Skip to main content

Devolutions PowerShell Universal Authenticated Code Injection Enables Full Server Compromise (CVE-2026-16801)

Scope: Devolutions PowerShell Universal Versions 2026.2.2 and Earlier

WP Foodbakery WordPress Plugin Subscriber-Level Path Traversal Allows Arbitrary File Deletion Leading to RCE (CVE-2026-15802)

Scope: WP Foodbakery Plugin for WordPress Versions up to and Including 4.9 (No Patch Curre

Oracle July 2026 Critical Patch Update Addresses 1,235 CVEs Across E-Business Suite, HRMS, and Fusion Middleware

Scope: Oracle E-Business Suite (Including Oracle HRMS), Oracle Fusion Middleware, Oracle P

Easy Form Builder by WhiteStudio WordPress Plugin Allows Unauthenticated Full Administrator Takeover (CVE-2026-13439)

Scope: Easy Form Builder by WhiteStudio WordPress Plugin Versions up to and Including 4.0.

Essential Addons for Elementor Stored XSS via Fancy Text Widget Allows Session Hijacking (CVE-2026-15145)

Scope: Essential Addons for Elementor WordPress Plugin Versions up to and Including 6.6.1

WordPress Core Pre-Authentication RCE Chain "wp2shell" Now Has Public Exploits (CVE-2026-63030 / CVE-2026-60137)

Scope: WordPress Core Versions 6.8.0 through 6.8.5 (SQL injection only), 6.9.0 through 6.

VentraConnect WordPress Plugin OTP Brute Force Enables Unauthenticated Administrator Account Takeover (CVE-2026-13142)

Scope: Social Login, Passkeys, Magic Link and Email OTP WordPress Plugin (VentraConnect)

Subscribe to