Announcements

CVE-2026-18316 (matched: wordpress)

  • 17th August 2026
A security flaw (tracked as CVE-2026-18316) affects the Solace Extra plugin for WordPress, with all versions up to and including 1.6.0 impacted. The gap lets any person logged into your WordPress site, even users with only basic subscriber access, make unauthorized changes to or delete important site content.Attackers with this level of access can ...
Continue reading

CVE-2026-18432 (matched: wordpress)

  • 17th August 2026
There is a security vulnerability in the Frontend Admin by DynamiApps plugin for WordPress, impacting all versions up to and including 3.29.9. This is a privilege escalation flaw, meaning it lets unauthorized users gain full administrator-level access to your WordPress site.The flaw occurs because the plugin skips a key security check that ...
Continue reading

CVE-2026-16098 (matched: wordpress)

  • 17th August 2026
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, ...
Continue reading

CVE-2026-14524 (matched: wordpress)

  • 17th August 2026
Continue reading