A security flaw has been identified in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The issue comes from a missing permission check that allows any logged-in user on your site, even those with only basic subscriber access (the lowest level of user permission), to perform unauthorized actions.Attackers ...
Continue reading
A security flaw has been identified in the Frontend Admin by DynamiApps plugin for WordPress, impacting all versions up to and including 3.29.9. This vulnerability allows attackers to escalate their account privileges to full administrator level, which gives them unrestricted control over your WordPress site, its content, and all user ...
Continue reading
A security vulnerability (CVE-2026-16098) has been found in the ProSolution WP Client plugin for WordPress, affecting all versions up to and including 2.0.10. This flaw lets unauthenticated (not logged-in) attackers upload files to your website without permission.These uploaded files can be set to run code on your server, which could let attackers ...
Continue reading
A security vulnerability has been identified in the ProSolution WP Client plugin for WordPress, impacting all versions of the plugin up to and including 2.0.8. If your WordPress site uses this plugin, it is at risk: the flaw allows unauthenticated attackers (people who do not have login credentials for your site) to delete arbitrary files stored ...
Continue reading