Skip to main content

NEX-Forms WordPress Plugin Unauthenticated Stored XSS via Form Field Name (CVE-2026-12142)

Scope: NEX-Forms Ultimate Forms Plugin for WordPress Versions up to and Including 9.2.2

WP-BusinessDirectory WordPress Plugin Unauthenticated Arbitrary File Deletion (CVE-2026-6070)

Scope: WP-BusinessDirectory WordPress Plugin Versions up to and Including 4.0.1

CVE-2026-57620 in Exclusive Addons Elementor Plugin

Scope: Exclusive Addons Elementor: from n

parse-server – Supply Chain Incident (CVE-2021-47987)

Scope: parse-server, Git-Based Dependencies

WSO2 API Manager – Server-Side Request Forgery (CVE-2026-2053)

Scope: WSO2 API Manager, Versions 3.1.0, 3.

Subscribe to