Privilege Escalation in User Registration & Membership
Versions of User Registration & Membership up to 5.1.2 let unauthenticated attackers create administrator accounts via an unguarded AJAX endpoint.
27 June 2026
Read moreBooking Manipulation in WP Travel Engine
CVE-2026-49078: WP Travel Engine ≤6.7.10 lets unauthenticated attackers create fraudulent bookings and access customer data via AJAX endpoints with non-fatal nonce validation.
22 June 2026
Read moreInformation Disclosure in Advanced Custom Fields
CVE-2026-4812: ACF 6.7.0 and earlier let unauthenticated attackers leak internal post, user, and relationship data by manipulating AJAX query parameters.
16 June 2026
Read moreVendor IDOR in WCFM Frontend Manager for WooCommerce
WCFM Frontend Manager for WooCommerce is the dashboard lots of multi-vendor marketplaces sit on top of. It gives each vendor a front-end area to manage their own products, orders and content without ever touching wp-admin. Versions up to and including 6.7.25 had a set of matching authorisation bugs in that dashboard that let any logged-in vendor reach well beyond their own shop. CVE-2026-4896 covers the lot.
6 April 2026
Read moreMissing Authorisation in Product Filter for WooCommerce Lets Anyone Delete Your Filter Data
Product Filter for WooCommerce: unauthorised attackers can delete all filter configurations. Learn about CVE-2026-3138 and protect your store now.
2 April 2026
Read moreUnauthenticated Privilege Escalation in User Registration plugin
There's a critical unauthenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin.
31 March 2026
Read more