WordPress Security Update Advisory (CVE-2026-87902)
WordPress Security Update Advisory. CVE-2026-87902, a vulnerability in WordPress that allows PHP files to be included through page template path traversal, has been resolved. Follow the instructions on the reference site to update to the latest version with the Vulnerability Patch. Affected Versions include various WordPress versions ranging from 4.7.0
WordPress Security Update Advisory (CVE-2026-64638)
Overview A security update has been released to address a vulnerability in WordPress. This vulnerability, identified as CVE-2026-64638, is a pre-authentication reflected cross-site scripting (XSS) vulnerability—a type of vulnerability that tricks users into executing malicious scripts—occurring on the WordPress login screen. Affected Versions The affected WordPress versions are as follows:
WordPress Product Security Update Advisory
Overview A security update has been released to address vulnerabilities in WordPress. Users of this product should update to the latest version. Affected Versions WordPress versions: 6.8.0 Through 6.8.5. WordPress versions: 6.9.0 Through 6.9.4. WordPress versions: 7.0.0 Through 7.0.1. Resolved Vulnerabilities CVE-2026-60137: SQL injection vulnerability in WordPress (a vulnerability where
WordPress Plugin Security Update Advisory (CVE-2026-8732)
Overview A security update has been issued for a vulnerability in the WordPress plugin WP Maps Pro. the vulnerability is an unauthenticated privilege escalation vulnerability (CVE-2026-8732), which can be exploited through the wpgmptempaccess_ajax AJAX Action (a feature that allows web applications to handle asynchronous requests) related to the way threat
WordPress Plugin Security Update Advisory (CVE-2026-1357)
Overview We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version. Affected Products CVE-2026-1357 WPvivid Backup & Migration Version: 0.9.123 and earlier Resolved Vulnerabilities Unauthenticated arbitrary file
WordPress Plugin Security Update Advisory (CVE-2025-13486)
Overview We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-13486 Advanced Custom Fields: Extended Versions: 0.9.0.5 and later and 0.9.1.1 and earlier Resolved Vulnerabilities
WordPress Plugin Security Update Advisory (CVE-2025-6389)
Overview We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-6389 Sneeit Framework Version: 8.3 and earlier Resolved Vulnerabilities Remote code execution vulnerability in
WordPress Plugin Security Update Advisory (CVE-2025-9501)
Overview We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-9501 W3 Total Cache versions: 2.8.12 and earlier Resolved Vulnerabilities Remote code execution (RCE)
WordPress Plugin Security Update Advisory (CVE-2025-5821)
Overview We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-5821 Case-theme-user Version: 1.0.3 and earlier Resolved Vulnerabilities Social Login Authentication Bypass Vulnerability in
WordPress Plugin Security Update Advisory (CVE-2025-7384)
Overview We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-7384 Contact-form-entries Version: 1.4.3 and earlier Resolved Vulnerabilities PHP object injection vulnerability in contact-form-entries

