A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions up to and including 1.4.0. This flaw allows people who are not logged into your site to take over any user account on the site, including administrator accounts, without needing to know any passwords or access your site’s ...
Continue reading
A security flaw has been identified in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0.
The vulnerability allows anyone without a valid login for your website to access a built-in plugin function that has no required verification steps. If an attacker submits the email address of any existing user on ...
Continue reading
A security flaw (identified as CVE-2026-14484) affects the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, impacting all versions up to and including 1.0.4. This plugin is designed to let visitors upload multiple files through Contact Form 7 forms on your WordPress site.
The issue comes from the plugin not properly ...
Continue reading
On July 20, 2026, Malaysia’s national cybersecurity agency (MyCERT) issued a security advisory warning of newly observed attacks targeting Microsoft SharePoint, a popular platform used to host shared workspaces, document storage, and team collaboration tools for websites and internal business systems.The advisory outlines recommended security ...
Continue reading