A security vulnerability, tracked as CVE-2026-19598, has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a popular tool used to add custom content types and fields to WordPress sites. The flaw impacts every version of the plugin up to and including version 3.3.9. The issue stems from a coding bug that breaks ...
Continue reading
A security vulnerability has been discovered in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6.This flaw allows unauthenticated users (people who are not logged into your site) to change the email address for any user account on your WordPress site, including administrator accounts. After an attacker updates ...
Continue reading
A security vulnerability has been identified in the User Profile Builder plugin for WordPress.This flaw affects all versions of the plugin up to and including 3.16.4. It allows unauthenticated third parties to bypass standard login protections to access your site’s primary administrator account.If successfully exploited, this would give an ...
Continue reading
A security vulnerability tracked as CVE-2026-15341 has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0. This flaw allows unauthenticated visitors (people who are not logged into your site) to take full control of any user account on your WordPress site, including ...
Continue reading