Five critical flaws across WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP open sites to takeover and code execution.
Two unauthenticated bugs in the miniOrange SAML plugin let attackers log in as any WordPress user.
Patchstack warns that a CVSS 9.0 flaw in Elementor Pro lets unauthenticated attackers upload PHP files and take over sites.
A critical arbitrary file upload bug in Forminator Forms, running on more than 600,000 WordPress sites, lets unauthenticated attackers execute…
The Avada Builder plugin flaws allow low level users to read server files and unauthenticated attackers to steal database credentials.