Stored XSS in Gutentor WordPress Plugin
Security researchers found a stored cross-site scripting (XSS) flaw in Gutentor. This WordPress page builder plugin has over…
Security researchers found a stored cross-site scripting (XSS) flaw in Gutentor. This WordPress page builder plugin has over…
Overview of CVE-2026-6810 A missing authorization vulnerability affects the Booking Calendar Contact Form plugin. This flaw has a…
Attackers can upload malicious files through MaxiBlocks Builder. This puts your WordPress site at risk. You need to…
# CVE-2026-5364: Critical Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7 Plugin (CVSS…
A supply chain attack targeting the PHP ecosystem has been discovered this week. Security researchers found a backdoor…
Security researchers have identified a new variant of the CrawlerX botnet that specifically targets WooCommerce sites. The latest…
A hardened WordPress site is one where every attack surface is minimized, every configuration is intentional, and no…
Your WordPress database contains everything that makes your site your site: posts, user accounts, plugin settings, WooCommerce orders,…
WordPress uses a built-in cron system (wp-cron.php) to schedule tasks like checking for updates, publishing scheduled posts, running…
A Reflected Cross-Site Scripting vulnerability has been discovered in the ShopBuilder WordPress plugin for WooCommerce. Tracked as CVE-2025-13456…