Settings hijack

Stored XSS in ManageWP Worker

ManageWP Worker versions prior to 4.9.32 contain a stored XSS vulnerability in the brand customisation feature, allowing an attacker with ManageWP account access to inject JavaScript into the WordPress admin dashboard.

29 June 2026

Read more

WP Mail Gateway – Missing Authorisation on Email Settings

The WP Mail Gateway plugin has a critical authorisation flaw in version 1.8 and earlier. Any authenticated user, including a Subscriber with no special permissions, can modify your site's email gateway settings. This means redirecting all outgoing mail to an attacker's server, intercepting password resets, and escalating to administrator access.

15 May 2026

Read more