Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Brandon Steed

#15012of 56,330
19.2Total CVSS
Vulnerabilities · 2
Critical
2
PT-2026-71007
9.8
2026-08-12
WordPress · Giftware · CVE-2026-15039
**Name of the Vulnerable Software and Affected Versions** giftware WordPress plugin versions prior to 4.2.10 **Description** The plugin fails to validate the type of uploaded files in one of its upload paths. This allows unauthenticated users to upload arbitrary files, such as PHP code, which can result in remote code execution (RCE), a state where an attacker can execute arbitrary commands on the server. **Recommendations** Update giftware WordPress plugin to version 4.2.10 or later.
PT-2026-67081
9.4
2026-08-03
WordPress · Simple Membership · CVE-2026-15930
**Name of the Vulnerable Software and Affected Versions** Simple Membership WordPress plugin versions prior to 4.7.8 **Description** The plugin fails to verify if user creation was successful during the registration process before utilizing the returned value as a user ID to update an account. This flaw allows unauthenticated attackers to overwrite the primary administrator account data, such as the email address, enabling full account takeover via the password reset mechanism. **Recommendations** Update Simple Membership WordPress plugin to version 4.7.8 or later.