A CSRF flaw in the Elementor website builder lets a single link create a rogue administrator account on millions of…
An anonymous commenter could plant a script that ran in an administrator's browser and, from there, uploaded a web shell…
Five critical flaws across WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP open sites to takeover and code execution.
Two unauthenticated bugs in the miniOrange SAML plugin let attackers log in as any WordPress user.
Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.