Orizon[verified]@OrizonCyberPatch
The tweet alerts that BookingPress Pro for WordPress suffers from a critical CVE (arbitrary file upload) and that a patch is now available.
ThreatAft@ThreatAftDisclosure
A tweet announces that three WordPress plugins—Avada Builder, Divi Form Builder, and BookingPress Pro—contain critical 9.8‑CVSS unauthenticated vulnerabilities.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑6960, revealing that the BookingPress Pro plugin allows arbitrary file uploads because it lacks file‑type validation; no PoC, exploit code, patch, or evidence of active exploitation is provided.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑6960 affecting BookingPress Pro, highlighting arbitrary file upload flaws due to missing file type validation, with no exploit or patch details provided.