Announcements

CVE-2026-16142 (matched: wordpress)

  • 16th August 2026
A security vulnerability has been discovered in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6.This flaw allows unauthenticated users (people who are not logged into your site) to change the email address for any user account on your WordPress site, including administrator accounts. After an attacker updates ...
Continue reading

CVE-2026-15826 (matched: wordpress)

  • 16th August 2026
A security vulnerability has been identified in the User Profile Builder plugin for WordPress.This flaw affects all versions of the plugin up to and including 3.16.4. It allows unauthenticated third parties to bypass standard login protections to access your site’s primary administrator account.If successfully exploited, this would give an ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 16th August 2026
A security vulnerability tracked as CVE-2026-15341 has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0. This flaw allows unauthenticated visitors (people who are not logged into your site) to take full control of any user account on your WordPress site, including ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 16th August 2026
A security flaw has been identified in the 6Storage Rentals plugin for WordPress, affecting all versions of the plugin up to and including 2.27.0.This issue allows anyone without existing access to your website to log in as any registered user on your WordPress site, including administrators, simply by entering that user's registered email ...
Continue reading