A security vulnerability tracked as CVE-2026-73533 has been identified in Ninja Tables Pro, a popular WordPress plugin used to create and manage tables on websites. The issue affects version 5.2.11 of the plugin, which was distributed with hidden malicious code through an old, decommissioned update server that the plugin’s developer no longer ...
Continue reading
A security flaw has been identified in AlanWeb SCADA, a software platform some users run for their operational systems. The issue occurs because the software does not verify whether users are authorized to access certain system folders.This gap allows unauthorized attackers to view all files stored in these unprotected folders, run select files ...
Continue reading
A security vulnerability (tracked as CVE-2026-16142) impacts the TrueBooker plugin for WordPress, with all versions of the plugin up to and including 1.2.6 affected.This flaw allows anyone who is not logged into your WordPress site to change the email address linked to any user account on the site, including administrator accounts. An attacker ...
Continue reading
A security vulnerability has been identified in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. This flaw allows unauthenticated users (people not logged into your site) to bypass standard login protections and access your site’s main Administrator account, giving them full administrative control ...
Continue reading