Ultimate Member Vulnerabilities Put Private Data at Risk
Two Ultimate Member vulnerabilities can expose privacy-restricted profile fields and place administrator sessions at risk through stored XSS. Site owners…
Two Ultimate Member vulnerabilities can expose privacy-restricted profile fields and place administrator sessions at risk through stored XSS. Site owners…
A newly disclosed All in One SEO vulnerability can allow unauthenticated visitors to trigger registered WordPress shortcodes through crafted search…
A high-severity XSS vulnerability affects BoldGrid Post and Page Builder versions 1.27.14 and earlier. CVE-2026-100510 does not require attacker authentication,…
CVE-2026-92820 affects specific Ninja Forms File Uploads configurations using the external Amazon S3 upload flow. Vulnerable versions through 3.3.34 may…
A high-severity Schema & Structured Data vulnerability affects WordPress plugin versions 1.66 and earlier. Learn what CVE-2026-97291 means, why Contributor…
A critical WPMobile.App vulnerability tracked as CVE-2026-94541 can expose WordPress password-reset URLs and enable administrator account takeover. Sites running version…
A serious Motors plugin vulnerability tracked as CVE-2026-6806 can expose WordPress databases through unauthenticated time-based blind SQL injection. Learn which…
A vulnerability in Frontend Post Submission Manager Lite can expose WordPress sites using guest submission forms to stored DOM-based XSS….
A newly disclosed Simply Schedule Appointments vulnerability can allow local file inclusion through the ssa_locale parameter. Although formally classified as…
The s2Member vulnerability CVE-2026-19804 can expose WordPress sites to remote code execution when PayPal Checkout and specific Signup Tracking Codes…