Critical Paytium Vulnerability Enables Admin Creation
A critical Paytium vulnerability tracked as CVE-2026-18467 can allow unauthenticated attackers to create WordPress administrator accounts under specific payment-form conditions….
A critical Paytium vulnerability tracked as CVE-2026-18467 can allow unauthenticated attackers to create WordPress administrator accounts under specific payment-form conditions….
WordPress 7.1.2 fixes a critical unauthenticated path traversal vulnerability that can lead to remote code execution under specific theme and…
A critical JetFormBuilder vulnerability can allow unauthenticated attackers to create WordPress administrator accounts through unsafe form validation. Site owners running…
Site Security & Redirects gives WordPress administrators a clean way to manage maintenance mode, disable XML-RPC, and enforce HTTPS. Version…
A high-severity Eventin vulnerability can give administrator-equivalent capabilities back to WordPress user ID 1 after the account has been demoted….
A MotoPress Hotel Booking vulnerability can expose premium installations using Stripe to stored XSS when webhook signature verification is not…
A critical WooCommerce Wholesale Lead Capture vulnerability is being actively exploited to upload dangerous files to WordPress servers. Store owners…
A Really Simple Security vulnerability can reset completed email two-factor authentication, potentially allowing an attacker who already knows a WordPress…
Two critical The Events Calendar vulnerabilities can expose WordPress websites to unauthenticated remote code execution. Site owners should update directly…
A critical Unlimited Elements vulnerability allows unauthenticated attackers to target the WordPress database through SQL injection. Sites using affected Unlimited…