THREAT OPS › Threat News
Threat Intelligence News
11910 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-15234 — The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes innvd · 2026-08-01
- [NVD] CVE-2026-14840 — The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votesnvd · 2026-08-01
- [NVD] CVE-2026-14839 — The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending,nvd · 2026-08-01
- [NVD] CVE-2026-14836 — The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthentnvd · 2026-08-01
- [NVD] CVE-2026-14823 — The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of evnvd · 2026-08-01
- [NVD] CVE-2026-14596 — The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to anvd · 2026-08-01
- [NVD] CVE-2026-14561 — The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user wnvd · 2026-08-01
- [NVD] CVE-2026-14315 — The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs unvd · 2026-08-01
- [NVD] CVE-2026-14309 — The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, andnvd · 2026-08-01
- [NVD] CVE-2026-14292 — The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of anvd · 2026-08-01
- [NVD] CVE-2026-14214 — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the invd · 2026-08-01
- [NVD] CVE-2026-14197 — The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.nvd · 2026-08-01
- [NVD] CVE-2026-14195 — The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft postsnvd · 2026-08-01
- [NVD] CVE-2026-13729 — The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator invd · 2026-08-01
- [NVD] CVE-2026-13725 — The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site nvd · 2026-08-01
- [NVD] CVE-2026-13604 — The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access nvd · 2026-08-01
- [NVD] CVE-2026-13329 — The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured onvd · 2026-08-01
- [NVD] CVE-2026-13158 — The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisinvd · 2026-08-01
- [NVD] CVE-2026-13157 — The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite)nvd · 2026-08-01
- [NVD] CVE-2026-12966 — The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers tnvd · 2026-08-01
- [NVD] CVE-2026-12696 — The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser nvd · 2026-08-01
- [NVD] CVE-2026-11882 — The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access tokenvd · 2026-08-01
- [NVD] CVE-2026-10827 — The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the nvd · 2026-08-01
- [NVD] CVE-2025-15669 — The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to stornvd · 2026-08-01
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interactionthehackernews · 2026-08-01
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malwarethehackernews · 2026-08-01
- [NVD] CVE-2026-3141 (CRITICAL 9.1) — The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registerenvd · 2026-08-01
- [coinbasecartel] CEN and Cenelec posted to leak siteransomware_live · 2026-08-01
- [coinbasecartel] MIM Fertility posted to leak siteransomware_live · 2026-08-01
- [coinbasecartel] M. B. Kahn Construction Co. posted to leak siteransomware_live · 2026-08-01
- [coinbasecartel] Xs Cad posted to leak siteransomware_live · 2026-08-01
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-01
- Re: 33 Vulnerabilities in cJSONoss_sec · 2026-08-01
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-01
- Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerabilityoss_sec · 2026-08-01
- Rejected CVE reports against SQLite, libraw, ESP32-audioI2Soss_sec · 2026-08-01
- RE: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerabilityoss_sec · 2026-08-01
- [Breach] Alcon — 218,395 accounts exposedhibp_breaches · 2026-08-01
- [Breach] Questel — 1,226,209 accounts exposedhibp_breaches · 2026-08-01
- Re: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerabilityoss_sec · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- Vulnerability & Patch Roundup — July 2026sucuri_blog · 2026-07-31
- [GHSA] GHSA-vvp7-h4fj-m28w (high) — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesgithub_advisories · 2026-07-31
- [GHSA] GHSA-g65v-27r3-5p6m (medium) — guard-livereload has a directory traversal vulnerabilitygithub_advisories · 2026-07-31
- [GHSA] GHSA-c5px-58j2-7fqp (medium) — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline modegithub_advisories · 2026-07-31
- [GHSA] GHSA-jhh7-832h-f8hv (medium) — WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)github_advisories · 2026-07-31
- [GHSA] GHSA-pjp7-q6wp-97qx (medium) — core-geonetwork has an Open Redirect Bypassgithub_advisories · 2026-07-31
- [GHSA] GHSA-wg4g-wm44-ch5j (medium) — Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messagegithub_advisories · 2026-07-31
- [GHSA] GHSA-34rh-wp3j-6cxc (medium) — Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attributegithub_advisories · 2026-07-31
- [GHSA] GHSA-wqqc-jjcq-vfxm (low) — sigstore-go fails to check signature timestamps against a signing key's validity periodgithub_advisories · 2026-07-31
- [GHSA] GHSA-wf43-fpp3-cf65 (high) — @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Taggithub_advisories · 2026-07-31
- [GHSA] GHSA-34pj-2622-jvxq (low) — @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host headergithub_advisories · 2026-07-31
- [GHSA] GHSA-6h5j-32cf-4253 (critical) — Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypassgithub_advisories · 2026-07-31
- [GHSA] GHSA-vccv-cmxp-4j9h (medium) — sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributesgithub_advisories · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- Friday Squid Blogging: Squid Helps Discover New Marine Speciesschneier · 2026-07-31
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftmsstic · 2026-07-31
- Wordfence Bug Bounty Program Monthly Report – April 2026wordfence · 2026-07-31
- [GHSA] GHSA-qj55-47fp-p62j (medium) — free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failuregithub_advisories · 2026-07-31
- [GHSA] GHSA-3whf-vgf2-9w6g (medium) — zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limitgithub_advisories · 2026-07-31
- [GHSA] GHSA-p849-8hwh-84j9 (critical) — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCEgithub_advisories · 2026-07-31
- [GHSA] GHSA-98pp-vccm-qm25 (high) — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlersgithub_advisories · 2026-07-31
- [GHSA] GHSA-mx5j-mp4f-g8jg (high) — Savon::Model evaluates WSDL operation names as Ruby sourcegithub_advisories · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [GHSA] GHSA-45qg-252v-3f7p (medium) — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitizationgithub_advisories · 2026-07-31
- [GHSA] GHSA-rxcw-mc6f-6hr3 (high) — Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carriergithub_advisories · 2026-07-31
- [GHSA] GHSA-5957-5c94-3v7w (medium) — Jodit has prototype pollution via Jodit.configure() / ConfigMergegithub_advisories · 2026-07-31
- [GHSA] GHSA-j839-gqq4-gf9j (medium) — Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSSgithub_advisories · 2026-07-31
- [GHSA] GHSA-cj54-hpcc-gj6h (high) — Thumbor has path traversal via post-validation URL decoding bypass in file_loadergithub_advisories · 2026-07-31
- [qilin] Community Management Associates posted to leak siteransomware_live · 2026-07-31
- [GHSA] GHSA-phj3-59pf-cp83 (high) — Thumbor proportion filter allows unbounded post-transform resize leading to remote DoSgithub_advisories · 2026-07-31
- [GHSA] GHSA-5vjc-7cxw-4w6j (high) — Thumbor has Regex Denial of Service (ReDoS) in `convolution` filtergithub_advisories · 2026-07-31
- [GHSA] GHSA-cqjp-jf4r-h5q9 (high) — Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoSgithub_advisories · 2026-07-31
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkthehackernews · 2026-07-31
- [GHSA] GHSA-mw3h-qjxj-6xg9 (high) — Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signaturegithub_advisories · 2026-07-31
- Kate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Conventioncitizenlab · 2026-07-31
- [GHSA] GHSA-6x26-6r6f-m537 (high) — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dotgithub_advisories · 2026-07-31
- [thegentlemen] Las Cenizas posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Kenaitze Indian Tribe posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Additive Manufacturing posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Salem Saleh Babgi posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Salama Medicals Distributors Private posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Krafman posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Kosh Innovations posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Saturn Industries posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Acosta Sons posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] CFS posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] OHK Energy posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Hutch Paving posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] CRB group posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Partition Specialties posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Preferred posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Premier Fiduciary posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Bater posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Precision Concrete Pumping posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Clear Vision Signs posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Orsima posted to leak siteransomware_live · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [thegentlemen] The Municipal Chamber of Serra posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Efrata College of Education posted to leak siteransomware_live · 2026-07-31