If your WordPress site uses the WooCommerce Social Login plugin in version 2.8.7 or older, the plugin has a critical security flaw in its Apple login feature. The plugin fails to properly verify that Apple login requests are legitimate, and a security protection meant to limit access to the login flow is publicly exposed to all visitors via ...
Continue reading
This security notice applies to WordPress site owners who use the Single Sign On For TNG plugin, in all versions up to 2.0.0. The plugin has a critical flaw that allows anyone who visits your site to reset the password for any WordPress account on your site, including administrator accounts, without needing permission or confirmation.The flaw ...
Continue reading
A security vulnerability has been identified in the FormGent plugin for WordPress, a tool many site owners use to manage form submissions and user-uploaded files. The flaw impacts all versions of the plugin up to and including version 1.9.2.The vulnerability exists because the plugin's built-in file-management tool does not require users to log in ...
Continue reading
A new security advisory was published by Malaysia’s national cybersecurity agency (MyCERT) on 20 July 2026, focused on Microsoft SharePoint, a widely used platform for hosting team collaboration sites, sharing files, and running web content. The advisory was issued in response to newly reported exploitation attempts targeting SharePoint ...
Continue reading