Elementor Pro: WordPress Plugin with Critical RCE Flaw
A popular WordPress page builder plugin. Versions up to 4.2.1 are vulnerable to unauthenticated PHP upload and RCE (CVE-2026-32475). Patched in 4.2.2.
A popular WordPress page builder plugin. Versions up to 4.2.1 are vulnerable to unauthenticated PHP upload and RCE (CVE-2026-32475). Patched in 4.2.2.
Cybersecurity researchers have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to upload PHP files…
An arbitrary file upload vulnerability in WSO2 products, used by Evooo1Bot.
Active Storage is a Ruby on Rails component for handling file uploads. It is affected by CVE-2026-66066, which allows unauthenticated attackers to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
SP Page Builder by JoomShaper is a Joomla page builder affected by CVE-2026-48908, an unrestricted file upload vulnerability allowing unauthenticated PHP code…
A high-severity flaw in Progress Kemp LoadMaster allows WAF bypass by using whitespace padding in filenames to circumvent file upload extension checks.