Information Disclosure

Information Disclosure in Advanced Custom Fields

CVE-2026-4812: ACF 6.7.0 and earlier let unauthenticated attackers leak internal post, user, and relationship data by manipulating AJAX query parameters.

16 June 2026

Read more

W3 Total Cache Security Token Exposure (CVE-2026-5032)

W3 Total Cache is used on millions of sites and does everything from page caching to CDN integration. But today, I want to talk about a specific security flaw that highlights why "internal maintenance" features can be a liability if they aren't properly locked down.

12 May 2026

Read more