View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical CVE-2026-15369 WooCommerce flaw allows unauthenticated RCE

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • CRPx0 ransomware operation offers ClickFix-based RaaS CRPx0 is operating a ransomware-as-a-service platform that uses ClickFix for delivery.
    • CRPx0 targets organizations with ransomware, data theft, and cryptocurrency theft.
    • The operation encrypts files with the .CRPx0 extension and steals documents, credentials, wallet seed phrases, and clipboard cryptocurrency payments.
    • Its RaaS platform offers affiliates Windows EXE, DLL, and VBS ClickFix stagers.
    • ClickFix lures victims into executing disguised commands through fake verification pages or documents. ๐Ÿ“„ Source: ransom-isac.org ยท ๐Ÿ“Ž Coverage: kelacyber.com ยท ๐Ÿ‘ via @GossiTheDog@cyberplace.social

๐Ÿ”“ CVEs & KEV

  • CVE-2026-15369 โ€” CVSS 9.8 โ€” Custom User Registration Fields for WooCommerce through 2.2.3 - Unauthenticated Pr...

  • CVE-2026-81636 โ€” CVSS 8.7 โ€” Query-complexity limit bypass via first/last pagination arguments in AshGraph...

  • CVE-2026-80223 โ€” CVSS 7.1 โ€” Cross-tenant subscription disclosure in AshGraphql authorizes notifications i...

  • CVE-2026-78693 โ€” CVSS 6.9 โ€” Incomplete redaction re-attaches the original error path in AshGraphql, leaki...

  • CVE-2026-81633 โ€” CVSS 6.9 โ€” Unhandled KeyError in AshGraphql relay node resolution crashes queries via an...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check