A security vulnerability tracked as CVE-2026-46420 has been identified in setup-php, a common tool used to configure PHP environments for GitHub Actions automated workflows, which are often used for testing and deploying websites. The flaw affects all versions of setup-php from 2.25.0 up to (but not including) version 2.37.1. The tool pulls PHP ...
Continue reading
A security flaw has been identified in the "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" plugin for WordPress, affecting all versions up to and including 4.8.6.The flaw is an authentication bypass issue. Normally, this plugin sends secret one-time login codes only to the email address linked to a user ...
Continue reading
A security flaw has been identified in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, impacting all versions up to and including 1.2.6.
The vulnerability allows anyone who does not already have a login account for your WordPress site to change the email address associated with any user account on your site, ...
Continue reading
A security vulnerability has been identified in Apple’s macOS operating system. The flaw is an improper authentication issue, meaning the system’s standard security checks for its built-in Screen Sharing feature do not work as intended.
This issue could allow an attacker who is connected to the same network as your macOS device to access the ...
Continue reading