Security news
Freshly disclosed vulnerabilities and patches we're tracking. ZeroBreach's recurring scans check your stack against disclosures like these.
Beaver Builder ≤2.11.0.5 allows unauthenticated shortcode execution (CVE-2026-92084)
CVSS 9.1: the Beaver Builder page builder's Sidebar module lets unauthenticated attackers execute shortcodes, with a public proof-of-concept circulating. Update to 2.11.0.6 or later.
Critical PHP object injection in Advanced Post Manager (CVE-2026-97283)
CVSS 9.8: a PHP object injection flaw in Advanced Post Manager ≤4.5.5. Update to 4.5.6 or later without delay.
High-severity flaw in WP Spell Check — no patch yet, disable the plugin
A high-severity vulnerability in the WP Spell Check plugin has no official vendor patch at time of writing. Recommendation: disable the plugin until a fix ships.
WordPress core remote file inclusion under active exploit (CVE-2026-87902)
A remote file inclusion flaw in WordPress core can lead to unauthenticated remote code execution. It is actively exploited in the wild and CISA-listed. Patch immediately and check for compromise indicators.