Skip to content
Threat Feed

Vendor

WordPress Foundation

6 briefs RSS
high advisory

TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)

An unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.

TrueBooker – Appointment Booking and Scheduler System plugin +1 wordpress sqli plugin web-vulnerability cve
1r 2t 1c
critical advisory

MountDev AI MCP Connector WordPress Plugin Vulnerability Allows Unauthenticated Admin Access (CVE-2026-15015)

An authorization bypass vulnerability, CVE-2026-15015, in all versions up to 1.6.1 of the MountDev AI MCP Connector for WordPress plugin allows unauthenticated attackers to obtain an administrator-bound OAuth Bearer token by exploiting publicly accessible client registration and an unprotected authorization endpoint, granting full administrator-equivalent access to the plugin's tool surface and WordPress content.

MountDev AI MCP Connector for WordPress plugin <= 1.6.1 +1 wordpress authorization-bypass cve webserver privilege-escalation
1r 2t 1c
high advisory

WordPress: Multiple Vulnerabilities Enable Code Execution

A remote, unauthenticated attacker can exploit multiple, unspecified vulnerabilities in WordPress to execute arbitrary program code, potentially leading to a complete compromise of the web server hosting the instance.

WordPress rce web-application
1t
high advisory

CVE-2026-15005 - WordPress Loco Translate Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery vulnerability (CVE-2026-15005) in the WordPress Loco Translate plugin, affecting all versions up to 2.8.5, allows unauthenticated attackers to achieve remote code execution by tricking an administrator into clicking a malicious link, leading to arbitrary PHP code execution via `php://filter` stream wrapper abuse.

Loco Translate +1 wordpress plugin csrf rce cve
1r 2t 1c
critical advisory

Critical RCE Vulnerability in Blocksy Companion Pro WordPress Plugin (CVE-2026-58480)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-58480) in Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47 allows attackers to bypass extension validation via double-extension files, leading to remote code execution by forcing the web server to execute uploaded PHP files.

PoC Blocksy Companion Pro plugin < 2.1.47 +2 wordpress plugin rce file-upload web
1r 3t 2c 1i updated
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +516 roundup
10c 227i updated