ZeroBreach Request early access

Security news

Freshly disclosed vulnerabilities and patches we're tracking. ZeroBreach's recurring scans check your stack against disclosures like these.

critical CVE-2026-92084

Beaver Builder ≤2.11.0.5 allows unauthenticated shortcode execution (CVE-2026-92084)

CVSS 9.1: the Beaver Builder page builder's Sidebar module lets unauthenticated attackers execute shortcodes, with a public proof-of-concept circulating. Update to 2.11.0.6 or later.

critical CVE-2026-97283

Critical PHP object injection in Advanced Post Manager (CVE-2026-97283)

CVSS 9.8: a PHP object injection flaw in Advanced Post Manager ≤4.5.5. Update to 4.5.6 or later without delay.

high CVE-2026-100506

High-severity flaw in WP Spell Check — no patch yet, disable the plugin

A high-severity vulnerability in the WP Spell Check plugin has no official vendor patch at time of writing. Recommendation: disable the plugin until a fix ships.

critical CVE-2026-87902

WordPress core remote file inclusion under active exploit (CVE-2026-87902)

A remote file inclusion flaw in WordPress core can lead to unauthenticated remote code execution. It is actively exploited in the wild and CISA-listed. Patch immediately and check for compromise indicators.