Vulnerabilities 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. Ionut ArghireAugust 18, 2026
Vulnerabilities CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges. Ionut ArghireMay 27, 2026
Vulnerabilities Ally WordPress Plugin Flaw Exposes Over 200,000 Websites to Attacks The issue allows attackers to inject SQL queries and extract sensitive information from the database. Ionut ArghireMarch 12, 2026
Vulnerabilities Critical Flaw in Donation Plugin Exposed 100,000 WordPress Sites to Takeover A critical vulnerability in the GiveWP WordPress plugin could be exploited for remote code execution and arbitrary file deletion. Ionut ArghireAugust 20, 2024