Announcements

CVE-2026-9055 (matched: wordpress)

  • 2nd September 2026
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a ...
Continue reading

CVE-2026-18550 (matched: wordpress)

  • 2nd September 2026
The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` ...
Continue reading

PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

  • 2nd September 2026

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-81578

Continue reading

PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability

  • 2nd September 2026
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.Source: CISA Known Exploited ...
Continue reading