A security flaw tracked as CVE-2026-15341 has been found in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0.This is an authentication bypass vulnerability, meaning unauthenticated attackers can take full control of any user account on a WordPress site running the affected plugin, ...
Continue reading
A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0.
This flaw allows anyone without an existing account on your WordPress site to log in as any registered user, including site administrators, by only submitting that user's email address. No valid login ...
Continue reading
A popular WordPress plugin used to add secure multi-file upload features to Contact Form 7 forms has a critical security flaw affecting all versions up to and including 1.0.4. The flaw lets any visitor to your site, even someone who is not logged into your WordPress dashboard, delete arbitrary files stored on your web server. This happens because ...
Continue reading
A new version of WordPress, 7.0.4, has been released, and it includes a fix for a security issue. This is a security-focused release, so it is recommended to apply the update as soon as possible to patch gaps that could let unauthorized people access, modify, or harm your website, and keep your site and its visitor data safe.You can update to this ...
Continue reading