Announcements

CVE-2026-19598 (matched: wordpress)

  • 17th August 2026
A security flaw has been found in the Pods – Custom Content Types and Fields plugin for WordPress, a tool many sites use to manage custom content and fields. All versions of this plugin up to and including version 3.3.9 are affected by the issue. The bug causes the plugin's security checks to be completely skipped, even for people who do not ...
Continue reading

CVE-2026-16142 (matched: wordpress)

  • 17th August 2026
A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions of the plugin up to and including version 1.2.6. The issue allows anyone who visits your website, even if they are not logged in or have an account with you, to change the email address linked to any user on your WordPress site, including your ...
Continue reading

CVE-2026-15826 (matched: wordpress)

  • 17th August 2026
A security vulnerability exists in the WordPress User Profile Builder plugin, affecting all versions up to and including 3.16.4. The flaw is triggered when someone submits a site registration with a username that is 61 to 70 characters long, and it allows unauthenticated, unauthorized attackers to bypass normal login security to access your ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 17th August 2026
A security vulnerability tracked as CVE-2026-15341 impacts the User Session Synchronizer plugin for WordPress, with all versions up to and including 1.4.0 affected. This flaw allows unauthenticated attackers to completely bypass login requirements to take over any user account on an affected site, including administrator accounts that have full ...
Continue reading