Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 43138+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 7.2
File Upload Vulnerability in gallery-plugin (v4.0.0-4.0.9)
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview This vulnerability pertains to the file upload functionality within the `gallery-plugin` plugin. Attackers can exploit this by crafting specific requests to upload malicious…

Read more
CVSS 7.2
Analysis of Input Validation Flaw in InfillityGlobalErrorRecord.php
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview This web page screenshot displays a PHP file named `InfillityGlobalErrorRecord.php`, which contains a potential security vulnerability. The vulnerability relates to the hand…

Read more
CVSS 7.2
WordPress Infillity Global Error Record Arbitrary File Write and RCE Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The webpage screenshot displays a PHP file named `InfillityGlobalErrorRecord.php`, which contains a potential security vulnerability. The vulnerability primarily involves im…

Read more
CVSS 7.2
Bookly Plugin Reflected XSS: Unvalidated User Input in diagnostics.js via AJAX
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The webpage screenshot displays the source code file `diagnostics.js` from the plugin `bookly-responsive-appointment-booking-tool`. A potential security vulnerability exists…

Read more
CVSS 7.2
Bookly Plugin <27.7 Unauthorized Access via PluginsUpdater.php
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The webpage screenshot displays a PHP file named `PluginsUpdater.php`, which is part of the Bookly plugin source code. The file contains a potential security vulnerability, …

Read more
CVSS 7.2
WordPress Bookly Plugin Unauthenticated Update Bypass via speedUpUpdateAddons
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The provided webpage screenshot displays the source code file `PluginsUpdater.php` for the WordPress plugin `bookly-responsive-appointment-booking-tool`. The file contains a…

Read more
CVSS 7.2
WordPress Bookly Plugin SQL Injection Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The provided webpage screenshot displays the `Ajax.php` source code file for a WordPress plugin named `bookly-responsive-appointment-booking-tool`. A potential security vuln…

Read more
CVSS 7.2
Bookly WordPress Plugin RCE Vulnerability in PluginsUpdater.php with POC
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The webpage screenshot displays the source code file `PluginsUpdater.php` of a WordPress plugin named `bookly-responsive-appointment-booking-tool`. The file contains a poten…

Read more
CVSS 7.2
Analysis of Data Import Vulnerability in WordPress Bookly Plugin
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The screenshot from the webpage displays the source code file `Ajax.php` of the WordPress plugin named `bookly-responsive-appointment-booking-tool`. A potential security vul…

Read more
CVSS 7.5
wp-travel-engine AJAX Privilege Escalation Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The screenshot of this webpage displays a file named `AjaxController.php`, which is part of the WordPress plugin `wp-travel-engine`. The file contains a potential security v…

Read more
CVSS 7.5
WordPress wp-travel-engine Plugin Stored XSS Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The provided webpage screenshot displays the source code file `AddToCart.php` of the WordPress plugin named `wp-travel-engine`. A potential security vulnerability exists wit…

Read more
CVSS 7.5
wp-travel-engine AJAX Unauthorized Access Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The screenshot above shows a snippet of code from the file `AjaxController.php`, which is part of the `wp-travel-engine` plugin's source code. This file contains a potential…

Read more
CVSS 7.5
wp-travel-engine WordPress Plugin Input Validation Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The webpage screenshot displays the source code file `AddToCart.php` for the WordPress plugin named `wp-travel-engine`. The file contains a potential security vulnerability,…

Read more
CVSS 7.5
wp-travel-engine plugin unauthorized access vulnerability and fix details
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The provided web screenshot displays the source code of the `AddToCart.php` file from the WordPress plugin `wp-travel-engine`. The file contains a potential security vulnera…

Read more
CVSS 4.9
WordPress Kirki Plugin File Upload Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The provided web screenshot displays a PHP file named `ExportImport.php`, located in the `kirki/tags/6.1.1/includes/Ajax/` directory. This file is involved in the export and…

Read more
CVSS 4.9
WordPress Kirki Plugin Unauthenticated File Upload Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The webpage screenshot displays a file named `kirki/tags/6.1.1/includes/Ajax/ExportImport.php`, which contains a potential security vulnerability. This vulnerability involve…

Read more
CVSS 4.9
WordPress Kirki Plugin Arbitrary File Write Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The screenshot above depicts the `ExportImport.php` file located in the `kirki/tags/6.1.1/includes/Ajax/` directory. This file handles the export and import functionalities …

Read more
CVSS 4.9
Kirki WordPress Plugin Unauthenticated File Upload and Arbitrary Code Execution Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The web screenshot displays a file named `kirki/tags/6.1.1/includes/Ajax/ExportImport.php`, which contains a potential security vulnerability. This vulnerability involves fi…

Read more
CVSS 4.9
WordPress Kirki Plugin Unauthenticated File Upload and RCE via Malicious ZIP Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview The provided web screenshot displays a file named `kirki/tags/6.0.12/includes/Ajax/Exportimport.php`, which contains a potential security vulnerability. This vulnerability i…

Read more
CVSS 4.9
WordPress Kirki Plugin Unauthorized File Upload/RCE Analysis
plugins.trac.wordpress.org · 2026-08-16

### Vulnerability Overview This webpage screenshot displays a file named `kirki/tags/6.0.12/includes/Ajax/Exportimport.php`, which contains a potential vulnerability. The vulnerability involves file u…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.