Announcements

CVE-2024-13784 (matched: php)

  • 17th August 2026
A security flaw has been identified in the ARForms WordPress plugin, a popular tool for building contact forms, surveys, quizzes, and popup forms. The flaw impacts all versions of the plugin up to and including version 1.8.5, and relates to how the plugin handles data submitted through its forms. It makes it possible for attackers who do not have ...
Continue reading

CVE-2026-19598 (matched: php)

  • 17th August 2026
A security flaw has been found in the Pods – Custom Content Types and Fields plugin for WordPress, which impacts all versions up to and including 3.3.9. This vulnerability lets people who don’t have an account or login for your site bypass the plugin’s normal access restrictions.If taken advantage of, these unauthenticated users can gain ...
Continue reading

CVE-2024-13784 (matched: wordpress)

  • 17th August 2026
A security flaw has been found in the ARForms plugin for WordPress, a popular tool used to build contact forms, surveys, quizzes, and popups. The flaw impacts all versions of the plugin up to and including 1.8.5, and allows anyone (even people who don’t have login access to your site) to send specially crafted form submissions that inject ...
Continue reading

CVE-2026-18316 (matched: wordpress)

  • 17th August 2026
A security flaw has been identified in the Solace Extra plugin for WordPress, impacting all versions up to and including 1.6.0. The issue stems from a missing permission check on the plugin's import tool, which allows any logged-in user on your WordPress site — even those with the lowest-level "Subscriber" access — to modify or delete critical ...
Continue reading