← nejvýznamnější zprávy · všechny zprávy

EPSS 0.03 (nejvyšší)

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…

Číst originál na NCSC-FI →

1 zpráva z 1 zdroje · první 30. 8. 04:00 · poslední 30. 8. 04:00 CZ · EN/orig

WordPress WPMU DEV Avada TranslatePress FI

tg: zneužíváno tg: zranitelnost tp: dodavatelský řetězec

CVE v události 5

CVEhodnoceníKEVEPSS
CVE-2026-18431 9.8 3.1 · Wordfence 0.01
CVE-2026-19598 9.8 3.1 · Wordfence 0.03
CVE-2026-19632 9.8 3.1 · Wordfence 0.02
CVE-2026-76581 9.8 3.1 · Wordfence 0.00
CVE-2026-82222 10.0 3.1 · Patchstack 0.02

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Jak se o tom psalo 1

  1. · NCSC-FI FI nadpis události

    Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…