THREAT OPS › Threat News
Threat Intelligence News
11867 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-17017 — The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perfornvd · 2026-08-09
- [NVD] CVE-2026-17014 — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.nvd · 2026-08-09
- [NVD] CVE-2026-17011 — The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding,nvd · 2026-08-09
- [NVD] CVE-2026-16992 — The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content nvd · 2026-08-09
- [NVD] CVE-2026-16988 — The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listingnvd · 2026-08-09
- [NVD] CVE-2026-16965 — The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's actinvd · 2026-08-09
- [NVD] CVE-2026-16957 — The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published ponvd · 2026-08-09
- [NVD] CVE-2026-16032 — The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execnvd · 2026-08-09
- [NVD] CVE-2026-15038 — The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an admnvd · 2026-08-09
- [NVD] CVE-2026-19334 (MEDIUM 5.3) — A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed localnvd · 2026-08-09
- [NVD] CVE-2026-19333 (MEDIUM 5.3) — A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in commanvd · 2026-08-09
- [NVD] CVE-2026-19332 (MEDIUM 5.3) — A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required nvd · 2026-08-09
- [NVD] CVE-2026-19331 (MEDIUM 5.3) — A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the nvd · 2026-08-09
- [NVD] CVE-2026-19330 (MEDIUM 5.3) — A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local nvd · 2026-08-09
- [NVD] CVE-2026-19329 (MEDIUM 5.3) — A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command injectionnvd · 2026-08-09
- [NVD] CVE-2026-10595 (HIGH 7.5) — A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem panvd · 2026-08-09
- [NVD] CVE-2026-19328 (MEDIUM 5.3) — A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to nvd · 2026-08-09
- [NVD] CVE-2026-19327 (MEDIUM 5.3) — A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. Thnvd · 2026-08-09
- [NVD] CVE-2026-19326 (MEDIUM 4.4) — A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack munvd · 2026-08-09
- [NVD] CVE-2026-19325 (MEDIUM 5.3) — A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/appenvd · 2026-08-09
- [NVD] CVE-2026-19324 (LOW 3.3) — A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The anvd · 2026-08-09
- [krybit] studiotibaldi.it posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-17510 — Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, nvd · 2026-08-09
- [Panzer] Siam Oil Product posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-71993 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obnvd · 2026-08-09
- [NVD] CVE-2026-71992 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and nvd · 2026-08-09
- [NVD] CVE-2026-71991 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability throughnvd · 2026-08-09
- [NVD] CVE-2026-71990 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through thnvd · 2026-08-09
- [NVD] CVE-2026-71989 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute nvd · 2026-08-09
- [NVD] CVE-2026-71988 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malinvd · 2026-08-09
- [NVD] CVE-2026-71987 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicionvd · 2026-08-09
- [NVD] CVE-2026-71986 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicionvd · 2026-08-09
- [NVD] CVE-2026-71985 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol functionvd · 2026-08-09
- [NVD] CVE-2026-71984 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and nvd · 2026-08-09
- [NVD] CVE-2026-19323 (MEDIUM 5.3) — A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectNamenvd · 2026-08-09
- [NVD] CVE-2026-71983 (CRITICAL 9.8) — MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit thesenvd · 2026-08-08
- [NVD] CVE-2026-71502 — CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conversion whose name or description contains anvd · 2026-08-08
- [Panzer] Daily Trust posted to leak siteransomware_live · 2026-08-08
- PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Responsewordfence · 2026-08-08
- [NVD] CVE-2026-71958 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commnvd · 2026-08-08
- [NVD] CVE-2026-71957 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by cranvd · 2026-08-08
- [NVD] CVE-2026-71956 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command executionnvd · 2026-08-08
- [NVD] CVE-2026-71955 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPnvd · 2026-08-08
- [NVD] CVE-2026-71954 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fnvd · 2026-08-08
- [NVD] CVE-2026-71953 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in commanvd · 2026-08-08
- [NVD] CVE-2026-71952 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in nvd · 2026-08-08
- [NVD] CVE-2026-71951 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in cnvd · 2026-08-08
- [NVD] CVE-2026-71950 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting innvd · 2026-08-08
- [NVD] CVE-2026-71949 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue finvd · 2026-08-08
- [NVD] CVE-2026-71948 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting invd · 2026-08-08
- [NVD] CVE-2026-71947 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fienvd · 2026-08-08
- [NVD] CVE-2026-71946 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting innvd · 2026-08-08
- [NVD] CVE-2026-71945 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resunvd · 2026-08-08
- [NVD] CVE-2026-71944 (CRITICAL 9.8) — D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resunvd · 2026-08-08
- [qilin] Impact Centre Chrétien posted to leak siteransomware_live · 2026-08-08
- [NVD] CVE-2026-67620 (HIGH 7.7) — Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, alnvd · 2026-08-08
- [NVD] CVE-2026-42170 (HIGH 7.8) — A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel datnvd · 2026-08-08
- [incransom] Louisville Bar Association posted to leak siteransomware_live · 2026-08-08
- [NVD] CVE-2026-19288 (MEDIUM 5.3) — A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument librnvd · 2026-08-08
- [NVD] CVE-2026-19287 (MEDIUM 5.3) — A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the probnvd · 2026-08-08
- [NVD] CVE-2026-19285 (MEDIUM 5.3) — A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. Thnvd · 2026-08-08
- [NVD] CVE-2026-19284 (MEDIUM 5.3) — A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally. Thenvd · 2026-08-08
- [NVD] CVE-2026-19282 (MEDIUM 5.3) — A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead nvd · 2026-08-08
- [qilin] Clausing posted to leak siteransomware_live · 2026-08-08
- [qilin] CLLS Co Ltd posted to leak siteransomware_live · 2026-08-08
- [NVD] CVE-2026-19281 (MEDIUM 5.3) — A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injecnvd · 2026-08-08
- [NVD] CVE-2026-19279 (MEDIUM 5.3) — A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The nvd · 2026-08-08
- [NVD] CVE-2026-68082 — In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: nvd · 2026-08-08
- [NVD] CVE-2026-68081 — In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state Put all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid guest while emulating VMLAUNCH or VMRESUME. The invalid gnvd · 2026-08-08
- [Storm] United Group of Companies posted to leak siteransomware_live · 2026-08-08
- [Storm] Sawyer Savings Bank posted to leak siteransomware_live · 2026-08-08
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackersthehackernews · 2026-08-08
- [NVD] CVE-2026-19270 (MEDIUM 5.3) — A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename nvd · 2026-08-08
- [NVD] CVE-2026-19268 (MEDIUM 6.3) — A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since lenvd · 2026-08-08
- [NVD] CVE-2026-19266 (MEDIUM 5.5) — A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading nvd · 2026-08-08
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokensthehackernews · 2026-08-08
- [NVD] CVE-2026-19263 (HIGH 7.3) — A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in commannvd · 2026-08-08
- [NVD] CVE-2026-19259 (MEDIUM 5.3) — A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument GetNnvd · 2026-08-08
- [NVD] CVE-2026-16955 — The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reanvd · 2026-08-08
- [NVD] CVE-2026-16953 — The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file rnvd · 2026-08-08
- [NVD] CVE-2026-16948 — The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentanvd · 2026-08-08
- [NVD] CVE-2026-16608 — The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflanvd · 2026-08-08
- [NVD] CVE-2026-16595 — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.nvd · 2026-08-08
- [NVD] CVE-2026-16594 — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensinvd · 2026-08-08
- [NVD] CVE-2026-16590 — The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.nvd · 2026-08-08
- [NVD] CVE-2026-16589 — The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perfornvd · 2026-08-08
- [NVD] CVE-2026-16578 — The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including thenvd · 2026-08-08
- [NVD] CVE-2026-16574 — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated nvd · 2026-08-08
- [NVD] CVE-2026-16562 — The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitornvd · 2026-08-08
- [NVD] CVE-2026-16559 — The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the snvd · 2026-08-08
- [NVD] CVE-2026-16558 — The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript thnvd · 2026-08-08
- [NVD] CVE-2026-16535 — The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.nvd · 2026-08-08
- [NVD] CVE-2026-16282 — The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the aunvd · 2026-08-08
- [NVD] CVE-2026-16269 — The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when thnvd · 2026-08-08
- [NVD] CVE-2026-14526 (CRITICAL 9.8) — The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated anvd · 2026-08-08
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authenticationthehackernews · 2026-08-08
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persistthehackernews · 2026-08-08
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attemptsthehackernews · 2026-08-08
- [NVD] CVE-2026-18988 (MEDIUM 6.4) — The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() functionnvd · 2026-08-08
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)wordfence · 2026-08-08