Profile Builder vulnerability can allow unauthenticated attackers to access the WordPress account with user ID 1. Learn…
Two serious WordPress plugin vulnerabilities show why Subscriber accounts should never be treated as harmless. AcyMailing and Frontend Admin contained…