❌

Normal view

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

5 September 2026 at 15:00

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.

The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

4 September 2026 at 14:06

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.

The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek.

Critical Flaw Allowed to Azure Cosmos DB Pwnage

31 July 2026 at 11:04

Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.

The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek.

❌