wordpress 7
- How Patchstack Is Devaluing Vulnerability Research
- CVE-2026-16612: FiboSearch Autocomplete Exposed Password-Protected Products
- CVE-2026-15231: TaxoPress AI Preview Leaked Private Post-Derived Output
- CVE-2026-15248: Meta Box Contributor+ Arbitrary Attachment Deletion
- CVE-2026-11571: When an Email CSV Attachment Stayed Public in Everest Forms
- CVE-2026-11855: Forged Stripe Webhook Metadata to Admin-Context XSS in Simple Membership
- CVE-2026-14224: Easy Appointments Subscriber+ IDOR Enables Cross-User Notification Redirection