Skip to content
Threat Feed

July 2026 (30)

high advisory

CVE-2026-16597 - GTM4WP WordPress Plugin Vulnerable to Stored XSS via WooCommerce Billing Fields

The GTM4WP (Google Tag Manager) plugin for WordPress, in versions up to and including 1.22.3, is vulnerable to stored cross-site scripting (XSS) via CVE-2026-16597, allowing unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields during a guest checkout, which execute when a user accesses the compromised page.

GTM4WP +1 wordpress plugin xss web-vulnerability e-commerce
1r 1t 1c
critical advisory

Remote Code Execution in Cost Calculator Builder PRO WordPress Plugin

The Cost Calculator Builder PRO plugin for WordPress, versions up to and including 4.0.3, is vulnerable to unauthenticated Remote Code Execution (RCE) via CVE-2026-14900 due to insufficient sanitization of the `orderDetails[*].originalValue` field, allowing arbitrary code injection into a `PHP eval()` call that can be exploited by unauthenticated attackers.

Cost Calculator Builder PRO plugin wordpress plugin rce web-exploitation cve
1r 2t 1c
critical advisory

Meta Box AIO Plugin Vulnerable to Unauthenticated Post Deletion via CVE-2026-14488

Unauthenticated attackers can exploit a Missing Authorization vulnerability (CVE-2026-14488) in the MB Frontend Submission extension of the Meta Box AIO plugin for WordPress, affecting versions up to 3.8.0, to delete arbitrary posts and pages by injecting a crafted post ID via a GET parameter.

Meta Box AIO plugin +1 wordpress missing-authorization web-application plugin-vulnerability cve
1r 1t 1c
critical advisory

CVE-2025-10656: WordPress Spreadsheet Price Changer Plugin Missing Authorization Vulnerability

CVE-2025-10656 describes a Missing Authorization vulnerability in the Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin for WordPress, affecting all versions up to and including 2.4.37, which allows unauthenticated attackers to create new administrator accounts, leading to privilege escalation and potential full control over affected WordPress sites.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light wordpress plugin web cve missing-authorization privilege-escalation
3t 1c
high threat

Red Hat Enterprise Linux librest and pipewire Vulnerabilities Allow Code Execution

An attacker can exploit multiple vulnerabilities found in Red Hat Enterprise Linux, specifically within the librest and pipewire components, to bypass security measures and achieve arbitrary code execution on affected systems, posing a significant risk to the integrity and confidentiality of the system.

exploited Red Hat Enterprise Linux linux vulnerability redhat code-execution defense-evasion
2t
low advisory

PackageKit: Vulnerability Allows Bypassing Security Measures

A remote, authenticated attacker can exploit a vulnerability in PackageKit to bypass security mechanisms.

PackageKit vulnerability defense-evasion linux
1t
high threat

Gitea Remote Code Execution Vulnerability

A vulnerability in Gitea allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full compromise of the affected Gitea instance and potentially the underlying server.

exploited Gitea vulnerability rce
1t
medium advisory

Tanium Endpoint Management Vulnerability Allows Authenticated SQL Injection

A remote, authenticated attacker can exploit a SQL injection vulnerability in Tanium Endpoint Management, enabling the execution of arbitrary SQL commands and potentially leading to data manipulation or unauthorized access.

Tanium Endpoint Management sql-injection vulnerability endpoint-management
2t
medium threat

IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service

Multiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.

exploited WebSphere Application Server Liberty denial-of-service vulnerability ibm websphere
1t
high advisory

WordPress Database for CF7 Plugin Stored Cross-Site Scripting (CVE-2026-13425)

The Database for CF7 plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via Array Form Field Values, allowing unauthenticated attackers to inject arbitrary web scripts by sending specially crafted array-structured input to the Contact Form 7 REST API endpoint /wp-json/contact-form-7/v1/contact-forms/{id}/feedback, which are insufficiently sanitized and executed when a user accesses an affected page.

Database for CF7 plugin < 1.2.7 web-application wordpress xss cve-2026-13425 stored-xss plugin-vulnerability
1r 2t 1c
critical advisory

Apache Axis2: Vulnerability Allows Code Execution

An anonymous, remote attacker can exploit a vulnerability in Apache Axis2 to execute arbitrary program code. This flaw allows for critical remote code execution without authentication, posing a significant risk to systems running the affected software.

Axis2 remote-code-execution vulnerability-exploitation apache
2t
critical advisory

Unauthenticated Credential Disclosure in Vacron VIN-DS783E-E6 via Hidden Functionality (CVE-2026-18191)

CVE-2026-18191 describes a critical Hidden Functionality vulnerability in Vacron VIN-DS783E-E6 devices that allows unauthenticated remote attackers to exploit a specific hidden function to obtain administrator credentials, leading to full device compromise.

VIN-DS783E-E6 vulnerability credential-access unauthenticated network-device CVE-2026-18191
2t 1c
critical advisory

Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin

A critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.

Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin wordpress authentication-bypass web-vulnerability
1r 3t 1c
high advisory

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike's AI security research team has identified 18 new prompt injection techniques, expanding its taxonomy to over 200 methods, which enable adversaries to manipulate AI systems and agents through indirect means like hidden context, delayed triggers, and special token injection, leading to unauthorized actions such as data exfiltration or arbitrary command execution.

Gemini +36 prompt-injection ai llm ai-security cloud novel-technique
1r 4t 38i updated
high advisory

Easy Digital Downloads Plugin Arbitrary File Upload Leads to RCE (CVE-2026-12476)

The Easy Digital Downloads plugin for WordPress versions up to and including 3.6.9 is vulnerable to Arbitrary File Upload (CVE-2026-12476) due to insufficient file type validation, allowing authenticated attackers with Shop Manager-level access or higher to upload arbitrary files which can lead to remote code execution.

Easy Digital Downloads plugin web arbitrary-file-upload rce wordpress plugin
1r 3t 1c
critical advisory

WordPress Wholesale for WooCommerce Plugin Privilege Escalation (CVE-2026-12144)

The Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation due to insufficient validation and capability checks in `save_requests_meta()` function, allowing authenticated attackers with author-level access or higher to escalate their privileges to administrator by supplying 'administrator' as the `user_role_set` value in a crafted request.

Wholesale for WooCommerce plugin wordpress plugin privilege-escalation web-vulnerability
1t 1c
high advisory

Path Traversal Vulnerability in openhole-server (CVE-2026-54650)

An unauthenticated path traversal vulnerability (CVE-2026-54650) in openhole-server and openhole CLI versions 0.1.1 and earlier allows remote attackers to read arbitrary files outside the web root on tunneled local services by exploiting URL-decoded percent-encoded dot-segments and slashes, enabling arbitrary file disclosure and potential bypass of access controls.

openhole-server +1 vulnerability path-traversal webserver
1r 2t
high advisory

Prototype Pollution Vulnerability in Style Dictionary convertTokenData Function

A prototype pollution vulnerability exists in the Style Dictionary library, specifically within the `convertTokenData()` utility function, allowing malicious users to exploit it by crafting a token array containing `__proto__` keys, which, when processed, will globally pollute the `Object.prototype`, impacting NodeJS server applications and web applications.

Style Dictionary prototype-pollution supply-chain npm nodejs
1c
critical advisory

SQL Injection Vulnerability in @hypequery/clickhouse Allows Arbitrary SQL Execution

A SQL injection vulnerability exists in the `escapeValue()` function of the `@hypequery/clickhouse` library, affecting versions prior to 2.0.2, allowing attackers to leverage a trailing backslash in user-controlled query parameters to bypass escaping mechanisms, leading to arbitrary SQL execution against ClickHouse databases.

@hypequery/clickhouse sql-injection vulnerability npm clickhouse supply-chain
2t
high advisory

td Library Denial of Service via Unbounded Memory Allocation

A denial-of-service vulnerability exists in the `go/github.com/gotd/td` library versions prior to 0.145.1. A remote, unauthenticated attacker can exploit this by sending a crafted unencrypted MTProto packet during the handshake. This packet declares a large `dataLen` value, forcing the application to allocate an excessive amount of memory, potentially leading to out-of-memory (OOM) termination and denial of service due to unbounded memory allocation before length validation.

go/github.com/gotd/td denial-of-service vulnerability go-lang
1t
critical advisory

Goshs WebDAV MOVE Method Bypasses No-Delete Flag

A critical vulnerability (CVE-2026-64863) in the goshs WebDAV server, affecting versions up to 2.1.3, allows an attacker to bypass the `--no-delete` security flag using the `MOVE` HTTP method, leading to unauthorized deletion of source files or overwriting of existing destination files, impacting data integrity.

goshs <= 2.1.3 +1 webdav vulnerability file-deletion data-destruction server golang
1r 1t
high advisory

Goshs File-Based ACL Authorization Bypass via Bulk Zip Download

An unauthenticated attacker can exploit CVE-2026-54719 in goshs versions up to 1.1.4 and goshs/v2 up to 2.1.0 to bypass file-based Access Control Lists (ACLs) and read any file under the webroot using the `?bulk` zip-download route, leading to unauthorized information disclosure.

goshs +1 authorization-bypass webserver vulnerability cve information-disclosure
1r 3t
high advisory

`datamodel-code-generator` Vulnerable to Code Injection via `default_factory` Field

The `datamodel-code-generator` library is vulnerable to code injection (CVE-2026-54653) when generating Python models from attacker-controlled schemas (e.g., JSON Schema, OpenAPI, YAML). This occurs because the `default_factory` schema field's value is interpolated directly as a raw Python expression into the generated code, allowing an attacker who controls the input schema to achieve arbitrary Python code execution within the consumer's process at module import time, affecting developers or CI pipelines that process untrusted schemas.

datamodel-code-generator code-injection supply-chain developer-tools python rce cve
1t 1i
high advisory

datamodel-code-generator Arbitrary Local File Read Vulnerability

The `datamodel-code-generator` library (versions <= 0.61.0) is vulnerable to an unauthenticated path traversal and arbitrary local file read (CVE-2026-55389), allowing an attacker to supply a crafted JSON-Schema with `$ref` fields pointing to local files using `file://` URIs or `../` path traversal sequences, bypassing the `--no-allow-remote-refs` security control, which leads to information disclosure of sensitive data and enables filesystem mapping.

datamodel-code-generator <= 0.61.0 vulnerability path-traversal information-disclosure python
2t 1i
high advisory

datamodel-code-generator Vulnerable to Code Injection via Unescaped Carriage Return

The `datamodel-code-generator` Python package is vulnerable to code injection (CVE-2026-54654) when a developer uses the `--extra-template-data` option with a file whose `comment` value contains an unescaped carriage return, leading to arbitrary Python code execution during the import process of the generated code.

datamodel-code-generator code-injection supply-chain rce python vulnerability
1t
medium advisory

datamodel-code-generator Vulnerable to SSRF Protection Bypass via DNS Rebinding

The `datamodel-code-generator` tool is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass, identified as CVE-2026-55391, due to a time-of-check/time-of-use (TOCTOU) race condition through DNS rebinding, allowing attackers to access internal services like cloud instance metadata endpoints when processing attacker-influenced URLs.

datamodel-code-generator ssrf dns-rebinding vulnerability supply-chain python
4t 1i
high advisory

datamodel-code-generator Vulnerable to Arbitrary Local File Read via XSD Path Traversal

datamodel-code-generator versions 0.59.0 through 0.61.0 are vulnerable to an unauthenticated path traversal and information disclosure issue, allowing an attacker to read arbitrary local files on the system where the code generator is executed by crafting a malicious XML Schema (XSD) `schemaLocation` attribute, with the contents of the files then incorporated into the generated output.

datamodel-code-generator path-traversal information-disclosure supply-chain vulnerability
1t
high advisory

Datamodel Code Generator Vulnerable to SSRF via URL Parameter

The `datamodel-code-generator` tool, specifically versions from `0.9.1` up to `0.60.2`, is vulnerable to Server-Side Request Forgery (SSRF) when using the `--url` argument with the `[http]` extra installed, allowing attackers to access internal network resources and exfiltrate sensitive data into generated Python files.

datamodel-code-generator ssrf supply-chain code-generation python vulnerability
1r 3t 3i
critical advisory

IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)

A remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.

WebSphere Application Server 9.0 +8 vulnerability authentication-bypass websphere broken-access-control privilege-escalation deserialization RCE server-side-request-forgery +6
5t 7c 5i
high advisory

IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)

A path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.

WebSphere Application Server - Liberty 17.0.0.3 +45 vulnerability path-segment-injection information-disclosure websphere ibm
1c