VYPR

NewsCred Publishing

by WordPress

CVEs (1)

  • CVE-2026-4297Jun 24, 2026
    risk 0.00cvss epss

    The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function…