Industry news sourced where it breaks: provider newsrooms, trade press, community boards, status pages and CVE feeds, pulled nightly and reviewed by a human editor before anything is published. Briefs link straight to the original article; we summarise, we do not republish. Analysis pieces add what only a directory of 28,000+ hosts can: reliability scores, segment and country context.
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occu
A vulnerability tracked as CVE-2026-14812, with a CVSS score of 10, has been disclosed for the Premium SEO WordPress plugin. According to NVD, the plugin contains a malicious, unauthenticated backdoor that creates a hidden administrator account. Some builds also allow remote code execution, server-side request forgery and arbitrary content injection.
The news index is populated nightly from primary sources: provider newsrooms and blogs, independent trade press, community boards, provider status pages and vulnerability feeds. Briefs are drafted with AI assistance and every item is reviewed, edited and approved by a human editor before publication; nothing is published automatically. Briefs link out, so the original publisher gets the click and the credit, and no affiliate revenue is attached to news links. Syndication and partner sources receive no ranking consideration: the news layer and the HostList Reliability Index never touch. See About HostList for the editorial independence statement, or subscribe to the RSS feed.
A vulnerability tracked as CVE-2026-15930 has been identified in the Simple Membership WordPress plugin, versions before 4.7.8. According to NVD, the flaw fails to check whether user creation succeeded during registration, letting unauthenticated attackers overwrite the primary administrator's account data. The issue carries a CVSS score of 9.4. Site owners should update the plugin.
A vulnerability tracked as CVE-2026-12965 has been disclosed in the Super Store Finder WordPress plugin, affecting versions through 7.8. The flaw stems from an unsanitised parameter in an unauthenticated AJAX action, allowing attackers to perform SQL injection and extract database data without needing to log in. The issue carries a CVSS score of 9.1.
A vulnerability tracked as CVE-2026-15014, with a CVSS score of 9.8, has been identified in the SMS Alert plugin for WooCommerce, covering order notifications and abandoned cart recovery for WordPress. All versions up to and including 3.9.7 are affected, allowing authentication bypass and account takeover via the billing_phone parameter, according to NVD.
A vulnerability in the TrueBooker WordPress plugin, tracked as CVE-2026-14545 with a CVSS score of 9.8, has been disclosed via NVD. Versions before 1.2.4 fail to validate account ownership during password resets, letting unauthenticated attackers set arbitrary passwords, including for administrator accounts, potentially leading to full site takeover.
A critical vulnerability, CVE-2026-13714, has been identified in the Realtyna Organic IDX plugin and WPL Real Estate WordPress plugin, versions before 5.3.0. The flaw stems from unvalidated file uploads and an API secured with hardcoded credentials shared across installations. NVD rates it CVSS 9.8. Site owners should update affected plugins promptly.
A critical vulnerability, CVE-2026-12394, has been identified in the MemberGlut WordPress plugin. Versions before 1.1.5 fail to validate the role selected during front-end registration, letting unauthenticated users register accounts with any role, including administrator. This can result in full site compromise. The flaw carries a CVSS score of 9.8. Users should update the plugin promptly.