Skip to content
Threat Feed

Tag

Web

43 briefs RSS
critical advisory

CVE-2025-10656: WordPress Spreadsheet Price Changer Plugin Missing Authorization Vulnerability

CVE-2025-10656 describes a Missing Authorization vulnerability in the Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light plugin for WordPress, affecting all versions up to and including 2.4.37, which allows unauthenticated attackers to create new administrator accounts, leading to privilege escalation and potential full control over affected WordPress sites.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light wordpress plugin web cve missing-authorization privilege-escalation
3t 1c
high advisory

Easy Digital Downloads Plugin Arbitrary File Upload Leads to RCE (CVE-2026-12476)

The Easy Digital Downloads plugin for WordPress versions up to and including 3.6.9 is vulnerable to Arbitrary File Upload (CVE-2026-12476) due to insufficient file type validation, allowing authenticated attackers with Shop Manager-level access or higher to upload arbitrary files which can lead to remote code execution.

Easy Digital Downloads plugin web arbitrary-file-upload rce wordpress plugin
1r 3t 1c
high advisory

CVE-2026-15025: Missing Authorization in Uncanny Automator WordPress Plugin

A Missing Authorization vulnerability, CVE-2026-15025, in the Uncanny Automator WordPress plugin versions up to and including 7.3.2, allows authenticated attackers with Subscriber-level access or higher to enumerate sensitive data from integrated Google Contacts and Mautic services, potentially consuming third-party API quotas.

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress wordpress uncanny-automator missing-authorization data-enumeration web
1r 1t 1c
high advisory

CVE-2026-13440: Stored Cross-Site Scripting in StoreGrowth WooCommerce Plugin

A high-severity Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-13440, exists in the StoreGrowth: Smart Sales Booster for WooCommerce WordPress plugin (versions up to and including 2.1.0) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'message_popup' parameter that execute when a user accesses an affected page, facilitated by an exposed nonce.

StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin xss wordpress web impact execution
3t 1c
high advisory

Generic SQL Injection Vulnerability in WordPress Web Directory Free Plugin (CVE-2026-14785)

The Web Directory Free plugin for WordPress, in all versions up to and including 1.7.13, is vulnerable to generic SQL Injection through the 'levels' parameter. This flaw, caused by insufficient input escaping and lack of query preparation, enables unauthenticated attackers to append arbitrary SQL queries to existing ones, allowing them to extract sensitive information directly from the database.

Web Directory Free sql-injection wordpress plugin web cve
1r 2t 1c
high advisory

Privilege Escalation in Eazy Plugin Manager for WordPress (CVE-2026-14328)

The Eazy Plugin Manager - Powerful Plugin Management Solution for WordPress plugin for WordPress (versions up to and including 4.4.1) is vulnerable to privilege escalation (CVE-2026-14328), allowing authenticated attackers with Subscriber-level access to read sensitive WordPress options, compute an authentication key, and obtain Administrator authentication cookies, leading to full site takeover if the plugin's remote connection feature is configured.

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress <= 4.4.1 wordpress web privilege-escalation cve-2026-14328
2r 1t 1c
high advisory

CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection

Unauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.

Bookly plugin for WordPress <= 27.5 web sql-injection wordpress plugin vulnerability cve exfiltration
1r 2t 1c
low advisory

Denial of Service Vulnerability in React Server Components

A denial of service vulnerability (CVE-2026-44907) affects multiple versions of the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages, allowing threat actors to trigger out-of-memory exceptions or excessive CPU usage by sending specially crafted HTTP requests to server function endpoints.

react-server-dom-webpack +2 react denial-of-service web vulnerability
1t 1c
high advisory

CVE-2026-15212: WordPress WPO365 Login Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability in the WPO365 | Login plugin for WordPress, affecting versions up to and including 43.2, allows unauthenticated attackers to overwrite arbitrary plugin options. This is due to a misconfiguration where the nonce check is effectively disabled. By tricking a site administrator into clicking a malicious link, an attacker can manipulate settings such as enabling the SCIM REST endpoint, planting a SCIM secret token, and setting the default user role for new registrations to 'administrator', potentially leading to full site compromise and unauthorized administrative access.

WPO365 | Login plugin wordpress plugin csrf vulnerability web
1r 4t 1c
high advisory

JupyterLab Image Viewer XSS Vulnerability Leading to RCE

A cross-site scripting (XSS) vulnerability exists in JupyterLab's image viewer, allowing an attacker to achieve remote code execution (RCE) on the JupyterLab server if a specially crafted image file is opened in the image viewer and then opened in a new browser tab; affected versions include JupyterLab prior to 4.5.10 and versions from 4.6.0 up to, but not including, 4.6.2, with patches available in versions 4.5.10 and 4.6.2.

JupyterLab +1 xss rce vulnerability web
2t
high advisory

@better-auth/sso Authorization Bypass Allows Unauthorized SSO Provider Registration

A high-severity authorization bypass vulnerability (CVE-2026-53515) in `@better-auth/sso` versions `>= 1.2.10, < 1.6.11` allows regular organization members to register new SSO providers for an organization, potentially leading to unauthorized user creation and, under specific configurations, unauthorized administrative access within the target organization.

@better-auth/sso web vulnerability authorization-bypass sso
2t 1c
high advisory

Unauthenticated Server-Side Request Forgery in meta-ads-mcp via image_url

An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in `meta-ads-mcp` v1.0.113, specifically within the `upload_ad_image` function, by providing a malicious `image_url` parameter that causes the server to make arbitrary outbound HTTP requests to internal services, RFC 1918 addresses, or cloud metadata endpoints, leading to information disclosure and potential internal network compromise.

meta-ads-mcp 1.0.113 ssrf vulnerability web python unauthenticated
3t 2i
critical advisory

Privilege Escalation Vulnerability in Aimogen Pro WordPress Plugin

A critical privilege escalation vulnerability, CVE-2026-15982, exists in the Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit WordPress plugin, affecting versions up to and including 2.8.4, allowing unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists, execute arbitrary PHP functions, and create administrator accounts, leading to full compromise of the WordPress site.

Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin web wordpress plugin privilege-escalation cve
2t 1c
high advisory

Sensitive Information Exposure in LearnPress WordPress Plugin (CVE-2026-13765)

An unauthenticated sensitive information exposure vulnerability (CVE-2026-13765) in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses, versions up to 4.4.1, allows attackers to extract quiz answers, options, explanations, and question content, including for paid courses.

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.4.1 wordpress plugin vulnerability information-exposure web
1r 2t 1c
high advisory

Grav API Plugin Vulnerability Exposes JWT Access Tokens via URL Parameter

The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.0-rc.16 is vulnerable to sensitive information exposure, accepting JWT access tokens via the '?token=' URL query parameter, causing these tokens to be logged in web server access logs, browser history, and potentially leaked through Referer headers, proxy, or CDN logs, which allows an attacker to gain unauthorized API access, read configuration and user data, create new admin accounts, modify system settings, and delete pages.

Grav API plugin +1 vulnerability web api jwt information-exposure grav
1r 6t 1c
critical advisory

CVE-2026-63089: WireGuard Easy Weak One-Time Link Token Generation Vulnerability

Unauthenticated network attackers can exploit a cryptographically weak one-time link token generation vulnerability, CVE-2026-63089, in WireGuard Easy through version 15.3.0 by brute-forcing a limited keyspace against the unauthenticated `/cnf/:oneTimeLink` route, allowing them to recover WireGuard peer credentials (PrivateKey and PresharedKey) and impersonate legitimate peers to gain unauthorized VPN access.

WireGuard Easy vulnerability cve weak-cryptography credential-access initial-access web
1r 2t 1c
high advisory

Unauthenticated Access to @andrea9293/mcp-documentation-server Web UI/API

The `@andrea9293/mcp-documentation-server` version 1.13.0 defaults to binding its Web UI/API to all network interfaces (0.0.0.0:3080) and lacks authentication for its document-management endpoints, enabling any network-reachable attacker to perform unauthorized operations such as reading, searching, adding, and deleting documents, potentially corrupting the user's knowledge base.

@andrea9293/mcp-documentation-server vulnerability web api node.js default-misconfiguration unauthenticated-access
1r 4t
medium advisory

dd-trace-rb: Improper Parsing of W3C Baggage Headers Leads to DoS

A vulnerability (CVE-2026-50276) in Datadog tracing libraries, specifically `dd-trace-rb` versions prior to 2.32.0, allows a remote and unauthenticated attacker to perform a Denial of Service (DoS) by sending HTTP requests with malformed W3C baggage headers, leading to unbounded CPU and memory consumption.

dd-trace-rb < 2.32.0 denial-of-service vulnerability ruby web
1t
medium advisory

Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS

Attackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.

Grafana vulnerability web DoS XSS
2t
high advisory

Unrestricted File Upload Vulnerability in hcr707305003 shiroiAdmin

A remote unrestricted file upload vulnerability (CVE-2026-15488) exists in hcr707305003 shiroiAdmin versions 1.1 and 1.3, allowing attackers to upload arbitrary files by manipulating the 'File' argument in FileController::upload, potentially leading to remote code execution.

shiroiAdmin < 1.4 vulnerability web file-upload remote-code-execution
1r 3t 1c
high advisory

CVE-2026-13378 - Form Vibes WordPress Plugin Vulnerable to Stored Cross-Site Scripting

The Form Vibes - Database Manager for Forms plugin for WordPress, including all versions up to and including 1.5.2, is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when a user accesses an injected page.

Form Vibes – Database Manager for Forms wordpress plugin vulnerability xss web
1r 2t 1c 5i
critical advisory

CVE-2026-14262: WordPress Simple JWT Login Plugin Authentication Bypass to Privilege Escalation

An authentication bypass vulnerability (CVE-2026-14262) exists in the WordPress Simple JWT Login plugin, affecting all versions up to and including 3.6.6, which allows authenticated attackers with subscriber-level access or higher to escalate privileges to Administrator by injecting crafted identity claims into the `payload` parameter of a JWT token.

Simple JWT Login <= 3.6.6 wordpress plugin authentication-bypass privilege-escalation web
1r 1t 1c
high advisory

Local File Inclusion Vulnerability in LA-Studio Element Kit for Elementor Plugin for WordPress

A Local File Inclusion vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress, affecting all versions up to and including 1.6.1, which allows authenticated attackers with contributor-level access or higher to include and execute arbitrary .php files on the server due to improper path traversal handling and an easily bypassed extension check, leading to PHP code execution, access control bypass, and sensitive data exposure.

LA-Studio Element Kit for Elementor plugin for WordPress wordpress plugin vulnerability lfi web
4t 1c
critical advisory

miniOrange WordPress Plugin Authentication Bypass via OTP Weakness

An authentication bypass vulnerability (CVE-2026-12761) in the miniOrange Social Login and Register WordPress plugin, affecting versions up to 7.7.0, allows unauthenticated attackers to trigger an OTP email to an arbitrary admin's address, offline crack the weak OTP from a leaked hash, and gain full administrator access by logging in as the target user.

miniOrange Social Login and Register web authentication-bypass wordpress cve account-takeover plugin
4t 1c
critical advisory

Authorizer Unvalidated Redirect Vulnerability Allows OAuth2 Token Theft

An unvalidated redirect vulnerability, CVE-2026-54072, in the Authorizer `/authorize` endpoint allows an unauthenticated attacker to steal OAuth2 access, ID, and refresh tokens by crafting a malicious URL with an attacker-controlled `redirect_uri` to which the application redirects a logged-in user, exposing their tokens.

authorizer oauth vulnerability redirect token-theft web ghsa
1r 2t 1i
high advisory

CVE-2026-15288: SureForms WordPress Plugin Payment Manipulation Vulnerability

The SureForms - Drag and Drop Form Builder for WordPress plugin (versions up to and including 2.2.1) is vulnerable to improper input validation (CVE-2026-15288), allowing unauthenticated attackers to modify payment amounts in user-controlled POST data when submitting Stripe payment forms, enabling them to purchase products or services at arbitrarily reduced prices.

SureForms - Drag and Drop Form Builder for WordPress plugin <= 2.2.1 wordpress plugin vulnerability web payment-fraud
1r 1t 1c
high advisory

CVE-2026-12598: LoginPress Pro WordPress Plugin Authentication Bypass

An authentication bypass vulnerability (CVE-2026-12598) exists in the LoginPress Pro plugin for WordPress, affecting versions up to and including 6.2.3 within the Spotify Social Login addon, enabling unauthenticated attackers to log in as any existing WordPress user, including administrators, by registering a Spotify account with the target's email.

LoginPress Pro plugin <= 6.2.3 +1 wordpress plugin authentication-bypass web
2t 1c
high advisory

UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)

The UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.

UsersWP plugin <= 1.2.65 +1 wordpress plugin vulnerability web file-deletion remote-code-execution
1r 3t 1c
high advisory

CVE-2026-4275 - The Divi Torque Lite - Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to CSRF

The Divi Torque Lite plugin for WordPress, in versions up to 4.2.3, is vulnerable to Cross-Site Request Forgery (CVE-2026-4275), allowing an unauthenticated attacker to exploit inadequate nonce verification on the /install_plugin and /activate_plugin REST API endpoints to install arbitrary WordPress plugins, potentially leading to remote code execution or further system compromise.

Divi Torque Lite plugin for WordPress web vulnerability wordpress csrf cve
1r 1t 1c
high advisory

CVE-2026-14372 - The Bit Form WordPress Plugin Arbitrary File Deletion

The Bit Form WordPress plugin (versions up to 3.1.1) is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files like wp-config.php, potentially leading to remote code execution.

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress wordpress plugin vulnerability web rce file-deletion
3t 1c
critical advisory

CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE

The Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.

Blocksy Companion plugin +3 web vulnerability arbitrary-file-upload wordpress
2t 1c
critical advisory

CVE-2026-14245 - miniOrange OTP WordPress Plugin Authentication Bypass

A critical authentication bypass vulnerability, CVE-2026-14245, exists in the miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress, affecting all versions up to 5.5.1, allowing unauthenticated attackers to obtain a password-reset URL for an arbitrary Administrator account and achieve full account takeover due to a lack of server-side OTP verification and reliance on a publicly exposed `form_nonce`.

miniOrange OTP Login, Verification and SMS Notifications plugin < 5.5.1 wordpress plugin authentication-bypass web cve
3t 1c
critical advisory

Critical RCE Vulnerability in Blocksy Companion Pro WordPress Plugin (CVE-2026-58480)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-58480) in Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47 allows attackers to bypass extension validation via double-extension files, leading to remote code execution by forcing the web server to execute uploaded PHP files.

PoC Blocksy Companion Pro plugin < 2.1.47 +2 wordpress plugin rce file-upload web
1r 3t 2c 1i updated
high advisory

CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference

Authenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace < 2.11.10 wordpress web vulnerability idor privilege-escalation
2t 1c
critical advisory

Better Auth OAuth Refresh Token Replay via Missing Client Authentication (CVE-2026-53512)

The legacy `oidcProvider` and `mcp` plugins in the `better-auth` library versions prior to 1.6.11 are vulnerable to CVE-2026-53512, an OAuth refresh-token replay attack where the plugins fail to verify the `client_secret` of confidential clients during the `refresh_token` grant, allowing an attacker who obtains a valid `refresh_token` and `client_id` to indefinitely mint new access tokens and impersonate the client for unauthorized resource access.

better-auth oauth authentication-bypass vulnerability web
1t
high advisory

CVE-2026-14809: Unauthenticated SQL Injection in Prog Management System

A SQL Injection vulnerability, identified as CVE-2026-14809, exists in the Prog Management System developed by PROG MIS, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Prog Management System sql-injection vulnerability web cve high-severity
1r 2t 1c
medium advisory

PHP JWT Library PBES2-HS*+A*KW Unbounded p2c Iteration Count Leads to DoS

An unauthenticated attacker can exploit a vulnerability in the PHP JWT Library's PBES2AESKW::unwrapKey() function when processing JWE tokens that use PBES2-HS*+A*KW algorithms by crafting a JWE with an excessively large 'p2c' (PBKDF2 iteration count) parameter in the JOSE header, forcing the server to perform an unbounded and CPU-intensive PBKDF2 computation, resulting in a CPU-amplification denial of service.

jwt-library +3 denial-of-service web php jwt jwe cwe-400
2r 1t
high advisory

PHP JWT Framework Algorithm Confusion Vulnerability (TOCTOU)

A Time-of-Check/Time-of-Use (TOCTOU) vulnerability exists in the `JWSVerifier` and `JWEDecrypter` components of the `web-token/jwt-framework` and `web-token/jwt-library` PHP packages, allowing an attacker to override the integrity-protected `alg` parameter from the unprotected header, leading to authentication bypass and unauthorized access.

jwt-framework <= 4.2.99 +3 vulnerability php jwt web authentication-bypass
2r 2t
high threat

Heimdall Proxy Forwarded Header Injection via Unsanitized Host Header

Attackers can exploit Heimdall proxy versions <= 0.17.16 operating in proxy mode by injecting malicious values into the `Host` HTTP header, leading to the construction of a manipulated `Forwarded` header that can spoof client IP addresses for upstream services, potentially bypassing IP-based access controls.

exploited Heimdall header-injection proxy access-control-bypass ip-spoofing vulnerability web
1r 1t
critical advisory

npm PraisonAI AgentOS Unauthenticated API Exposure

The npm `praisonai` package's TypeScript `AgentOS` HTTP server defaults to `0.0.0.0` and exposes unauthenticated API endpoints (`/api/agents`, `/api/chat`), allowing attackers to disclose agent configurations and invoke agents without authorization, leading to potential data exfiltration, unauthorized actions, and resource consumption.

praisonai api-abuse unauthenticated-access information-disclosure server-side-request-forgery web node.js npm
2r 4t
medium threat

WP Learn Manager Stored XSS Vulnerability (CVE-2021-47975)

WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability (CVE-2021-47975) that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter via a POST request to the jslm_fieldordering page, resulting in arbitrary JavaScript execution when administrators view the field ordering interface.

WP Learn Manager 1.1.2 cve xss web wordpress
1r 1t 1c
low advisory

Web Server Discovery or Fuzzing Activity Detection

This rule detects potential web server discovery or fuzzing activity by identifying a high volume of HTTP GET requests resulting in 404 or 403 status codes from a single source IP address within a short timeframe, indicating attackers discovering hidden resources for targeted attacks.

Nginx +4 web-server fuzzing reconnaissance web
2r 2t
critical advisory

Grav Login Plugin Privilege Escalation Vulnerability

Unauthenticated users can escalate privileges to admin in Grav CMS by manipulating registration data due to missing server-side validation in the Login plugin.

Login Plugin +2 grav privilege-escalation web
2r 1t 1i