Announcements

CVE-2026-19598 (matched: php)

  • 16th August 2026
A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a tool many site owners use to build custom content types and field structures for their sites. The flaw impacts all versions of the plugin up to and including 3.3.9. The issue stems from a bug in how the plugin runs its standard ...
Continue reading

CVE-2024-13784 (matched: wordpress)

  • 16th August 2026
A security flaw tracked as CVE-2024-13784 has been identified in the Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress. The flaw impacts all versions of the plugin up to and including version 1.8.5, and allows unauthenticated attackers (people who do not have login access to your website) to send specially crafted ...
Continue reading

CVE-2026-18316 (matched: wordpress)

  • 16th August 2026
A security flaw has been found in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The issue comes from a missing permission check that lets even low-level logged-in users (such as Subscribers, who normally only have read-only access to your site) run restricted site actions they are not supposed to be able ...
Continue reading

CVE-2026-18432 (matched: wordpress)

  • 16th August 2026
A security vulnerability has been found in the Frontend Admin by DynamiApps plugin for WordPress, a tool many site owners use to manage WordPress features directly from the public part of their website. The flaw affects all versions of the plugin up to and including version 3.29.9.The vulnerability lets unauthorized users gain full administrator ...
Continue reading