๐จ ACTIVE EXPLOITATION
- WordPress Core Pre-Auth RCE Vulnerability CVE-2026-63030 Affects Versions 6.9.0 to 7.0.1 โ fullhunt.io
A pre-authentication remote code execution vulnerability was found in WordPress Core versions 6.9.0 through 7.0.1.- Applies to WordPress Core versions 6.9.0 through 7.0.1, patched in 6.9.5 and 7.0.2
- Vulnerability involves a pre-auth SQL injection via the REST API batch endpoint allowing remote code execution
- Attack exploits array index desynchronization in batch request processing to bypass parameter validation
- Re-entrancy bug allows nested REST API calls without proper dispatch guards, exploitable without persistent object cache
- Fixes include synchronizing arrays in request validation and adding dispatch guards to prevent nested calls
๐ Coverage: fullhunt.io ยท ๐ via r/netsec
๐ CVEs & KEV
-
CVE-2026-12228 โ CVSS 8.7 โ Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms
A stored cross-site scripting vulnerability affecting direct messages in the parisneo/lollms project. -
CVE-2026-16154 โ CVSS 7.3 โ SourceCodester Class and Exam Timetabling System edit_room1.php SQL injection
SQL injection vulnerability in edit_room1.php of SourceCodester Class and Exam Timetabling System. -
CVE-2026-16152 โ CVSS 7.3 โ SourceCodester Class and Exam Timetabling System edit_rooma.php SQL injection
SQL injection vulnerability in edit_rooma.php of SourceCodester Class and Exam Timetabling System. -
CVE-2026-16151 โ CVSS 6.3 โ CartoDB carto-api-client filters.ts addFilter prototype pollution
Prototype pollution vulnerability in addFilter function of CartoDB carto-api-client filters.ts. -
CVE-2026-57857 โ CVSS 4.3 โ Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_me parameter
Reflected cross-site scripting vulnerability in Flow Payment Plugin for WordPress via error_me parameter. -
CVE-2026-16155 โ CVSS 3.5 โ SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting
Cross-site scripting vulnerability in schoolyr.php of SourceCodester Class and Exam Timetabling System. -
CVE-2026-16194 โ CVSS โ zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery
Server-side request forgery vulnerability in WebFetch.execute of zhayujie CowAgent web_fetch.py. -
CVE-2026-16156 โ CVSS โ SourceCodester Class and Exam Timetabling System forexam.php cross site scripting
Cross-site scripting vulnerability in forexam.php of SourceCodester Class and Exam Timetabling System.