WebToffee PDF Invoices Vulnerability Exposes Server Files
A vulnerability in WebToffee WooCommerce PDF Invoices can allow Subscriber-level users to read sensitive server files through generated invoices. Stores…
A vulnerability in WebToffee WooCommerce PDF Invoices can allow Subscriber-level users to read sensitive server files through generated invoices. Stores…
A high-severity Security Hardener vulnerability can allow authenticated WordPress subscribers to bypass normal REST API permission checks and create administrator…
A new WPForms Pro vulnerability allows unauthenticated visitors to store malicious JavaScript through public form fields. Administrators reviewing affected entries…
A critical Automation Web Platform vulnerability tracked as CVE-2026-77264 can expose authentication tokens and allow unauthenticated attackers to access WordPress…
A critical Elementor Pro vulnerability tracked as CVE-2026-32475 can allow unauthenticated attackers to bypass file-extension checks and upload executable PHP…
A serious Forminator vulnerability affecting file-upload handling could expose WordPress websites to malicious uploads and possible compromise. Administrators using Forminator…
A serious Solace Extra vulnerability can allow unauthenticated attackers to permanently delete WordPress content imported through Starter Templates. Administrators running…
A critical User Profile Builder vulnerability can allow unauthenticated attackers to access the WordPress account with user ID 1. Learn…
WordPress 7.0.4 addresses a serious remote code execution risk involving malicious image-like uploads, Imagick, and Ghostscript. This guide explains the…