Ultimate Member – Reflected XSS in Member Directory
The Ultimate Member plugin's Members List page has a sorting feature that accepts user input via GET parameters. The plugin fails to properly escape this input when displaying it back in the HTML, creating a reflected XSS vulnerability.
24 June 2026
Read moreStored XSS in All-in-One WP Security & Firewall
CVE-2026-8438: All-in-One WP Security & Firewall ≤5.4.7 allows unauthenticated attackers to inject persistent JavaScript via unsanitised input, executing in visitors' browsers across the site.
21 June 2026
Read more