A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions up to and including 1.4.0. This flaw allows unauthenticated attackers (people without existing login access to your site) to take over any user account on your WordPress site, including administrator accounts, with no need for ...
Continue reading
A security flaw has been identified in the 6Storage Rentals plugin for WordPress, impacting all versions up to and including 2.27.0. This vulnerability allows anyone without a valid account for your WordPress site to log in as any existing user, including site administrators, by only providing that user’s email address.
The issue stems from a ...
Continue reading
A security flaw, tracked as CVE-2026-14484, has been found in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, which impacts all versions up to and including 1.0.4. The plugin does not properly validate file paths when handling file deletion requests, making it possible for anyone without an account on your site ...
Continue reading
A security vulnerability has been identified in Ray, a tool commonly used by developers to build and test applications. This is a code injection flaw, which could allow an attacker to run unauthorized, malicious code on any system where Ray is in use.This vulnerability can be exploited when accessing Ray through the Firefox or Safari web browsers. ...
Continue reading