OpenAI’s new ChatGPT Admin plugin lets workspace admins manage users and permissions, analyze usage, and build reports ...
Two miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability ...
WordPress SAML SSO vulnerability in the miniOrange plugin is being actively exploited -- attackers can log in as any ...
Threat actors have been hacking WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange ...
Two critical miniOrange SAML 2.0 SSO flaws let unauthenticated attackers take over WordPress accounts, including admins.
Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On WordPress plugin could allow unauthenticated attackers ...
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign ...
A critical security vulnerability in the Pods WordPress plugin could allow unauthenticated attackers to seize ...
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
GatekeepWP announces a CAPTCHA free WordPress anti spam plugin designed to measure spam that existing protection may fail to ...
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.