Critical Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7 Plugin
# CVE-2026-5364: Critical Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7 Plugin (CVSS…
# CVE-2026-5364: Critical Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7 Plugin (CVSS…
A supply chain attack targeting the PHP ecosystem has been discovered this week. Security researchers found a backdoor…
Security researchers have identified a new variant of the CrawlerX botnet that specifically targets WooCommerce sites. The latest…
A Reflected Cross-Site Scripting vulnerability has been discovered in the ShopBuilder WordPress plugin for WooCommerce. Tracked as CVE-2025-13456…
A Cross-Site Scripting (XSS) vulnerability has been discovered in the Logo Slider WordPress plugin. Tracked as CVE-2025-13153 with…
CVE-2025-12685 WPBookit CSRF Privilege Escalation. A Cross-Site Request Forgery (CSRF) vulnerability affects the WPBookit WordPress plugin. Tracked as…
CVE-2025-14047 WP User Frontend SQL Injection. An unauthorized data loss vulnerability affects the WP User Frontend plugin for…
A missing capability check vulnerability affects the My Sticky Elements plugin for WordPress. Tracked as CVE-2025-14428 with a…
Patchstack has reported a significant increase in WordPress plugin vulnerabilities during the first quarter of 2026. According to…
WordPress 6.8 introduces several important security improvements that site owners should be aware of. While not a major…