Announcements

CVE-2026-15341 (matched: wordpress)

  • 17th August 2026
A critical security flaw, tracked as CVE-2026-15341, affects the User Session Synchronizer plugin for WordPress. This vulnerability allows unauthenticated attackers (people with no existing access to your site) to take over any user account on your site, including full administrator accounts, without needing to know any of your site's passwords or ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 17th August 2026
A security flaw tracked as CVE-2026-15303 impacts the 6Storage Rentals plugin for WordPress, with all versions up to and including 2.27.0 affected. The issue exists in a plugin feature that handles user account logins, which does not require any verification (such as a security check, proof of account ownership, or permission confirmation) before ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 17th August 2026
A critical security flaw has been found in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, affecting all versions up to and including 1.0.4. The plugin fails to properly validate file paths when processing file deletion requests, and the secret security token required to trigger this deletion feature is ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 17th August 2026
MyCERT has released a new security advisory for Microsoft SharePoint, after discovering that bad actors are already actively trying to exploit flaws in the platform to break into systems. The alert, published on July 20, 2026, outlines recommended security hardening steps to lower risk from these emerging threats. If you use SharePoint as part of ...
Continue reading