Announcements

CVE-2026-15826 (matched: wordpress)

  • 15th August 2026
A security flaw exists in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The bug is triggered when a new user registration is submitted with a username that is between 61 and 70 characters long.Due to a coding error in the plugin, attackers can exploit this issue to generate a valid login link for ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 15th August 2026
A critical security flaw, tracked as CVE-2026-15341, affects the User Session Synchronizer plugin for WordPress, impacting all versions up to and including 1.4.0. This vulnerability allows anyone who is not logged into your site to bypass normal login security and take full control of any user account on your WordPress site, including ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 15th August 2026
A security flaw has been discovered in the 6Storage Rentals plugin for WordPress, which affects all versions of the plugin up to and including 2.27.0. This vulnerability allows anyone who does not have an account on your website to log in as any existing WordPress user on your site, including administrator accounts, simply by entering that ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 WordPress plugin, which adds secure file upload features to Contact Form 7 forms. All versions of the plugin up to and including 1.0.4 are affected by this flaw.The issue allows unauthenticated attackers (people who do not have admin login ...
Continue reading