[QILIN] - Ransomware Victim: Glenhardie Country Club - https://www.redpacketsecurity.com/qilin-ransomware-victim-glenhardie-country-club/
RedPacket Security
[QILIN] - Ransomware Victim: Glenhardie Country Club - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: LD Constructora - https://www.redpacketsecurity.com/qilin-ransomware-victim-ld-constructora/
RedPacket Security
[QILIN] - Ransomware Victim: LD Constructora - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[RHYSIDA] - Ransomware Victim: Gress Clark Young & Schoepper - https://www.redpacketsecurity.com/rhysida-ransomware-victim-gress-clark-young-schoepper/
RedPacket Security
[RHYSIDA] - Ransomware Victim: Gress Clark Young & Schoepper - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-89301 - rtcamp - rtMedia for WordPress, BuddyPress and bbPress - https://www.redpacketsecurity.com/cve-alert-cve-2026-89301-rtcamp-rtmedia-for-wordpress-buddypress-and-bbpress/
RedPacket Security
CVE Alert: CVE-2026-89301 - rtcamp - rtMedia for WordPress, BuddyPress and bbPress - RedPacket Security
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the
CVE Alert: CVE-2026-104725 - trainingbusinesspros - Groundhogg — CRM, Newsletters, and Marketing Automation - https://www.redpacketsecurity.com/cve-alert-cve-2026-104725-trainingbusinesspros-groundhogg-crm-newsletters-and-marketing-automation/
RedPacket Security
CVE Alert: CVE-2026-104725 - trainingbusinesspros - Groundhogg — CRM, Newsletters, and Marketing Automation - RedPacket Security
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,
CVE Alert: CVE-2026-104723 - lifterlms - LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - https://www.redpacketsecurity.com/cve-alert-cve-2026-104723-lifterlms-lifterlms-wp-lms-for-elearning-online-courses-quizzes/
RedPacket Security
CVE Alert: CVE-2026-104723 - lifterlms - LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - RedPacket Security
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
CVE Alert: CVE-2026-104797 - nasirahmed - Advanced Form Integration — Connect Forms to 300+ Apps - https://www.redpacketsecurity.com/cve-alert-cve-2026-104797-nasirahmed-advanced-form-integration-connect-forms-to-300-apps/
RedPacket Security
CVE Alert: CVE-2026-104797 - nasirahmed - Advanced Form Integration — Connect Forms to 300+ Apps - RedPacket Security
The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all
CVE Alert: CVE-2026-104021 - hostspa - Fastcache by Host.it - https://www.redpacketsecurity.com/cve-alert-cve-2026-104021-hostspa-fastcache-by-host-it/
RedPacket Security
CVE Alert: CVE-2026-104021 - hostspa - Fastcache by Host.it - RedPacket Security
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings`
CVE Alert: CVE-2026-104766 - latepoint - Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress - https://www.redpacketsecurity.com/cve-alert-cve-2026-104766-latepoint-appointment-booking-plugin-latepoint-calendar-scheduling-for-wordpress/
RedPacket Security
CVE Alert: CVE-2026-104766 - latepoint - Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress - RedPacket…
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all
CVE Alert: CVE-2026-104899 - paoltaia - GeoDirectory – WP Business Directory Plugin and Classified Listings Directory - https://www.redpacketsecurity.com/cve-alert-cve-2026-104899-paoltaia-geodirectory-wp-business-directory-plugin-and-classified-listings-directory/
RedPacket Security
CVE Alert: CVE-2026-104899 - paoltaia - GeoDirectory – WP Business Directory Plugin and Classified Listings Directory - RedPacket…
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions
CVE Alert: CVE-2026-83526 - foliovision - FV Player 8 - https://www.redpacketsecurity.com/cve-alert-cve-2026-83526-foliovision-fv-player-8/
RedPacket Security
CVE Alert: CVE-2026-83526 - foliovision - FV Player 8 - RedPacket Security
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This
CVE Alert: CVE-2026-14335 - smub - Easy Digital Downloads – eCommerce Payments and Subscriptions made easy - https://www.redpacketsecurity.com/cve-alert-cve-2026-14335-smub-easy-digital-downloads-ecommerce-payments-and-subscriptions-made-easy/
RedPacket Security
CVE Alert: CVE-2026-14335 - smub - Easy Digital Downloads – eCommerce Payments and Subscriptions made easy - RedPacket Security
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN
CVE Alert: CVE-2026-77183 - foosales - FooSales – Point of Sale (POS) for WooCommerce - https://www.redpacketsecurity.com/cve-alert-cve-2026-77183-foosales-foosales-point-of-sale-pos-for-woocommerce/
RedPacket Security
CVE Alert: CVE-2026-77183 - foosales - FooSales – Point of Sale (POS) for WooCommerce - RedPacket Security
The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
CVE Alert: CVE-2026-92975 - trainingbusinesspros - Groundhogg — CRM, Newsletters, and Marketing Automation - https://www.redpacketsecurity.com/cve-alert-cve-2026-92975-trainingbusinesspros-groundhogg-crm-newsletters-and-marketing-automation/
RedPacket Security
CVE Alert: CVE-2026-92975 - trainingbusinesspros - Groundhogg — CRM, Newsletters, and Marketing Automation - RedPacket Security
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,
CVE Alert: CVE-2026-96667 - rameez_iqbal - Real Estate Manager – Property Listing and Agent Management - https://www.redpacketsecurity.com/cve-alert-cve-2026-96667-rameez-iqbal-real-estate-manager-property-listing-and-agent-management/
RedPacket Security
CVE Alert: CVE-2026-96667 - rameez_iqbal - Real Estate Manager – Property Listing and Agent Management - RedPacket Security
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name'
CVE Alert: CVE-2026-93775 - eteubert - Podlove Podcast Publisher - https://www.redpacketsecurity.com/cve-alert-cve-2026-93775-eteubert-podlove-podcast-publisher/
RedPacket Security
CVE Alert: CVE-2026-93775 - eteubert - Podlove Podcast Publisher - RedPacket Security
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including,
[EXITIUM] - Ransomware Victim: KOIKE Sanso Kogoyo Co[.] Ltd[.] - https://www.redpacketsecurity.com/exitium-ransomware-victim-koike-sanso-kogoyo-co-ltd/
RedPacket Security
[EXITIUM] - Ransomware Victim: KOIKE Sanso Kogoyo Co[.] Ltd[.] - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: Secretaría de Modernización e Innovación del Municipio - https://www.redpacketsecurity.com/qilin-ransomware-victim-secretaria-de-modernizacion-e-innovacion-del-municipio/
RedPacket Security
[QILIN] - Ransomware Victim: Secretaría de Modernización e Innovación del Municipio - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: ACI Proyectos SAS - https://www.redpacketsecurity.com/qilin-ransomware-victim-aci-proyectos-sas/
RedPacket Security
[QILIN] - Ransomware Victim: ACI Proyectos SAS - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
HackerOne Bug Bounty Disclosure: information-disclosure-unauthen-leak-private-content-truong-nguyen-long - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-information-disclosure-unauthen-leak-private-content-truong-nguyen-long/
RedPacket Security
HackerOne Bug Bounty Disclosure: information-disclosure-unauthen-leak-private-content-truong-nguyen-long - RedPacket Security
CompanyWordPress
CVE Alert: CVE-2026-100196 - wp_media - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes - https://www.redpacketsecurity.com/cve-alert-cve-2026-100196-wp-media-lazyload-plugin-lazy-load-images-videos-and-iframes/
RedPacket Security
CVE Alert: CVE-2026-100196 - wp_media - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes - RedPacket Security
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content