WordPress Security Update Advisory (CVE-2026-87902)

WordPress Security Update Advisory (CVE-2026-87902)

WordPress Security Update Advisory. CVE-2026-87902, a vulnerability in WordPress that allows PHP files to be included through page template path traversal, has been resolved. Follow the instructions on the reference site to update to the latest version with the Vulnerability Patch. Affected Versions include various WordPress versions ranging from 4.7.0

WordPress Security Update Advisory (CVE-2026-64638)

WordPress Security Update Advisory (CVE-2026-64638)

Overview A security update has been released to address a vulnerability in WordPress. This vulnerability, identified as CVE-2026-64638, is a pre-authentication reflected cross-site scripting (XSS) vulnerability—a type of vulnerability that tricks users into executing malicious scripts—occurring on the WordPress login screen. Affected Versions The affected WordPress versions are as follows:

WordPress Product Security Update Advisory

WordPress Product Security Update Advisory

Overview A security update has been released to address vulnerabilities in WordPress. Users of this product should update to the latest version. Affected Versions WordPress versions: 6.8.0 Through 6.8.5. WordPress versions: 6.9.0 Through 6.9.4. WordPress versions: 7.0.0 Through 7.0.1. Resolved Vulnerabilities CVE-2026-60137: SQL injection vulnerability in WordPress (a vulnerability where

WordPress Plugin Security Update Advisory (CVE-2026-8732)

WordPress Plugin Security Update Advisory (CVE-2026-8732)

Overview A security update has been issued for a vulnerability in the WordPress plugin WP Maps Pro. the vulnerability is an unauthenticated privilege escalation vulnerability (CVE-2026-8732), which can be exploited through the wpgmptempaccess_ajax AJAX Action (a feature that allows web applications to handle asynchronous requests) related to the way threat

WordPress Plugin Security Update Advisory (CVE-2026-1357)

WordPress Plugin Security Update Advisory (CVE-2026-1357)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2026-1357   WPvivid Backup & Migration Version: 0.9.123 and earlier     Resolved Vulnerabilities   Unauthenticated arbitrary file

WordPress Plugin Security Update Advisory (CVE-2025-13486)

WordPress Plugin Security Update Advisory (CVE-2025-13486)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-13486   Advanced Custom Fields: Extended Versions: 0.9.0.5 and later and 0.9.1.1 and earlier     Resolved Vulnerabilities

WordPress Plugin Security Update Advisory (CVE-2025-6389)

WordPress Plugin Security Update Advisory (CVE-2025-6389)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-6389   Sneeit Framework Version: 8.3 and earlier     Resolved Vulnerabilities   Remote code execution vulnerability in

WordPress Plugin Security Update Advisory (CVE-2025-9501)

WordPress Plugin Security Update Advisory (CVE-2025-9501)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-9501   W3 Total Cache versions: 2.8.12 and earlier     Resolved Vulnerabilities   Remote code execution (RCE)

WordPress Plugin Security Update Advisory (CVE-2025-5821)

WordPress Plugin Security Update Advisory (CVE-2025-5821)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-5821   Case-theme-user Version: 1.0.3 and earlier     Resolved Vulnerabilities   Social Login Authentication Bypass Vulnerability in

WordPress Plugin Security Update Advisory (CVE-2025-7384)

WordPress Plugin Security Update Advisory (CVE-2025-7384)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-7384   Contact-form-entries Version: 1.4.3 and earlier     Resolved Vulnerabilities   PHP object injection vulnerability in contact-form-entries