Advisories
Vulnerability Advisories
Every CVE we have analysed: what it is, how bad it really is, who is affected and what to do about it. Written by the team that found and disclosed three of them.
| Published | Product | Class | CVSS | CVE | Analysis |
|---|---|---|---|---|---|
| Sep 22, 2026 | WordPress coreHigh | Selector injection: forced theme install, chained to RCE | 7.1 | Pending | Read |
| Sep 15, 2026 | The Events CalendarCritical | Code injection to RCE | 9.8 | CVE-2026-78159 | Read |
| Sep 15, 2026 | Amelia PremiumCritical | Unauthenticated privilege escalation to admin | 9.8 | CVE-2026-9055 | Read |
| Aug 22, 2026 | Forminator FormsCritical | Arbitrary file upload to RCE, unauthenticated | 9.8 | CVE-2026-15748 | Read |
| Aug 22, 2026 | Forminator FormsCritical | PHP object injection to RCE | 9.8 | CVE-2026-66583 | Read |
| Aug 22, 2026 | W3 Total CacheCritical | Path traversal to arbitrary file write | 10.0 | CVE-2026-18051 | Read |
| Aug 22, 2026 | WooCommerce SubscriptionsCritical | PHP object injection to RCE, unauthenticated | 9.8 | CVE-2026-18391 | Read |
| Aug 22, 2026 | WPvivid BackupCritical | Path traversal | 9.1 | CVE-2026-19725 | Read |
| Jul 28, 2026 | vBulletinCritical | Eval injection, pre-auth RCE | 9.8 | CVE-2026-61511 | Read |
| Jul 18, 2026 | WordPress coreCritical | REST batch route confusion, SQL injection, pre-auth RCE | 9.8 | CVE-2026-63030 (+CVE-2026-60137) | Read |
| Aug 14, 2024 | Tutor LMSHigh | SQL injection | 8.8 | CVE-2024-1751 | Read |
| Mar 12, 2024 | AmeliaMedium | Reflected XSS | 6.1 | CVE-2024-1484 | Read |
| Feb 27, 2024 | WP Booking CalendarCritical | SQL injection | 9.8 | CVE-2024-1207 | Read |
Exposure Check
Running one of the affected versions?
We will verify what you actually run, confirm whether the flaw was exploited before you patched, and test the fix. One visit from our team tells you where you stand.
Request a Check