Announcements

CVE-2026-16142 (matched: wordpress)

  • 15th August 2026
A security vulnerability (tracked as CVE-2026-16142) impacts the TrueBooker plugin for WordPress, with all versions of the plugin up to and including 1.2.6 affected.This flaw allows anyone who is not logged into your WordPress site to change the email address linked to any user account on the site, including administrator accounts. An attacker ...
Continue reading

CVE-2026-15826 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been identified in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. This flaw allows unauthenticated users (people not logged into your site) to bypass standard login protections and access your site’s main Administrator account, giving them full administrative control ...
Continue reading

CVE-2026-15341 (matched: wordpress)

  • 15th August 2026
A security flaw tracked as CVE-2026-15341 has been found in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0.This is an authentication bypass vulnerability, meaning unauthenticated attackers can take full control of any user account on a WordPress site running the affected plugin, ...
Continue reading

CVE-2026-15303 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This flaw allows anyone without an existing account on your WordPress site to log in as any registered user, including site administrators, by only submitting that user's email address. No valid login ...
Continue reading