Skip to main content

WP Foodbakery WordPress Plugin Subscriber-Level Path Traversal Allows Arbitrary File Deletion Leading to RCE (CVE-2026-15802)

Scope: WP Foodbakery Plugin for WordPress Versions up to and Including 4.9 (No Patch Curre

Oracle July 2026 Critical Patch Update Addresses 1,235 CVEs Across E-Business Suite, HRMS, and Fusion Middleware

Scope: Oracle E-Business Suite (Including Oracle HRMS), Oracle Fusion Middleware, Oracle P

n8n Workflow Automation Platform Triple Vulnerability Chain Enables Server Takeover (CVE-2026-65591 / CVE-2026-65592 / CVE-2026-65598)

Scope: n8n Versions Prior to 1.123.64, 2.29.8, and 2.30.1 (Self-Hosted and Cloud)

MapSVG WordPress Plugin Arbitrary File Upload Allows Administrator-Level Remote Code Execution (CVE-2026-1771)

Scope: MapSVG WordPress Plugin Versions up to and Including 8.14.0

Easy Form Builder by WhiteStudio WordPress Plugin Allows Unauthenticated Full Administrator Takeover (CVE-2026-13439)

Scope: Easy Form Builder by WhiteStudio WordPress Plugin Versions up to and Including 4.0.

Elementor Website Builder REST API Authorization Bypass Exposes Private Posts and Draft Content (CVE-2026-8825)

Scope: Elementor Website Builder Plugin Versions Prior to 4.1.4

Essential Addons for Elementor Stored XSS via Fancy Text Widget Allows Session Hijacking (CVE-2026-15145)

Scope: Essential Addons for Elementor WordPress Plugin Versions up to and Including 6.6.1

Subscribe to Advisories