Vulnfeed

Archives
Log in
Subscribe
August 16, 2026

[vulnfeed] 4 critical CVEs — 2026-08-16 08:00 UTC

vulnfeed Critical alert — 2026-08-16 08:53 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-16098CRITICAL
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing vali
CVSS 9.8
CVE-2026-18432CRITICAL
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic
CVSS 9.8
CVE-2026-14524CRITICAL
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and inc
CVSS 9.1
CVE-2026-18316CRITICAL
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a mis
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-08-16 12:00 UTC Older → [vulnfeed] 10 critical CVEs — 2026-08-16 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.