Výsledky hledání

výrobce: WordPress× typ: zneužíváno× v celém archivu zrušit filtry

6 karet z 7 položek CZ · EN/orig

1

1

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…

EPSS 0.03 CVSS 10.0 CVE-2026-18431 CVE-2026-19598 CVE-2026-19632 CVE-2026-76581 CVE-2026-82222 WordPress WPMU DEV Avada TranslatePress FI

tg: zneužíváno tg: zranitelnost tp: dodavatelský řetězec

NCSC-FI ·

1

1

1

Hackers target WordPress sites in miniOrange auth bypass attacks

Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

EPSS 0.01 CVSS 9.8 CVE-2026-15981 CVE-2026-61979 WordPress miniOrange FI US 2 zdrojů

tg: varování tg: zneužíváno tg: zranitelnost tp: identita

NCSC-FI · BleepingComputer

1

Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

KEV ✓ EPSS 0.97 CVSS 9.0 CVE-2026-60137 CVE-2026-63030 WordPress CZ US AT FR 5 zdrojů

tg: zneužíváno tg: rozbor tg: návod tg: přehled tp: malware tp: ransomware

NÚKIB · Cisco Talos · Elastic Security · CERT.at · CERT-FR – alerty