Announcements

CVE-2026-15748 (matched: wordpress)

  • 18th August 2026
A security vulnerability has been found in the Forminator Forms plugin for WordPress, a tool used to add forms and file upload features to WordPress websites. The flaw impacts every version of the plugin up to and including version 1.56.1. This issue lets people who do not have an account or login access to your site upload dangerous files that ...
Continue reading

CVE-2026-18432 (matched: wordpress)

  • 18th August 2026
A security flaw has been found in the Frontend Admin by DynamiApps plugin for WordPress, affecting all versions up to and including 3.29.9. This is a privilege escalation vulnerability, meaning it lets unauthorized people gain higher-level access to your WordPress site than they are supposed to have. Attackers can exploit this issue without being ...
Continue reading

CVE-2026-16098 (matched: wordpress)

  • 18th August 2026
A security flaw has been identified in the ProSolution WP Client plugin for WordPress, affecting all versions up to and including 2.0.10. The vulnerability allows unauthenticated visitors (people who do not have login access to your WordPress dashboard) to upload files to your website.This is possible due to gaps in two key security safeguards for ...
Continue reading

Ray-Project Ray: Ray-Project Ray Code Injection Vulnerability

  • 18th August 2026
A security vulnerability has been identified in Ray, a development tool used by many people building applications and online services. This is a code injection flaw, which means an unauthorized attacker could potentially run harmful code on systems that use the tool, a risk referred to as remote code execution.The issue can be exploited when ...
Continue reading