News Security Avada zero-click RCE chain (CVE-2026-18431) and a separate Fusion Builder XSS: what WordPress admins should know August 31, 2026 by Alex Mira | Leave a Comment A critical six-step chain in the Avada theme enables zero-click RCE (CVE-2026-18431), and a separate stored XSS impacts Fusion Builder up to 3.15.6 (CVE-2026-16654). Here’s what’s confirmed and what to update now. Read more » Avada theme CVE-2026-16654 CVE-2026-18431 Fusion Builder Remote code execution Stored XSS WordPress security
News Security CVE-2026-82222 in GiveWP: Remote command execution fixed in 4.16.7.2 August 31, 2026 by Alex Mira | Leave a Comment CVE-2026-82222 affects GiveWP through 4.16.7.1 and can lead to remote command execution via an object injection chain. Update to 4.16.7.2 and review recent user registrations. Read more » CVE-2026-82222 GiveWP Patchstack Remote code execution vulnerability Website security wordpress
News Security CVE-2026-32475: Critical Elementor Pro file upload flaw can enable unauthenticated RCE August 21, 2026 by Alex Mira | Leave a Comment Elementor Pro sites with a File Upload field in a public form are exposed to a critical file upload flaw (CVE-2026-32475) that can enable unauthenticated RCE. Update to 4.2.2+ and audit the Elementor forms upload directory. Read more » CVE-2026-32475 Elementor Pro Patch management Plugin Vulnerabilities Remote code execution WordPress security
News Security CISA flags active RCE exploitation in Joomla extensions; separate SQLi fix lands for Quix Page Builder July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment CISA added two actively exploited Joomla extension flaws to its KEV catalog, warning of RCE via file uploads in iCagenda and Balbooa Forms. Separately, Quix Page Builder patched an unauthenticated SQL injection in version 6.2.1. Read more » CISA CMS security cve Joomla Joomla extensions Patch management Remote code execution
News Security Patch now: WordPress Core “wp2shell” chain (CVE-2026-60137, CVE-2026-63030) July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment Two WordPress Core bugs—CVE-2026-60137 and CVE-2026-63030—can be chained for pre-auth RCE on specific versions. Public PoCs exist. Update to 7.0.2 or 6.9.5 now. Read more » CVE-2026-60137 CVE-2026-63030 Remote code execution Security Update SQL injection wordpress
News Security CVE-2026-35273: Critical unauthenticated RCE risk in Oracle PeopleSoft PeopleTools June 22, 2026 / June 22, 2026 by Alex Mira | Leave a Comment Oracle warns of CVE-2026-35273, a critical unauthenticated RCE risk in PeopleSoft PeopleTools 8.61/8.62. Mitigations are available now and immediate action is advised amid reports of active exploitation. Read more » CVE-2026-35273 Mitigation Oracle PeopleSoft PeopleTools Remote code execution Security Alert
News CVE-2026-3300: Active exploits target Everest Forms Pro’s Complex Calculation feature June 7, 2026 / June 7, 2026 by Alex Mira | Leave a Comment CVE-2026-3300 in Everest Forms Pro is under active exploitation. The bug enables unauthenticated remote code execution via the Complex Calculation feature. Update to 1.9.13, audit admin users for “diksimarina,” and review logs for the IPs cited by Wordfence. Read more » CVE-2026-3300 Everest Forms Pro Plugin vulnerability Remote code execution security wordpress
News ScadaBR 1.2.0 flagged by CISA for four serious flaws (CVE-2026-8602 through CVE-2026-8605) May 21, 2026 / May 21, 2026 by Alex Mira | Leave a Comment CISA warns that ScadaBR 1.2.0 contains four vulnerabilities (CVE-2026-8602 to CVE-2026-8605) that could enable unauthenticated RCE, data injection, CSRF abuse, and admin access via hard-coded credentials. Read more » CISA advisory cve Industrial control systems Remote code execution SCADA security ScadaBR