Announcements

CVE-2026-19598 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, impacting all versions up to and including 3.3.9. This plugin is commonly used to add custom content types and fields to WordPress sites, so it may be installed on your website if you use it for customized content management.The flaw ...
Continue reading

CVE-2026-16142 (matched: wordpress)

  • 15th August 2026
A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions of the tool up to and including 1.2.6. The issue allows anyone who is not logged into your website to change the email address linked to any user account on your WordPress site, including administrator accounts.Once an attacker changes an ...
Continue reading

CVE-2026-15826 (matched: wordpress)

  • 15th August 2026
A security flaw exists in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The bug is triggered when a new user registration is submitted with a username that is between 61 and 70 characters long.Due to a coding error in the plugin, attackers can exploit this issue to generate a valid login link for ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 15th August 2026
A critical security flaw, tracked as CVE-2026-15341, affects the User Session Synchronizer plugin for WordPress, impacting all versions up to and including 1.4.0. This vulnerability allows anyone who is not logged into your site to bypass normal login security and take full control of any user account on your WordPress site, including ...
Continue reading