A security flaw has been found in the Link Library plugin for WordPress, affecting all versions up to and including 7.9.4. This issue could let unauthenticated attackers delete files stored on your website's server, but only if the plugin's "Delete local file on link deletion" setting is turned on. This setting is disabled by default for all sites ...
Continue reading
A security flaw has been found in the WordPress plugin Pods – Custom Content Types and Fields, which is used to create custom content types and fields for WordPress sites. The vulnerability affects all versions of the plugin up to and including version 3.3.9.The issue lets attackers bypass all of the plugin's built-in access security checks, ...
Continue reading
A security vulnerability has been identified in the TrueBooker plugin for WordPress, impacting all versions up to and including version 1.2.6. The flaw stems from a user update tool built into the plugin being accessible to unauthenticated visitors (people who do not have a login for your site) with no checks to confirm the person submitting ...
Continue reading
A security flaw tracked as CVE-2026-15826 has been identified in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The vulnerability stems from a bug in the plugin's user login handling code that is triggered when a visitor submits a site registration attempt with a username between 61 and 70 ...
Continue reading