Articles
Newsflash
27 Jul 2026 Business and Enterprise Solutions
WordPress: Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in Breeze Cache

In Breeze Cache component for WordPress versions before 2.5.6 a medium severity vulnerability CVE-2026-10551 was detected. This vulnerability allows an attacker to inject arbitrary HTML attributes in the final HTML output. To address this issue, users should upgrade Breeze Cache to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10551.

Read more
CMS
27 Jul 2026 Business and Enterprise Solutions
WordPress: Payment Forgery Vulnerability in User Registration & Membership

In User Registration & Membership component for WordPress versions before 5.2.2 a critical severity vulnerability CVE-2026-11964 was detected. This vulnerability allows unauthenticated attackers to forge a payment-approved event and activate a paid membership without completing a real payment. To address this issue, users should upgrade User Registration & Membership to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11964.

Read more
CMS
27 Jul 2026 Business and Enterprise Solutions
WordPress: PHP Object Injection in Database for Contact Form 7, WPforms, Elementor forms plugin

In Database for Contact Form 7, WPforms, Elementor forms WordPress plugin component for WordPress versions before 1.5.2 a medium severity vulnerability CVE-2026-12081 was detected. This vulnerability allows unauthenticated users to inject arbitrary PHP objects. To address this issue, users should upgrade Database for Contact Form 7, WPforms, Elementor forms WordPress plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12081.

Read more
CMS
27 Jul 2026 Business and Enterprise Solutions
WordPress: Authorization Bypass in User Registration & Membership plugin

In User Registration & Membership component for WordPress versions before 5.2.2 a high severity vulnerability CVE-2026-11963 was detected. This vulnerability allows any authenticated user to change another user’s WordPress role and membership tier. To address this issue, users should upgrade User Registration & Membership to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11963.

Read more
CMS
27 Jul 2026 Business and Enterprise Solutions
WordPress: Unauthorized Quiz Modification in Tutor LMS

In Tutor LMS component for WordPress versions before 3.9.13 a medium severity vulnerability CVE-2026-12271 was detected. This vulnerability allows authenticated users to modify and force-complete other students’ quiz attempts. To address this issue, users should upgrade Tutor LMS to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12271.

Read more
CMS
24 Jul 2026 Infrastructure and Network
Zeek: Denial of Service Vulnerability

In Zeek versions before 8.0.9 a high severity vulnerability CVE-2026-60109 was detected. This vulnerability allows unauthenticated remote attackers to cause a denial of service. To address this issue, users should upgrade Zeek to version 8.0.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60109.

Read more
Security
Case Studies