Articles
Newsflash
9 Oct 2026 Business and Enterprise Solutions
WordPress: Path Traversal vulnerability in eesy_ID2WP – Publish InDesign HTML5 plugin

In eesy_ID2WP – Publish InDesign HTML5 plugin component for WordPress versions 1.0.3 and earlier a high severity vulnerability CVE-2026-77193 was detected. This vulnerability allows unauthenticated attackers to read the contents of arbitrary files on the server. To address this issue, users should upgrade eesy_ID2WP – Publish InDesign HTML5 plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77193.

Read more
CMS
9 Oct 2026 Business and Enterprise Solutions
WordPress: Origin Validation Error in YOP Poll plugin

In YOP Poll component for WordPress versions 7.0.10 and earlier a high severity vulnerability CVE-2026-85682 was detected. This vulnerability allows unauthenticated attackers to take over an administrator’s account. To address this issue, users should upgrade YOP Poll to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-85682.

Read more
CMS
9 Oct 2026 Business and Enterprise Solutions
WordPress: Local File Inclusion Vulnerability in Visual Composer Website Builder

In Visual Composer Website Builder component for WordPress versions 45.16.0 and earlier a critical severity vulnerability CVE-2026-12227 was detected. This vulnerability allows unauthenticated attackers to include and execute arbitrary files on the server. To address this issue, users should upgrade Visual Composer Website Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12227.

Read more
CMS
9 Oct 2026 Business and Enterprise Solutions
WordPress: Stored Cross-Site Scripting vulnerability in WP Multilang – Translation and Multilingual Plugin

In WP Multilang – Translation and Multilingual Plugin component for WordPress versions 2.4.31 and earlier a medium severity vulnerability CVE-2026-15731 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade WP Multilang – Translation and Multilingual Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15731.

Read more
CMS
9 Oct 2026 Business and Enterprise Solutions
WordPress: Server-Side Request Forgery vulnerability in Kirki plugin

In the Kirki – Freeform Page Builder, Website Builder & Customizer component for WordPress versions 6.2.0 and earlier a medium severity vulnerability CVE-2026-18335 was detected. This vulnerability allows unauthenticated attackers to make web requests to arbitrary locations from the server. To address this issue, users should upgrade the Kirki plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18335.

Read more
CMS
8 Oct 2026 Communication and Collaboration
Mattermost: Excessive Database Load Vulnerability

In Mattermost versions 11.10.1 and earlier, 11.9.1 and earlier, 11.8.5 and earlier, and 11.7.10 and earlier a medium severity vulnerability CVE-2026-95666 was detected. This vulnerability allows an authenticated user to cause excessive database load. To address this issue, users should upgrade Mattermost to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-95666.

Read more
Communication
Case Studies