[vulnfeed] 2 critical CVEs — 2026-08-01 08:00 UTC
vulnfeed
Critical alert — 2026-08-01 10:13 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-15964CRITICAL
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated pas
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_aj
CVSS 9.8
CVE-2026-3141CRITICAL
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capab
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versio
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: