Announcements

CVE-2026-18855 (matched: wordpress)

  • 17th August 2026
A security vulnerability has been found in the Link Library plugin for WordPress, a tool used to manage and display link lists on WordPress sites. All versions of this plugin up to and including version 7.9.4 are affected. The flaw allows unauthenticated third parties to delete arbitrary files stored on your web server under specific conditions. ...
Continue reading

CVE-2026-19598 (matched: wordpress)

  • 17th August 2026
A security flaw has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a tool many site owners use to build custom content structures and manage specialized data on their sites. All versions of this plugin up to and including version 3.3.9 are affected by this vulnerability. The issue stems from a bug in the ...
Continue reading

CVE-2026-16142 (matched: wordpress)

  • 17th August 2026
A security vulnerability has been identified in the TrueBooker plugin for WordPress, a tool some site owners use to manage booking functionality. All versions of the plugin up to and including version 1.2.6 are affected by this flaw.The issue allows anyone without a valid login to your WordPress site to change the email address linked to any user ...
Continue reading

CVE-2026-15826 (matched: wordpress)

  • 17th August 2026
A security vulnerability has been identified in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The flaw stems from a coding error in how the plugin processes user registration submissions. When a username between 61 and 70 characters is entered, WordPress core rejects the registration with an ...
Continue reading