CVE Alert: CVE-2026-104766 - latepoint - Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress - https://www.redpacketsecurity.com/cve-alert-cve-2026-104766-latepoint-appointment-booking-plugin-latepoint-calendar-scheduling-for-wordpress/
RedPacket Security
CVE Alert: CVE-2026-104766 - latepoint - Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress - RedPacket…
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all
CVE Alert: CVE-2026-104899 - paoltaia - GeoDirectory – WP Business Directory Plugin and Classified Listings Directory - https://www.redpacketsecurity.com/cve-alert-cve-2026-104899-paoltaia-geodirectory-wp-business-directory-plugin-and-classified-listings-directory/
RedPacket Security
CVE Alert: CVE-2026-104899 - paoltaia - GeoDirectory – WP Business Directory Plugin and Classified Listings Directory - RedPacket…
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions
CVE Alert: CVE-2026-83526 - foliovision - FV Player 8 - https://www.redpacketsecurity.com/cve-alert-cve-2026-83526-foliovision-fv-player-8/
RedPacket Security
CVE Alert: CVE-2026-83526 - foliovision - FV Player 8 - RedPacket Security
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This
CVE Alert: CVE-2026-14335 - smub - Easy Digital Downloads – eCommerce Payments and Subscriptions made easy - https://www.redpacketsecurity.com/cve-alert-cve-2026-14335-smub-easy-digital-downloads-ecommerce-payments-and-subscriptions-made-easy/
RedPacket Security
CVE Alert: CVE-2026-14335 - smub - Easy Digital Downloads – eCommerce Payments and Subscriptions made easy - RedPacket Security
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN
CVE Alert: CVE-2026-77183 - foosales - FooSales – Point of Sale (POS) for WooCommerce - https://www.redpacketsecurity.com/cve-alert-cve-2026-77183-foosales-foosales-point-of-sale-pos-for-woocommerce/
RedPacket Security
CVE Alert: CVE-2026-77183 - foosales - FooSales – Point of Sale (POS) for WooCommerce - RedPacket Security
The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
CVE Alert: CVE-2026-92975 - trainingbusinesspros - Groundhogg — CRM, Newsletters, and Marketing Automation - https://www.redpacketsecurity.com/cve-alert-cve-2026-92975-trainingbusinesspros-groundhogg-crm-newsletters-and-marketing-automation/
RedPacket Security
CVE Alert: CVE-2026-92975 - trainingbusinesspros - Groundhogg — CRM, Newsletters, and Marketing Automation - RedPacket Security
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,
CVE Alert: CVE-2026-96667 - rameez_iqbal - Real Estate Manager – Property Listing and Agent Management - https://www.redpacketsecurity.com/cve-alert-cve-2026-96667-rameez-iqbal-real-estate-manager-property-listing-and-agent-management/
RedPacket Security
CVE Alert: CVE-2026-96667 - rameez_iqbal - Real Estate Manager – Property Listing and Agent Management - RedPacket Security
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name'
CVE Alert: CVE-2026-93775 - eteubert - Podlove Podcast Publisher - https://www.redpacketsecurity.com/cve-alert-cve-2026-93775-eteubert-podlove-podcast-publisher/
RedPacket Security
CVE Alert: CVE-2026-93775 - eteubert - Podlove Podcast Publisher - RedPacket Security
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including,
[EXITIUM] - Ransomware Victim: KOIKE Sanso Kogoyo Co[.] Ltd[.] - https://www.redpacketsecurity.com/exitium-ransomware-victim-koike-sanso-kogoyo-co-ltd/
RedPacket Security
[EXITIUM] - Ransomware Victim: KOIKE Sanso Kogoyo Co[.] Ltd[.] - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: Secretaría de Modernización e Innovación del Municipio - https://www.redpacketsecurity.com/qilin-ransomware-victim-secretaria-de-modernizacion-e-innovacion-del-municipio/
RedPacket Security
[QILIN] - Ransomware Victim: Secretaría de Modernización e Innovación del Municipio - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: ACI Proyectos SAS - https://www.redpacketsecurity.com/qilin-ransomware-victim-aci-proyectos-sas/
RedPacket Security
[QILIN] - Ransomware Victim: ACI Proyectos SAS - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
HackerOne Bug Bounty Disclosure: information-disclosure-unauthen-leak-private-content-truong-nguyen-long - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-information-disclosure-unauthen-leak-private-content-truong-nguyen-long/
RedPacket Security
HackerOne Bug Bounty Disclosure: information-disclosure-unauthen-leak-private-content-truong-nguyen-long - RedPacket Security
CompanyWordPress
CVE Alert: CVE-2026-100196 - wp_media - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes - https://www.redpacketsecurity.com/cve-alert-cve-2026-100196-wp-media-lazyload-plugin-lazy-load-images-videos-and-iframes/
RedPacket Security
CVE Alert: CVE-2026-100196 - wp_media - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes - RedPacket Security
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content
CVE Alert: CVE-2026-96682 - 2winfactor - Presto Player - https://www.redpacketsecurity.com/cve-alert-cve-2026-96682-2winfactor-presto-player/
RedPacket Security
CVE Alert: CVE-2026-96682 - 2winfactor - Presto Player - RedPacket Security
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via <presto-player> Tag in all versions up to,
CVE Alert: CVE-2026-107742 - 10web - 10Web Booster – Website speed optimization, Cache & Page Speed optimizer - https://www.redpacketsecurity.com/cve-alert-cve-2026-107742-10web-10web-booster-website-speed-optimization-cache-page-speed-optimizer/
RedPacket Security
CVE Alert: CVE-2026-107742 - 10web - 10Web Booster – Website speed optimization, Cache & Page Speed optimizer - RedPacket Security
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE Alert: CVE-2026-100161 - villatheme - Photo Reviews for WooCommerce - https://www.redpacketsecurity.com/cve-alert-cve-2026-100161-villatheme-photo-reviews-for-woocommerce/
RedPacket Security
CVE Alert: CVE-2026-100161 - villatheme - Photo Reviews for WooCommerce - RedPacket Security
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all
CVE Alert: CVE-2026-12626 - ladela - Online Scheduling and Appointment Booking System – Bookly - https://www.redpacketsecurity.com/cve-alert-cve-2026-12626-ladela-online-scheduling-and-appointment-booking-system-bookly/
RedPacket Security
CVE Alert: CVE-2026-12626 - ladela - Online Scheduling and Appointment Booking System – Bookly - RedPacket Security
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,
CVE Alert: CVE-2026-94538 - JoomUnited - WP File Download - https://www.redpacketsecurity.com/cve-alert-cve-2026-94538-joomunited-wp-file-download/
RedPacket Security
CVE Alert: CVE-2026-94538 - JoomUnited - WP File Download - RedPacket Security
The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not
CVE Alert: CVE-2026-95684 - e4jvikwp - VikBooking Hotel Booking Engine & PMS - https://www.redpacketsecurity.com/cve-alert-cve-2026-95684-e4jvikwp-vikbooking-hotel-booking-engine-pms/
RedPacket Security
CVE Alert: CVE-2026-95684 - e4jvikwp - VikBooking Hotel Booking Engine & PMS - RedPacket Security
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments' Parameter in all versions up
[UMBRA] - Ransomware Victim: Helwan University (HITU) - https://www.redpacketsecurity.com/umbra-ransomware-victim-helwan-university-hitu/
RedPacket Security
[UMBRA] - Ransomware Victim: Helwan University (HITU) - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[REDACT] - Ransomware Victim: DexCom - https://www.redpacketsecurity.com/redact-ransomware-victim-dexcom/
RedPacket Security
[REDACT] - Ransomware Victim: DexCom - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating