EPSS 0.03 (nejvyšší)
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…
CVE v události 5
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-18431 | 9.8 3.1 · Wordfence | – | 0.01 |
| CVE-2026-19598 | 9.8 3.1 · Wordfence | – | 0.03 |
| CVE-2026-19632 | 9.8 3.1 · Wordfence | – | 0.02 |
| CVE-2026-76581 | 9.8 3.1 · Wordfence | – | 0.00 |
| CVE-2026-82222 | 10.0 3.1 · Patchstack | – | 0.02 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.
Jak se o tom psalo 1
-
· NCSC-FI FI nadpis události
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…