CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  39875 articles  ·  updated every 4 hours · grows forever

39875Total
28949Full Text
Jul 28, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6225 | taskbuilder Taskbuilder Plugin up to 5.0.6 on WordPress project_search sql injection

A vulnerability has been found in taskbuilder Taskbuilder Plugin up to 5.0.6 on WordPress and classified as critical . Affected is an unknown function. This manipulation of the argument project_search…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-3892 | stylemix Motors Plugin up to 1.4.107 on WordPress file inclusion

A vulnerability was found in stylemix Motors Plugin up to 1.4.107 on WordPress and classified as problematic . Affected by this vulnerability is an unknown functionality. Such manipulation leads to fi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-5395 | techjewel Fluent Forms Plugin up to 6.2.0 on WordPress exportEntries authorization

A vulnerability was found in techjewel Fluent Forms Plugin up to 6.2.0 on WordPress. It has been classified as critical . Affected by this issue is the function exportEntries . Performing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6271 | shahinurislam Career Section Plugin up to 1.7 on WordPress unrestricted upload

A vulnerability was found in shahinurislam Career Section Plugin up to 1.7 on WordPress. It has been declared as critical . This affects an unknown part. Executing a manipulation can lead to unrestric…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6506 | Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress infusedwoo_gdpr_upddata authorization

A vulnerability was found in Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress. It has been rated as critical . This vulnerability affects the function infusedwoo_gdpr_upddata . The manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6670 | erolsk8 Media Sync Plugin up to 1.4.9 on WordPress sub_dir/media_items path traversal

A vulnerability categorized as critical has been discovered in erolsk8 Media Sync Plugin up to 1.4.9 on WordPress. This issue affects some unknown processing. The manipulation of the argument sub_dir/…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6510 | Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress AJAX iwar_save_recipe authorization

A vulnerability identified as critical has been detected in Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress. Impacted is the function iwar_save_recipe of the component AJAX Handler . Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-3694 | boldthemes Bold Page Builder Plugin up to 5.6.8 on WordPress bt_bb_button text cross site scripting

A vulnerability labeled as problematic has been found in boldthemes Bold Page Builder Plugin up to 5.6.8 on WordPress. The affected element is the function bt_bb_button . Such manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-5193 | wpdevteam Essential Addons for Elementor Plugin up to 6.5.13 on WordPress register_user privileges management

A vulnerability marked as critical has been reported in wpdevteam Essential Addons for Elementor Plugin up to 6.5.13 on WordPress. The impacted element is the function register_user . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-3718 | managewp ManageWP Worker Plugin up to 4.9.31 on WordPress HTTP Request Header cross site scripting

A vulnerability described as problematic has been identified in managewp ManageWP Worker Plugin up to 4.9.31 on WordPress. This affects an unknown function of the component HTTP Request Header Handler…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-5365 | LatePoint Plugin up to 5.3.2 on WordPress request_cancellation cross-site request forgery

A vulnerability classified as problematic has been found in LatePoint Plugin up to 5.3.2 on WordPress. This impacts the function request_cancellation . The manipulation leads to cross-site request for…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6252 | mr2p Meta Field Block Plugin up to 1.5.2 on WordPress Block Attribute tagName cross site scripting

A vulnerability classified as problematic was found in mr2p Meta Field Block Plugin up to 1.5.2 on WordPress. Affected is an unknown function of the component Block Attribute Handler . The manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6145 | wpeverest User Registration & Membership Plugin up to 5.1.5 on WordPress is_admin_creation_process authorization

A vulnerability, which was classified as critical , has been found in wpeverest User Registration & Membership Plugin up to 5.1.5 on WordPress. Affected by this vulnerability is the function is_admin_…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6514 | Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress popup_submit server-side request forgery

A vulnerability, which was classified as critical , was found in Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress. Affected by this issue is the function popup_submit . Such manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6206 | websoudan MW WP Form Plugin up to 5.1.2 on WordPress _get_post_property_from_querystring authorization

A vulnerability has been found in websoudan MW WP Form Plugin up to 5.1.2 on WordPress and classified as problematic . This affects the function _get_post_property_from_querystring . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6174 | caterhamcomputing CC Child Pages Plugin up to 2.1.1 on WordPress more cross site scripting

A vulnerability was found in caterhamcomputing CC Child Pages Plugin up to 2.1.1 on WordPress and classified as problematic . This vulnerability affects unknown code. Executing a manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6512 | Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress authorization

A vulnerability was found in Infused Addons InfusedWoo Pro Plugin up to 5.1.2 on WordPress. It has been classified as critical . This issue affects some unknown processing. The manipulation leads to m…

VulDB Read →
⬡ Vulnerabilities & CVEs May 14, 2026
CVE-2026-6504 | wproyal Royal Addons for Elementor Plugin up to 1.7.1058 on WordPress title_tag cross site scripting

A vulnerability was found in wproyal Royal Addons for Elementor Plugin up to 1.7.1058 on WordPress. It has been declared as problematic . Impacted is an unknown function. The manipulation of the argum…

VulDB Read →
◇ Industry News & Leadership May 14, 2026
When ransomware gets physical: cybercriminals turn to threats of violence

Pay up, or we'll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats - and even hiring local muscle to deliver the message. Read more in my article on the H…

Graham Cluley Read →
◇ Industry News & Leadership May 14, 2026
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading

Iran-linked hackers have been quietly breaking into networks around the world, and their latest campaign is more calculated than anything we have seen from them before. The group known as Seedworm, al…

Cybersecurity News Read →
◇ Industry News & Leadership May 14, 2026
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak

Packagist is sounding the alarm for PHP developers everywhere. A flaw in Composer, the widely used PHP dependency manager, briefly caused GitHub authentication tokens to leak into publicly visible CI …

Cybersecurity News Read →
◇ Industry News & Leadership May 14, 2026
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker

Attackers are now abusing a fresh Langflow vulnerability to quietly steal cloud keys and turn victim systems into workers for a new NATS based botnet. This campaign shows how a single exposed AI workf…

Cybersecurity News Read →
◇ Industry News & Leadership May 14, 2026
OpenAI Hit with Class-Action Privacy Lawsuit for Sharing ChatGPT Data with Google and Meta

OpenAI Global LLC is facing a new class‑action complaint in the Southern District of California that accuses the company of quietly wiring its ChatGPT web interface with Meta’s Facebook Pixel and Goog…

Cybersecurity News Read →
◇ Industry News & Leadership May 14, 2026
Lyrie.ai Launches the Global Identity Standard for the AI Agent Age & Anthropic’s Cyber Verification Program

DUBAI, UAE — May 11, 2026 — As the internet transitions from a playground of chatbots to a workforce of autonomous agents, the question isn’t just what AI can do—it’s who the AI is. Today, OTT Cyberse…

Cybersecurity News Read →
← Prev 829 / 1662 Next →