Announcements

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 21st July 2026
A security vulnerability has been discovered in the core WordPress software that powers a large number of websites. This is a SQL injection flaw, which occurs when unfiltered, untrusted input is passed to a specific system parameter, typically when a WordPress plugin or theme sends that unvetted input to the core WordPress system.This flaw can be ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st July 2026
A security advisory (ID: MA-1471.072026) was published by Malaysia’s cybersecurity agency (MyCERT) on 20 July 2026, focused on securing Microsoft SharePoint following reports of new exploitation attempts targeting the platform. Microsoft SharePoint is a common tool used by organizations to store, share, and collaborate on documents and internal ...
Continue reading

CVE-2026-13439 (matched: wordpress)

  • 21st July 2026
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st July 2026
On July 20, 2026, cybersecurity authority MyCERT published a new security advisory focused on Microsoft SharePoint. The advisory was released following confirmed reports of new active exploitation attempts targeting the SharePoint platform. If your hosted services include Microsoft SharePoint deployments for team collaboration, document ...
Continue reading