{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anewfoldbluehostwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:newfold:crazy_domains:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:newfold:wp_plugin_web:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:newfold:hostgator:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:newfold:bluehost:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-80099"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Crazy Domains (\u003c= 2.5.2)","WP Plugin Web (\u003c= 2.3.4)","WP Plugin Hostgator (\u003c= 3.1.0)","WP Plugin Bluehost (\u003c= 4.17.1)","wp-module-data (\u003c= 2.9.4)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","cve-2026-80099"],"_cs_type":"advisory","_cs_vendors":["Newfold"],"content_html":"\u003cp\u003eResearchers have identified a critical authentication bypass vulnerability (CVE-2026-80099) affecting the \u003ccode\u003ewp-module-data\u003c/code\u003e library, which is bundled with several Newfold Digital WordPress plugins. The vulnerability is triggered when the \u003ccode\u003eauthenticate()\u003c/code\u003e method - registered via the \u003ccode\u003erest_authentication_errors\u003c/code\u003e filter - encounters a failure in \u003ccode\u003eHiiveConnection::get_auth_token()\u003c/code\u003e. Under these conditions, PHP type coercion causes the secret HMAC salt to collapse into a publicly known static constant.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can control the remaining inputs required for the HMAC calculation, including the HTTP method, request URI, raw body, and the \u003ccode\u003eX-Timestamp\u003c/code\u003e header. This allows the attacker to compute a valid Bearer token offline. Once forged, the token permits the attacker to bypass authentication and invoke \u003ccode\u003ewp_set_current_user()\u003c/code\u003e as an administrator. This vulnerability grants attackers complete control over affected WordPress installations, enabling actions such as creating new administrative users or installing arbitrary malicious plugins, which effectively leads to total site compromise. The issue affects multiple plugins, including Crazy Domains, WP Plugin Web, Hostgator, and Bluehost.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full administrator-level access to the vulnerable WordPress installation. Threat actors can use this access to exfiltrate database contents, deploy web shells for persistence, inject malicious scripts, or host phishing content. This affects all organizations relying on the specified versions of the affected Newfold plugins for their web infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify and audit all WordPress installations for the affected plugins: Crazy Domains (\u0026lt;= 2.5.2), WP Plugin Web (\u0026lt;= 2.3.4), Hostgator (\u0026lt;= 3.1.0), and Bluehost (\u0026lt;= 4.17.1).\u003c/li\u003e\n\u003cli\u003eUpdate all instances of \u003ccode\u003ewp-module-data\u003c/code\u003e to a version beyond 2.9.4 and update associated plugins to the latest available patched versions.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, restrict access to the REST API endpoints associated with the vulnerable plugins using firewall rules or web application firewall (WAF) policies.\u003c/li\u003e\n\u003cli\u003eReview WordPress user lists for any unauthorized administrative accounts created or modified since the release of this advisory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T10:50:05Z","date_published":"2026-09-09T10:50:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-newfold-auth-bypass/","summary":"An authentication bypass vulnerability in the wp-module-data library used by multiple Newfold plugins allows unauthenticated attackers to forge administrative access tokens and take over WordPress sites.","title":"Authentication Bypass in Newfold WordPress Plugins via wp-module-data","url":"https://feed.craftedsignal.io/briefs/2026-09-newfold-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:newfold:bluehost:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}