Announcements

CVE-2026-15826 (matched: wordpress)

  • 15th August 2026
A security flaw has been found in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The issue is triggered when someone submits a user registration with a username between 61 and 70 characters long, due to a coding error in how the plugin processes these requests.This error allows unauthenticated ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0. The flawed code runs automatically on every page load of sites using the plugin, and fails to properly verify that incoming requests to the plugin's sync feature are legitimate.This gap ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This is an authentication bypass flaw, which allows unauthorized people to access your site without needing valid login credentials.If you use the 6Storage Rentals plugin on your WordPress site, you may be ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 15th August 2026
A security vulnerability tracked as CVE-2026-14484 has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, which impacts all versions of the plugin up to and including 1.0.4. This plugin is designed to let visitors upload files through Contact Form 7 forms on WordPress sites.The flaw stems from the ...
Continue reading