Vulnerabilities
Wukong_HRM ParamAspect Auth Bypass CVE-2026-108707 Risks Remote HR Data Manipulation and Deletion
A critical flaw in the ParamAspect component allows unauthenticated users to access all HR API endpoints by omitting a specific header.
Everything Firewall Pulse has reported about authentication bypass: 2 stories, newest first. Part of our Vulnerabilities coverage.
A critical flaw in the ParamAspect component allows unauthenticated users to access all HR API endpoints by omitting a specific header.
A critical authentication bypass in the WPCOM Member plugin for WordPress allows attackers to hijack admin accounts by forging social login sessions without valid credentials.