Vendor
Arbitrary Shortcode Execution in Forminator WordPress Plugin
1 TTP 1 CVEThe Forminator plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92229) allowing unauthenticated attackers to execute arbitrary shortcodes by leveraging improper input validation.
CVE-2026-83627: Unauthenticated RCE in Hummingbird WordPress Plugin
1 rule 1 TTP 1 CVEAn unauthenticated remote code execution vulnerability in the Hummingbird WordPress plugin allows attackers to inject and execute arbitrary PHP code via unsanitized cookie headers in the debug log.
Authentication Bypass in WPMU DEV Dashboard Plugin
1 TTP 1 CVEAn authentication bypass vulnerability in the WPMU DEV Dashboard WordPress plugin allows unauthenticated attackers to forge an administrator session by exploiting flawed HMAC validation in the Hub SSO flow.
Stored XSS Vulnerability in Forminator Forms WordPress Plugin
1 TTP 1 CVEThe Forminator Forms WordPress plugin (up to v1.57.0.1) is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the Rich-Text Textarea field, allowing malicious script execution in the context of victim browsers.
Arbitrary File Upload in Forminator Forms Plugin for WordPress
2 TTPs 1 CVEThe Forminator Forms WordPress plugin version 1.56.1 and earlier contains an arbitrary file upload vulnerability allowing unauthenticated remote code execution via insufficient MIME type validation.
Stored Cross-Site Scripting in Forminator Forms Plugin for WordPress
2 TTPs 1 CVEAn unauthenticated stored XSS vulnerability in Forminator Forms plugin versions 1.56.1 and earlier allows attackers to inject and execute arbitrary web scripts via forged upload records.
Critical Privilege Escalation in WordPress Branda Plugin (CVE-2026-11551)
2 rules 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-11551, a critical privilege escalation vulnerability in the WordPress Branda plugin up to version 3.4.29, by leveraging improper identity validation to change arbitrary user passwords, including administrators, leading to full account takeover and potential compromise of the WordPress site.