Announcements

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 21st July 2026
A security flaw has been found in the core WordPress software that powers a large number of websites. This issue, known as an interpretation conflict, exists in unpatched versions of the WordPress platform.If an attacker exploits this flaw, they could inject harmful commands into your site's database, which may lead to full remote control of your ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 21st July 2026
We are sharing information about a security flaw identified in WordPress Core. This is a SQL injection vulnerability that occurs when a plugin or theme installed on your site passes unvetted, untrusted user input to a specific site parameter. This flaw can be combined with a separate, already known WordPress vulnerability to let unauthenticated ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st July 2026
On July 20, 2026, cybersecurity agency MyCERT released an advisory noting new active attempts to exploit vulnerabilities in Microsoft SharePoint, a popular platform used to build and manage websites and internal business collaboration tools. If you run Microsoft SharePoint as part of your website or business operations hosted with us, these active ...
Continue reading

CVE-2026-65049 (matched: wordpress)

  • 21st July 2026
A security flaw, tracked as CVE-2026-65049, exists in the Ninja Forms plugin for WordPress Multisite, impacting all versions up to and including 3.14.8. The vulnerability stems from incorrect permission checks when the plugin runs certain data management routines on multisite networks.This issue allows a regular administrator of one individual ...
Continue reading