Articles
Newsflash
1 Oct 2026 DevOps
GitLab: File Access and Denial of Service Vulnerability in Terraform Integration

In GitLab versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 a low severity vulnerability CVE-2026-3855 was detected. This vulnerability allows an authenticated user with project-level permissions to access restricted file contents on the server or cause denial of service. To address this issue, users should upgrade GitLab to version 19.1.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3855.

Read more
Developer Tools
1 Oct 2026 Business and Enterprise Solutions
WordPress: HTML Injection Vulnerability in Royal Elementor Addons

In Royal Elementor Addons component for WordPress versions before 1.7.1067 a medium severity vulnerability CVE-2026-13407 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission. To address this issue, users should upgrade Royal Elementor Addons to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13407.

Read more
CMS
1 Oct 2026 Business and Enterprise Solutions
WordPress: Arbitrary Shortcode Execution in Formidable Forms

In Formidable Forms component for WordPress versions before 6.35 a medium severity vulnerability CVE-2026-19857 was detected. This vulnerability allows unauthenticated visitors to execute arbitrary shortcodes with chosen attributes on the server. To address this issue, users should upgrade Formidable Forms to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19857.

Read more
CMS
1 Oct 2026 Business and Enterprise Solutions
WordPress: Payment Bypass Vulnerability in Eventin

In Eventin component for WordPress versions before 4.1.24 a medium severity vulnerability CVE-2026-84906 was detected. This vulnerability allows unauthenticated visitors to mark unpaid orders of any value as paid. To address this issue, users should upgrade Eventin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84906.

Read more
CMS
1 Oct 2026 Business and Enterprise Solutions
WordPress: Improper Booking Capacity Check in Appointment Hour Booking

In Appointment Hour Booking component for WordPress versions before 1.5.95 a medium severity vulnerability CVE-2026-86475 was detected. This vulnerability allows unauthenticated visitors to take slots that are already fully booked. To address this issue, users should upgrade Appointment Hour Booking to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-86475.

Read more
CMS
30 Sep 2026 Business and Enterprise Solutions
WordPress: Cross-Site Scripting vulnerability in MotoPress Hotel Booking plugin

In MotoPress Hotel Booking plugin component for WordPress versions 6.2.4 and earlier a high severity vulnerability CVE-2026-90650 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade MotoPress Hotel Booking plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90650.

Read more
CMS
Case Studies