No authentication is required for the attack. In other words, a request that should merely point WordPress toward a page can, under vulnerable conditions, become a route straight into the server The WordPress security team has released emergency update 7.1.2 to address CVE-2026-87902, a critical vulnerability rated 9.2 on the CVSS scale. Under certain server and theme configurations, the flaw can allow an unauthenticated attacker to achieve remote code execution on the server. WordPress Can Be...
Modified: 09/23/2026The issue affects the vast majority of websites running recent versions of the popular content management system The WordPress development team has released emergency security updates after disclosing two core vulnerabilities that can be combined into a critical attack chain. The issue affects the vast majority of websites running recent versions of the popular content management system. One Request Is All It Takes According to the official security advisory ...
Modified: 07/22/2026A critical vulnerability has been discovered in Tassos Framework, a widely used foundation for extensions in the Joomla ecosystem. The issue lies in an AJAX handler and effectively behaves like an unlocked door — one that does not ask who is entering. The framework underpins several popular plugins, including Convert Forms, EngageBox, Advanced Custom Fields, and Google Structured Data. In practical terms, sites relying on multiple Tassos-based extensions may be dealing with a shared point of failure...
Modified: 04/02/2026The U.S. Cybersecurity and Infrastructure Security Agency, CISA, has added two flaws in the widely used email client Roundcube Webmail to its catalog of known actively exploited vulnerabilities. This is not a case of theoretical risk or academic curiosity — both issues have already been observed in real-world attacks. A Near-Perfect Score for Attackers The first vulnerability, tracked as CVE-2025-49113, carries a CVSS score ...
Modified: 02/26/2026