News Security Critical authentication bypass reported in User Profile Builder plugin August 18, 2026 by Alex Mira | Leave a Comment Wordfence reports a critical authentication bypass in the User Profile Builder plugin (CVE-2026-15826) that can log attackers in as user ID 1 under specific settings. Update to version 3.16.5 and review autologin configuration. Read more » Authentication bypass CVE-2026-15826 Plugin vulnerability User Profile Builder Website security Wordfence WordPress security
News Security CVE-2026-18072: Backdoored ARVE plugin enables admin logins without credentials July 29, 2026 / July 29, 2026 by Alex Mira | Leave a Comment CVE-2026-18072 affects Advanced Responsive Video Embedder (ARVE) 10.8.7, where a hardcoded backdoor can grant admin access without credentials. Check your version and remove 10.8.7 immediately if present. Read more » ARVE plugin Authentication bypass CVE-2026-18072 incident response plugin supply chain WordPress security
News Critical auth bypass in Burst Statistics plugin puts 200,000 WordPress sites at risk June 2, 2026 / June 2, 2026 by Alex Mira | Leave a Comment A critical auth bypass in the Burst Statistics WordPress plugin (CVE-2026-8181) could let attackers impersonate admins via the REST API. A patch is available; update now. A separate low-severity bypass in Advanced Access Manager (CVE-2026-42674) is fixed in 7.1.1. Read more » Advanced Access Manager Authentication bypass Burst Statistics CVE-2026-8181 Patch management Vulnerabilities WordPress security