Announcements

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 21st July 2026
A security flaw called an interpretation conflict has been identified in WordPress core, the base software that powers all standard WordPress websites. This vulnerability creates a risk that attackers could exploit it to perform SQL injection, a type of attack that lets bad actors access, alter or delete data stored in your site’s database. In ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 21st July 2026
A security vulnerability has been discovered in the core WordPress software that powers a large number of websites. This is a SQL injection flaw, which occurs when unfiltered, untrusted input is passed to a specific system parameter, typically when a WordPress plugin or theme sends that unvetted input to the core WordPress system.This flaw can be ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st July 2026
A security advisory (ID: MA-1471.072026) was published by Malaysia’s cybersecurity agency (MyCERT) on 20 July 2026, focused on securing Microsoft SharePoint following reports of new exploitation attempts targeting the platform. Microsoft SharePoint is a common tool used by organizations to store, share, and collaborate on documents and internal ...
Continue reading

CVE-2026-13439 (matched: wordpress)

  • 21st July 2026
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a ...
Continue reading