#plugin


Ninja Forms plugin vulnerability exploited by hackers. Urgent patching required!

Apr 8, 2026 // 01:17

A serious security hole exists in the Ninja Forms File Uploads add-on for WordPress, allowing unauthorized users to upload any type of file, potentially leading […]

CVE-2026-2313: Unauthenticated SQL Injection in Elementor Ally Plugin Impacts 250k+ Sites

Mar 11, 2026 // 23:30

A critical SQL Injection (SQLi) vulnerability has been discovered in the Elementor Ally plugin, putting over 250,000 WordPress sites at risk of complete database takeover. The Vulnerability: CVE-2026-0814 The flaw exists […]

CVE-2026-1492: Hackers Actively Exploiting User Registration & Membership Plugin for Admin Access

Mar 5, 2026 // 23:02

A critical zero-day vulnerability in the User Registration & Membership plugin for WordPress (CVE-2026-1492) is currently being exploited to create unauthorized administrator accounts.  The flaw allows unauthenticated […]