Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 398+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
Medium
ProfileGrid Unauthenticated Payment Bypass via PayPal IPN Forgery CVE-2026-12688
CVE-2026-12688 · wpscan.com · 2026-07-24
ProfileGrid <= 5.9.9.5
Read more
Medium
ProfileGrid < 5.9.9.7 Pre-Auth Missing Authorization License Tampering
CVE-2026-12690 · wpscan.com · 2026-07-24
ProfileGrid < 5.9.9.7
Read more
Critical
WordPress CAFEHAUS API Unauthenticated Arbitrary User Password Reset (CVE-2026-12981)
CVE-2026-12981 · wpscan.com · 2026-07-24
cafe-api <= 1.0.0
Read more
High
Unauthenticated SQL Injection in WordPress Plugin Software Issue Manager < 5.1.0
CVE-2026-12877 · wpscan.com · 2026-07-24
software-issue-manager < 5.1.0
Read more
High
WP Compress < 7.10.04 Reflected XSS via test_zone (CVE-2026-9066)
CVE-2026-9066 · wpscan.com · 2026-07-23
WP Compress < 7.10.04
Read more
High
Post Status Notifier Lite < 1.13.0 Reflected XSS Vulnerability (CVE-2026-9577) Advisory
CVE-2026-9577 · wpscan.com · 2026-07-23
post-status-notifier-lite < 1.13.0
Read more
High
Praison AI SEO <5.0.7 Unauthenticated BOLA and Settings Disclosure
CVE-2026-12082 · wpscan.com · 2026-07-23
seo-wordpress < 5.0.7
Read more
High
WordPress Security Ninja Premium < 5.290 Two-Factor Authentication Bypass (CVE-2026-14291) with PoC
CVE-2026-14291 · wpscan.com · 2026-07-23
Security Ninja (Premium) < 5.290
Read more
High
Events Manager <7.3.7 Unauthenticated SQL Injection via PHP Object Injection with PoC
CVE-2026-12987 · wpscan.com · 2026-07-22
Events Manager < 7.3.7
Read more
High
Product Addons < 1.6.15 Unauthenticated Stored XSS via SVG Upload (CVE-2026-12968)
CVE-2026-12968 · wpscan.com · 2026-07-22
Product Addons < 1.6.15
Read more
High
CVE-2026-11767: Unauthenticated Stored XSS in CRT Addons for Elementor < 1.6.7
CVE-2026-11767 · wpscan.com · 2026-07-21
CRT Addons for Elementor < 1.6.7
Read more
Medium
WordPress Academy LMS IDOR Vulnerability (CVE-2026-14184) Advisory
CVE-2026-14184 · wpscan.com · 2026-07-21
Academy LMS < 3.8.1
Read more
Medium
WPBot AI ChatBot <= 8.1.0 Subscriber+ Missing Authorization to Modify RAG Settings
CVE-2026-14185 · wpscan.com · 2026-07-21
WPBot AI ChatBot < 8.2.0
Read more
Medium
WordPress Classified Listing IDOR Vulnerability (CVE-2026-14183)
CVE-2026-14183 · wpscan.com · 2026-07-21
classified-listing < 5.3.9
Read more
High
Bpost Shipping Platform < 3.2.3 Unauthenticated SQL Injection
CVE-2026-8082 · wpscan.com · 2026-07-21
Bpost Shipping Platform < 3.2.3
Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.