Stored XSS

Stored XSS in ManageWP Worker

ManageWP Worker versions prior to 4.9.32 contain a stored XSS vulnerability in the brand customisation feature, allowing an attacker with ManageWP account access to inject JavaScript into the WordPress admin dashboard.

29 June 2026

Read more

Stored XSS in All-in-One WP Security & Firewall

CVE-2026-8438: All-in-One WP Security & Firewall ≤5.4.7 allows unauthenticated attackers to inject persistent JavaScript via unsanitised input, executing in visitors' browsers across the site.

21 June 2026

Read more