Announcements

CVE-2026-19598 (matched: php)

  • 16th August 2026
A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin, a common tool used to add custom content types and fields to WordPress websites. All versions of the plugin up to and including 3.3.9 are impacted by this flaw.The issue breaks the plugin’s built-in security checks that are designed to block ...
Continue reading

CVE-2026-73533 (matched: php)

  • 16th August 2026
A security vulnerability impacts the Ninja Tables Pro WordPress plugin, specifically version 5.2.11. A tampered, malicious version of this plugin was distributed through a decommissioned (no longer active) update server, so sites that installed this specific plugin version may have unknowingly added harmful code to their websites.The compromised ...
Continue reading

CVE-2024-13784 (matched: wordpress)

  • 16th August 2026
A security vulnerability tracked as CVE-2024-13784 has been identified in the ARForms plugin for WordPress, a tool used to build contact forms, surveys, quizzes, and popups. The flaw affects all versions of the plugin up to 1.8.5, and allows unauthenticated attackers to inject harmful code into your site by sending specially crafted form ...
Continue reading

CVE-2026-18316 (matched: wordpress)

  • 16th August 2026
A security flaw has been found in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The plugin does not properly check if a user has the correct permissions to run its import function, which means even users with very basic access to your site's backend (such as Subscribers, the lowest-level role for ...
Continue reading