๐ต๏ธ RESEARCH & DEEP DIVES
-
Kirki WordPress Plugin Through 6.1.1 Exposes User Metadata
CVE-2026-18347Kirki versions through 6.1.1 let authenticated users read sensitive WordPress user data.- WordPress sites using the Kirki โ Freeform Page Builder, Website Builder & Customizer plugin through version 6.1.1 are affected.
- Authenticated users with custom-level access or higher can access data belonging to any WordPress user, including administrators.
- The flaw exposes email addresses, assigned roles, registration dates, and arbitrary user metadata.
- Attackers supply a target user ID with a user-type context to the plugin's frontend collection endpoint; CVE-2026-18347, CWE-862, CVSS 4.3. ๐ Source: wordfence.com ยท ๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Kirki WordPress plugin through 6.1.1 exposed authenticated path traversal Kirki versions through 6.1.1 allow authenticated arbitrary file reads.
- Kirki โ Freeform Page Builder, Website Builder & Customizer WordPress plugin users are affected.
- All plugin versions through and including 6.1.1 are vulnerable to directory traversal.
- Authenticated users with Editor-level access or higher can exploit the flaw.
- The attack uses the data parameter to traverse paths and read arbitrary files. ๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Bookly WordPress Plugin through 27.7 Exposed to Unauthenticated Stored XSS
CVE-2026-13424The Bookly WordPress plugin is vulnerable to unauthenticated stored cross-site scripting.- WordPress sites using the Bookly Online Scheduling and Appointment Booking System plugin are affected.
- All Bookly versions up to and including 27.7 are vulnerable; CVE-2026-13424.
- Unauthenticated attackers can inject scripts through the bookly_speed_up_update_addons AJAX action.
- Payloads are stored in the bookly_log.details column and execute when an administrator views Diagnostics โ Logs. ๐ Source: wordfence.com ยท ๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
WP Travel Engine up to 6.8.4 exposes customer booking data
CVE-2026-16737WP Travel Engine exposes customer booking and billing data to unauthenticated attackers.- WordPress sites using WP Travel Engine Tour Booking Plugin through version 6.8.4 are affected.
- CVE-2026-16737 allows disclosure of customer booking orders and stored billing information.
- Unauthenticated cart actions process caller-supplied booking identifiers without authorization or ownership checks.
- Attackers can overwrite other customers' booking records with their own data. ๐ Source: nvd.nist.gov ยท ๐ Coverage: radar.offseq.com ยท ๐ via CVE ThreatInt
-
Gallery by BestWebSoft through 4.7.9 Exposes Authenticated SQL Injection
CVE-2026-2497Gallery by BestWebSoft is vulnerable to authenticated SQL injection.- WordPress sites using Gallery by BestWebSoft are affected.
- Versions 4.7.9 and earlier are vulnerable; CVE-2026-2497.
- Editor-level and higher users can exploit the gallery_order{post_id} array keys.
- Unsanitized keys are stored in post metadata and later inserted into SQL queries without prepared statements.
- Successful exploitation can extract sensitive database information. ๐ Source: wordfence.com ยท ๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
WP Compress โค7.10.09 Vulnerable to CSRF Options Deletion WP Compress versions through 7.10.09 are vulnerable to CSRF-based arbitrary options deletion.
- WordPress sites using the WP Compress โ Instant Performance & Speed Optimization plugin are affected.
- All plugin versions through and including 7.10.09 are vulnerable.
- A cross-site request can trigger arbitrary options deletion through an authenticated WordPress session. ๐ Coverage: wordfence.com ยท ๐ via CVE ThreatInt
-
Bold Page Builder through 5.6.8 - Authenticated (Contributor+) Stored Cross-Site S... โ CVE ThreatInt
-
Forminator Forms through 1.55.0.2 - Insecure Direct Object Reference to Unauthenti... โ CVE ThreatInt
-
Infility Global through 2.15.21 - Unauthenticated Stored Cross-Site Scripting via ... โ CVE ThreatInt
-
Extra Product Options Builder for WooCommerce before 1.2.176 - Unauthenticated Cus... โ CVE ThreatInt
-
Visualizer before 4.0.7 - Contributor+ Cross-User Chart Configuration DisclosureTh... โ CVE ThreatInt
-
WPvivid Backup & Migration before 0.9.131 - Unauthenticated Path Traversal via sen... โ CVE ThreatInt
-
CatFolders Document Gallery before 2.0.7 - Unauthenticated Attachment Disclosure v... โ CVE ThreatInt
-
Simple JWT Login before 3.6.8 - Unauthenticated Account Takeover via Missing Googl... โ CVE ThreatInt
-
Masteriyo LMS before 2.3.3 - Instructor+ Stored XSS via Quiz DescriptionThe Master... โ CVE ThreatInt
-
Premium Packages โ Sell Digital Products Securely before 7.0.7 - Subscriber+ Arbit... โ CVE ThreatInt
-
ECS before 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeat... โ CVE ThreatInt
-
All-in-One WP Migration and Backup before 7.108 - Multisite Subsite Admin+ Network... โ CVE ThreatInt
-
Manual Image Crop before 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite v... โ CVE ThreatInt
-
Free ways to learn Cyber security โ r/cybersecurity
-
What are the most important attack surfaces in AI applications? โ r/cybersecurity
-
Private companies can now Hack-Back โ r/cybersecurity