10 CVEs published in the last four months and 3 stories. Exploited flaws first.

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

A critical vulnerability in the Forminator WordPress plugin, used by over 600,000 sites, allows unauthenticated attackers to execute arbitrary code. This is achieved by exploiting a flaw that permits the upload of malicious PHP files. The vulnerability has a high severity rating.

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,