Posts on the topic: Bulletin
13 July 2026
Security Bulletin for 13 July 2026: Unauthenticated SQL Injection in the WordPress plugin Booking Package
A quiet start to the week: an unauthenticated SQL injection in the Booking Package plugin — reachable through an open REST endpoint, limited in exploitability by an email check and so far without a fix.
Read more → Security12 July 2026
Security Bulletin for 12 July 2026: Code Execution in WP Ultimate CSV Importer, File Inclusion in LA-Studio Element Kit, Cross-Site Scripting in Motors and Email Manipulation in NEX-Forms
Weekend security roundup: a code execution in WP Ultimate CSV Importer, a local file inclusion in LA-Studio Element Kit, a cross-site scripting in Motors and an email manipulation in NEX-Forms.
Read more → Security11 July 2026
Security Bulletin for 11 July 2026: File Read in W3 Total Cache, Account Takeover in Essential Addons for Elementor, Payment-Key Leak in Cost Calculator Builder and File Upload in RSFiles!
Daily security roundup: an unauthenticated file read in W3 Total Cache, an account takeover in Essential Addons for Elementor, a leak of payment keys in Cost Calculator Builder and a file upload with code execution in the Joomla extension RSFiles!.
Read more → Security10 July 2026
Security Bulletin for 10 July 2026: File Upload in Super Forms, Authentication Bypass in miniOrange Social Login, SQL Injection in Ultimate Member and Payment Manipulation in SureForms
Daily security roundup: a file upload with code execution in Super Forms, an authentication bypass in miniOrange Social Login, a SQL injection in Ultimate Member and a payment manipulation in SureForms.
Read more → Security9 July 2026
Security Bulletin for 9 July 2026: Authentication Bypass in miniOrange OTP, File Upload in Blocksy Companion Pro, Plugin Installation via CSRF in Divi Torque and Account Takeover in Divi Form Builder
Daily security roundup: an authentication bypass in miniOrange OTP, a file upload with code execution in Blocksy Companion Pro, a plugin installation via CSRF in Divi Torque and an account takeover in Divi Form Builder.
Read more → Security8 July 2026
Security Bulletin for 8 July 2026: Login-Free Plugin Installation in WP Learn Manager, Payment Bypass in LatePoint, Account Takeover in Eventer and SQL Injection in My Calendar
Daily security roundup: an unauthenticated plugin installation in WP Learn Manager, a payment bypass in LatePoint, an account takeover in Eventer and an unauthenticated SQL injection in My Calendar.
Read more → Security7 July 2026
Security Bulletin for 7 July 2026: Supply-Chain Backdoor in Uncanny Automator Pro, Code Execution in WPFunnels, File Deletion in Frontend File Manager and File Write in AMP for WP
Daily security roundup: a supply-chain attack with a backdoor in Uncanny Automator Pro, an unauthenticated code execution in WPFunnels, a file deletion in Frontend File Manager and a file write in AMP for WP.
Read more → Security6 July 2026
Security Bulletin for 6 July 2026: Command Injection in File Manager Plugins, File Upload in FileOrganizer, Privilege Escalation in Admin and Site Enhancements and Cross-Site Scripting in Simple Membership
Daily security roundup: a critical command injection in widely used file manager plugins, a file upload in FileOrganizer, an unauthenticated privilege escalation in Admin and Site Enhancements and cross-site scripting in Simple Membership.
Read more → Security5 July 2026
Security Bulletin for 5 July 2026: Critical NoSQL Injection in cve-search, OIDC Account Takeover in Keycloak and a Wave of SQL Injection in PHP Demo Applications
Security roundup: a critical NoSQL injection in the cve-search tool, an OIDC account takeover in Keycloak and a cluster of SQL injection flaws in small PHP demo applications.
Read more → Security4 July 2026
Security Bulletin for 4 July 2026: Privilege Escalation in HestiaCP, Heap Overflow in PHP Core, Stored Cross-Site Scripting in Ultimate Member and PII Tampering in LatePoint
Daily security roundup: a privilege escalation leading to server takeover in the HestiaCP control panel, a heap overflow in PHP core, stored cross-site scripting in Ultimate Member and unauthenticated tampering with customer data in LatePoint.
Read more → Security3 July 2026
Security Bulletin for 3 July 2026: Unauthenticated Stored Cross-Site Scripting in wpDiscuz, File Read in AR for WooCommerce and Cross-Site Scripting in NEX-Forms
Daily security roundup: a login-free stored cross-site scripting flaw in the wpDiscuz comment plugin, an unauthenticated file read in AR for WooCommerce and a stored cross-site scripting flaw in the NEX-Forms plugin.
Read more → Security2 July 2026
Security Bulletin for 2 July 2026: Critical Unauthenticated Remote Code Execution in Divi Form Builder, File Deletion in Printcart, File Read in Ninja Forms File Uploads and File Deletion in the Elementor Image Optimizer Plugin
Daily security roundup: a critical, login-free code execution in Divi Form Builder, an unauthenticated file deletion in the Printcart WooCommerce plugin, an unauthenticated file read in the Ninja Forms File Uploads add-on and a file deletion in the Image Optimizer plugin by Elementor.
Read more → Security1 July 2026
Security Bulletin for 1 July 2026: Critical Unauthenticated Privilege Escalation in PrivateContent, File Deletion in Business Directory, an SQL Injection in BookingPress and Cross-Site Scripting in Enable Media Replace
Daily security roundup: a critical, login-free privilege escalation in the PrivateContent plugin, an unauthenticated file deletion in the Business Directory Plugin, an SQL injection in the BookingPress appointment plugin and cross-site scripting in the widely used Enable Media Replace.
Read more → Security30 June 2026
Security Bulletin for 30 June 2026: Critical Unauthenticated SQL Injection in EventON, Account Takeover in ProfileGrid and a Deserialization Flaw in Export User Data
Daily security roundup: a critical, login-free SQL injection in the EventON calendar, an unauthenticated account takeover in ProfileGrid and a deserialization flaw with file deletion in Export User Data.
Read more → Security29 June 2026
Security Bulletin for 29 June 2026: Critical Unauthenticated Account Takeover in the Invoice Generator Plugin, an Authorization Flaw in ProfilePress and Stored Cross-Site Scripting in the SiteOrigin Page Builder
Daily security roundup: a critical, login-free account takeover in the Invoice Generator plugin, an IDOR authorization flaw in the ProfilePress membership plugin and stored cross-site scripting in the widely used SiteOrigin Page Builder.
Read more → Security28 June 2026
Security Bulletin for 28 June 2026: Actively Exploited Remote Code Execution in the Breeze Cache Plugin, an Authentication Bypass in Burst Statistics and an Unauthenticated Flaw in WP Travel Engine
Daily security roundup: actively exploited RCE in the Breeze WordPress cache plugin, an authentication bypass in Burst Statistics and an unauthenticated flaw in WP Travel Engine.
Read more → Security26 June 2026
Security Bulletin for 26 June 2026: Critical File Deletion in Avada Builder and Code Injection in RD Station, Plus a Status Follow-up on Two Open Flaws
Daily security overview: critical flaws in Avada Builder and RD Station, plus a status follow-up on two WordPress plugins that remain unpatched.
Read more → Security25 June 2026
Security Bulletin for 25 June 2026: CRLF Injection in the Laravel Framework and a Critical Account Takeover in the Kirki WordPress Plugin
Daily security overview: a CRLF injection in the Laravel PHP framework and a critical, unauthenticated account takeover in the Kirki WordPress plugin.
Read more → Security24 June 2026
Security Bulletin for 24 June 2026: Two Flaws in WP Activity Log and a SQL Injection in The Events Calendar
Daily security overview: two flaws in the WP Activity Log audit plugin and an unauthenticated SQL injection in The Events Calendar.
Read more → Security23 June 2026
Security Bulletin for 23 June 2026: SQL Injection in Infility Global and Two Still-Unpatched WordPress Plugin Flaws
Daily security overview for WordPress and PHP: a SQL injection in Infility Global and two WordPress plugin flaws that are not yet patched.
Read more → Security22 June 2026
Security Bulletin for 22 June 2026: Privilege Escalation in Vitepos, a Critical Flaw in PhpSpreadsheet, and Cross-Site Scripting in WooCommerce Auction Pro
Daily security overview for WordPress, e-commerce and PHP: privilege escalation in Vitepos, a flaw in PhpSpreadsheet, and XSS in WooCommerce Auction Pro.
Read more →