Announcements

CVE-2026-8457 (matched: wordpress)

  • 2nd August 2026
A popular WordPress plugin used to add Apple social login options to WooCommerce stores has a serious security vulnerability that impacts all versions up to and including 2.8.7. The flaw exists because the plugin fails to properly validate Apple login requests, and a security safeguard meant to protect the login process is publicly visible on your ...
Continue reading

CVE-2026-15964 (matched: wordpress)

  • 2nd August 2026
A critical security flaw has been found in the Single Sign On For TNG plugin for WordPress, affecting all versions up to and including 2.0.0. This vulnerability lets any visitor who is not logged into your site reset the password for any WordPress account on your site, including administrator accounts.The flaw exists because the plugin's password ...
Continue reading

CVE-2026-3141 (matched: wordpress)

  • 2nd August 2026
A security flaw has been found in the FormGent plugin for WordPress, impacting all versions up to and including 1.9.2. The issue lets unauthenticated attackers (people without login access to your WordPress dashboard) delete files via an unsecured tool built into the plugin, with no login check required to use that tool.At first, attackers can ...
Continue reading

PHP 8.2.33 Released!

  • 2nd August 2026
A new version of PHP 8.2, version 8.2.33, has been released. PHP is the core software that powers most dynamic, interactive websites, including WordPress sites, online stores, and custom web applications.No additional details about the specific changes, fixes, or required next steps for this update have been included in the initial release ...
Continue reading