26th
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
Please refer below article for more details
7th
Two security vulnerabilities affecting Plesk Control panel have been identified
Dear Customers, We would like to inform you that two security vulnerabilities affecting Plesk have been identified. Hotfixes are now available. Blind SQL Injection - CVE-2026-64636 An attacker could extract data from the server database through a read-only SQL injection. Affected Versions: Plesk Versions 18.0.51 up to 18.0.79.4 Fixed ... Read More »
15th
Control Web Panel (CWP) RCE Vulnerability
CVE-2025-67888 Overview CVE-2025-67888 is an unauthenticated OS command injection vulnerability in Control Web Panel (CWP) versions before 0.9.8.1209. The flaw resides in /admin/index.php, where the key GET parameter is not sanitized before being passed to OS command execution when the api parameter is set. Attackers can inject arbitrary shell ... Read More »
6th
