WordPress security bulletins

Stay informed with our up-to-date WordPress CVE security bulletins. We cover known Common Vulnerabilities and Exposures (CVEs) affecting WordPress so you can quickly understand potential risks to your site. Our WordPress security experts help identify and remediate vulnerabilities, giving you a trusted resource for tracking security issues and determining whether your website may be affected.

Hostel Plugin Vulnerability (CVE-2026-1645)

Security Alert Summary The Hostel plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in the custom_currency parameter and the locale_url setting. Authenticated attackers with Administrator-level access can inject…
Read security notice