A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers. [...]
A vulnerability marked as critical has been reported in Genolve Plugin up to 5.0.5 on WordPress. Affected by this vulnerability is the function genolve_setOpt of the component Capability Check. This manipulation causes improper authorization.
This vulnerability appears as CVE-2026-1359. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as problematic has been found in robin-w bbp Style Pack Plugin up to 6.4.5 on WordPress. Affected is the function bsp_topic_fields_form_save/bsp_topic_content_append_topic_fields of the component Topic Form Additional Fields Feature. The manipulation of the argument bsp_topic_fields_label{n} results in cross site scripting.
This vulnerability is reported as CVE-2026-15010. The attack can be launched remotely. No exploit exists.
A vulnerability identified as problematic has been detected in corvusinfo CorvusPay WooCommerce Payment Gateway Plugin up to 2.7.4 on WordPress. This impacts an unknown function of the file /wp-json/corvuspay/success of the component approval_code Handler. The manipulation of the argument approval_code leads to cross site scripting.
This vulnerability is documented as CVE-2026-6939. The attack can be initiated remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in freshlabs fresh Podcaster Plugin up to 1.0.7 on WordPress. This affects the function freshpodcaster of the component Shortcode Handler. Executing a manipulation of the argument attributes can lead to cross site scripting.
This vulnerability is registered as CVE-2026-1382. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in blendmedia WP CTA Plugin up to 2.2.2 on WordPress. It has been rated as critical. The impacted element is the function ajaxCheck. Performing a manipulation of the argument fildname results in sql injection.
This vulnerability is cataloged as CVE-2026-4661. It is possible to initiate the attack remotely. There is no exploit available.