Threat Modeling and Security by Design

Threat modeling tooling: Use our tool to start threat modeling within minutes.

Solve your threat modeling problems: We can help you to implement threat modeling and security by design.

Learn about threat modeling: We have lots of content to teach you about threat modeling.

Our Threat Modeling Tool Helps you to Perform Structured Threat Modeling at Scale

It’s easy to get started with threat modeling and gain initial security value from it. However, rolling out structured threat modeling at scale is a different matter. Our threat modeling tool helps you to get the most of threat modeling, in order to apply security by design and default.

  • Powerful assessment engine to understand potential threats and security weakness.
  • Flexible Diagram engine to visualize components and communication flows in play.
  • Clear reporting and metrics for compliance demonstration.

Try our threat modeling tool and get started within minutes!

Methods

Learn about the various threat modeling methods such as STRIDE, PASTA, LINDDUN, and Persona non Grata.

Tooling

We have a full list of threat modeling tools that can help to perform threat modeling. Including our own threat modeling tool.

Templates

Templates can help to kickstart the process. We have lots of free templates available.

Examples

We believe that you learn best from practical and real-world examples. We have lots of example cases and threat models available.

MDJM Event Management Arbitrary File Upload (CVE-2026-7537): Unrestricted File Upload Enables Server Compromise

An arbitrary file upload vulnerability in the MDJM Event Management WordPress plugin, tracked as CVE-2026-7537 (CVSS 7.2), allows authenticated attackers with administrator access to upload arbitrary files — including PHP webshells — to the server. All versions up to and including 1.7.8.3 are affected. What Is the Vulnerability? CVE-2026-7537 is an unrestricted file upload vulnerability (CWE-434) in the mdjm_send_comm_email function. The function performs no…

Continue Reading MDJM Event Management Arbitrary File Upload (CVE-2026-7537): Unrestricted File Upload Enables Server Compromise

Booking Package WordPress Plugin Privilege Escalation (CVE-2026-9851): Account Takeover via Missing Capability Check

A privilege escalation vulnerability in the Booking Package WordPress plugin, tracked as CVE-2026-9851 (CVSS 7.2), allows attackers to take over user accounts — including administrator accounts — through a missing capability check on the updateUser AJAX endpoint. All versions up to and including 1.7.16 are affected. What Is the Vulnerability? CVE-2026-9851 is an authorization bypass vulnerability (CWE-639) in the package_app_action AJAX endpoint. The updateUser…

Continue Reading Booking Package WordPress Plugin Privilege Escalation (CVE-2026-9851): Account Takeover via Missing Capability Check

WP User Manager Local File Inclusion (CVE-2026-9290): Unauthenticated PHP File Execution via Profile Template Scope

A local file inclusion vulnerability in the WP User Manager WordPress plugin, tracked as CVE-2026-9290 (CVSS 7.5), allows unauthenticated attackers to include and execute arbitrary PHP files on the server through the profile template scope function. All versions up to and including 2.9.17 are affected. What Is the Vulnerability? CVE-2026-9290 is a path traversal vulnerability (CWE-22) in the profile template scope function of WP…

Continue Reading WP User Manager Local File Inclusion (CVE-2026-9290): Unauthenticated PHP File Execution via Profile Template Scope

Everest Forms Pro Remote Code Execution (CVE-2026-3300): Actively Exploited eval() Injection via Complex Calculation Feature

A critical remote code execution vulnerability in the Everest Forms Pro WordPress plugin, tracked as CVE-2026-3300, allows unauthenticated attackers to execute arbitrary PHP code on the server through the plugin’s Complex Calculation feature. Active exploitation is confirmed — attackers are taking over WordPress sites by injecting PHP code through form submissions. All versions up to and including 1.9.12 are affected. What Is the Vulnerability?…

Continue Reading Everest Forms Pro Remote Code Execution (CVE-2026-3300): Actively Exploited eval() Injection via Complex Calculation Feature

Hippoo Mobile App for WooCommerce Authentication Bypass (CVE-2026-10580): Unauthenticated Administrator Account Takeover

An authentication bypass vulnerability in the Hippoo Mobile App for WooCommerce WordPress plugin, tracked as CVE-2026-10580 (CVSS 9.8), allows unauthenticated attackers to gain administrator-level access to WordPress sites. The vulnerability exists because the plugin’s permission checking function returns the same null sentinel for both administrators and unauthenticated visitors, creating a logic conflation that enables full account takeover with no credentials. What Is the Vulnerability?…

Continue Reading Hippoo Mobile App for WooCommerce Authentication Bypass (CVE-2026-10580): Unauthenticated Administrator Account Takeover