Advisories

Vulnerability Advisories

Every CVE we have analysed: what it is, how bad it really is, who is affected and what to do about it. Written by the team that found and disclosed three of them.

PublishedProductClassCVSSCVEAnalysis
Sep 22, 2026WordPress coreHighSelector injection: forced theme install, chained to RCE7.1PendingRead
Sep 15, 2026The Events CalendarCriticalCode injection to RCE9.8CVE-2026-78159Read
Sep 15, 2026Amelia PremiumCriticalUnauthenticated privilege escalation to admin9.8CVE-2026-9055Read
Aug 22, 2026Forminator FormsCriticalArbitrary file upload to RCE, unauthenticated9.8CVE-2026-15748Read
Aug 22, 2026Forminator FormsCriticalPHP object injection to RCE9.8CVE-2026-66583Read
Aug 22, 2026W3 Total CacheCriticalPath traversal to arbitrary file write10.0CVE-2026-18051Read
Aug 22, 2026WooCommerce SubscriptionsCriticalPHP object injection to RCE, unauthenticated9.8CVE-2026-18391Read
Aug 22, 2026WPvivid BackupCriticalPath traversal9.1CVE-2026-19725Read
Jul 28, 2026vBulletinCriticalEval injection, pre-auth RCE9.8CVE-2026-61511Read
Jul 18, 2026WordPress coreCriticalREST batch route confusion, SQL injection, pre-auth RCE9.8CVE-2026-63030 (+CVE-2026-60137)Read
Aug 14, 2024Tutor LMSHighSQL injection8.8CVE-2024-1751Read
Mar 12, 2024AmeliaMediumReflected XSS6.1CVE-2024-1484Read
Feb 27, 2024WP Booking CalendarCriticalSQL injection9.8CVE-2024-1207Read
Exposure Check

Running one of the affected versions?

We will verify what you actually run, confirm whether the flaw was exploited before you patched, and test the fix. One visit from our team tells you where you stand.

Request a Check
CVE Advisories: WordPress & Web App Vulnerability Research - IKZERO