We are sharing information about a security flaw identified in WordPress Core. This is a SQL injection vulnerability that occurs when a plugin or theme installed on your site passes unvetted, untrusted user input to a specific site parameter.
This flaw can be combined with a separate, already known WordPress vulnerability to let unauthenticated ...
Continue reading
On July 20, 2026, cybersecurity agency MyCERT released an advisory noting new active attempts to exploit vulnerabilities in Microsoft SharePoint, a popular platform used to build and manage websites and internal business collaboration tools.
If you run Microsoft SharePoint as part of your website or business operations hosted with us, these active ...
Continue reading
A security flaw, tracked as CVE-2026-65049, exists in the Ninja Forms plugin for WordPress Multisite, impacting all versions up to and including 3.14.8. The vulnerability stems from incorrect permission checks when the plugin runs certain data management routines on multisite networks.This issue allows a regular administrator of one individual ...
Continue reading
A security flaw has been found in the Ninja Forms plugin for WordPress, impacting versions 3.10.4 through 3.14.9. The issue is a vulnerability that lets hidden harmful code be saved with form submissions, via the plugin's Repeatable Fieldset feature used to build forms with dynamic, repeatable input sections.
This flaw allows anyone, even people ...
Continue reading