Announcements

CVE-2026-15341 (matched: wordpress)

  • 15th August 2026
A security flaw tracked as CVE-2026-15341 has been found in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0.This is an authentication bypass vulnerability, meaning unauthenticated attackers can take full control of any user account on a WordPress site running the affected plugin, ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This flaw allows anyone without an existing account on your WordPress site to log in as any registered user, including site administrators, by only submitting that user's email address. No valid login ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 15th August 2026
A popular WordPress plugin used to add secure multi-file upload features to Contact Form 7 forms has a critical security flaw affecting all versions up to and including 1.0.4. The flaw lets any visitor to your site, even someone who is not logged into your WordPress dashboard, delete arbitrary files stored on your web server. This happens because ...
Continue reading

WordPress 7.0.4 Release

  • 15th August 2026
A new version of WordPress, 7.0.4, has been released, and it includes a fix for a security issue. This is a security-focused release, so it is recommended to apply the update as soon as possible to patch gaps that could let unauthorized people access, modify, or harm your website, and keep your site and its visitor data safe.You can update to this ...
Continue reading