Announcements

CVE-2026-16142 (matched: wordpress)

  • 16th August 2026
A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions up to and including 1.2.6. The vulnerability allows unauthenticated visitors (people who are not logged into your WordPress site) to modify the email address associated with any user account on your site, including administrator accounts, with no ...
Continue reading

CVE-2026-15826 (matched: wordpress)

  • 16th August 2026
A security vulnerability exists in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. This flaw allows people who do not have a valid account on your site to bypass normal login security measures.If attackers exploit this vulnerability, they can log in as your site's main Administrator account, giving ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 16th August 2026
A critical security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, impacting all versions up to and including 1.4.0. This flaw allows unauthenticated attackers to bypass normal login security measures to take over any user account on a WordPress site, including high-level administrator accounts.The ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 16th August 2026
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling ...
Continue reading