News Security CVE-2026-19949: Unauthenticated SQL Injection in All‑in‑One WP Migration—Update to 7.110 September 1, 2026 by Alex Mira | Leave a Comment Wordfence reports a high‑severity SQL injection (CVE‑2026‑19949) in All‑in‑One WP Migration and Backup. Update to 7.110. Patchstack lists several other recent SQL injection fixes. Read more » CVE-2026-19949 Plugins security SQL injection Vulnerabilities wordpress
News Security Patch now: WordPress Core “wp2shell” chain (CVE-2026-60137, CVE-2026-63030) July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment Two WordPress Core bugs—CVE-2026-60137 and CVE-2026-63030—can be chained for pre-auth RCE on specific versions. Public PoCs exist. Update to 7.0.2 or 6.9.5 now. Read more » CVE-2026-60137 CVE-2026-63030 Remote code execution Security Update SQL injection wordpress
News CVE-2026-9082: Drupal’s PostgreSQL SQL injection is being probed — update your sites May 30, 2026 / May 30, 2026 by Alex Mira | Leave a Comment Drupal disclosed CVE-2026-9082, a PostgreSQL-only SQL injection in core. Exploit attempts are being observed. Update to the patched Drupal releases as soon as possible. Read more » CMS security CVE-2026-9082 Drupal Patching PostgreSQL SQL injection vulnerability