Vendor
critical
threat
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
exploited
PoC
WordPress Core 6.9.0 +51
wordpress
rce
web-vulnerability
cve
2t
15c
8i
updated
high
advisory
CVE-2026-60105: Monsta FTP SSRF Vulnerability Leading to Credential Disclosure
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-60105, a Server-Side Request Forgery vulnerability in Monsta FTP before 2.14.5, by leveraging an incomplete IP blocklist check with IPv4-mapped IPv6 addresses to force the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, potentially enabling retrieval of cloud instance metadata credentials.
Monsta FTP < 2.14.5
server-side-request-forgery
vulnerability
web-application
credential-access
1r
2t
1c