ShinyHunters leaked 234 GB of data allegedly stolen from DentaQuest after failed negotiations, potentially impacting 2.6 million people. The ShinyHunters extortion group has published a 234 GB archive of data allegedly stolen from dental benefits administrator DentaQuest. The cybercrime gang added the company to its Tor data leak site in May, and the data was […]
A vulnerability identified as critical has been detected in webfactory Advanced Google reCAPTCHA Plugin up to 5.38 on WordPress. This impacts the function ajax_run_tool of the component AJAX Handler. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is listed as CVE-2026-5415. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as critical has been found in Hippoo Mobile App for WooCommerce Plugin up to 1.9.4 on WordPress. Affected is the function HippooPermissions::get_user_permissions of the file /wc-hippoo/v1/ext of the component REST Endpoint. The manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-10580. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability classified as problematic was found in ThimPress LearnPress Plugin up to 4.3.6 on WordPress. Affected by this issue is some unknown functionality of the file /wp-json/lp/v1/courses/archive-course. Executing a manipulation of the argument return_type can lead to missing authorization.
This vulnerability is registered as CVE-2026-8502. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in wpdevteam Essential Addons for Elementor Plugin up to 6.6.4 on WordPress. Affected by this vulnerability is the function ajax_load_more of the component Elementor Template Handler. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-7665. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in wpdevteam EmbedPress Plugin up to 4.5.3 on WordPress. The affected element is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-7796. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.