CVE-2025-14998: Critical Account Takeover in Branda (Ultimate Branding) Plugin (CVSS 9.8)
CVE-2026-4123 Branda Account Takeover. A critical privilege escalation vulnerability has been discovered in the Branda plugin for WordPress,…
Security vulnerability reports and CVE analysis for WordPress plugins, themes, and core.
CVE-2026-4123 Branda Account Takeover. A critical privilege escalation vulnerability has been discovered in the Branda plugin for WordPress,…
A critical authentication bypass CVE-2026-4119 Create DB Tables vulnerability vulnerability has been discovered in the Comments WordPress plugin,…
If you run a WordPress site using the WebStack theme, there is no patch available for a critical…
CVE-2026-4119 Create DB Tables. A critical authorization bypass vulnerability affects the Create DB Tables WordPress plugin. The disclosure…
A critical SQL injection flaw (CVSS 9.6) in the Contact Form CFDB7 Database Addon plugin allows unauthenticated attackers…
On April 6, 2026, Wordfence publicly disclosed a critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms…
A missing return-value check in WPvivid Backup and Migration turned a failed RSA decryption into an unauthenticated remote…
A privilege escalation flaw in LatePoint lets users with the Agent role rebind customer records to the site…
A path traversal vulnerability in The Events Calendar (CVE-2026-3585) shows how a skipped update and a lingering author…
A CVSS 9.8 Remote Code Execution flaw in Advanced Custom Fields: Extended left 100,000 WordPress sites open to…