Stored XSS in ManageWP Worker
ManageWP Worker versions prior to 4.9.32 contain a stored XSS vulnerability in the brand customisation feature, allowing an attacker with ManageWP account access to inject JavaScript into the WordPress admin dashboard.
29 June 2026
Read moreWP Mail Gateway – Missing Authorisation on Email Settings
The WP Mail Gateway plugin has a critical authorisation flaw in version 1.8 and earlier. Any authenticated user, including a Subscriber with no special permissions, can modify your site's email gateway settings. This means redirecting all outgoing mail to an attacker's server, intercepting password resets, and escalating to administrator access.
15 May 2026
Read more