Announcements

CVE-2026-19598 (matched: php)

  • 16th August 2026
A security flaw tracked as CVE-2026-19598 affects the Pods – Custom Content Types and Fields plugin for WordPress, a tool used to build custom content types and fields for WordPress sites. The vulnerability impacts all versions of the plugin up to and including 3.3.9. The flaw exists because the part of the plugin that handles admin requests is ...
Continue reading

CVE-2026-73533 (matched: php)

  • 16th August 2026
A security issue affects version 5.2.11 of the Ninja Tables Pro WordPress plugin. The compromised version of the plugin was distributed via a decommissioned, no longer official update server for the tool, so users who installed or updated to this specific version through that old server may have received a tampered, malicious copy instead of the ...
Continue reading

CVE-2026-34184 (matched: php)

  • 16th August 2026
A security flaw has been identified in AlanWeb SCADA software. The flaw means the software does not check if people are authorized to access certain system folders, so it does not verify that visitors have permission to view or interact with files stored in those locations. This gap allows unauthorized attackers to read all files in these ...
Continue reading

CVE-2024-13784 (matched: wordpress)

  • 16th August 2026
A security vulnerability has been discovered in the ARForms plugin, a popular WordPress tool for building contact forms, surveys, quizzes and popup forms. The flaw impacts all versions of the plugin up to and including version 1.8.5, and allows unauthenticated attackers (people who do not have login credentials for your website) to submit ...
Continue reading