View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

WordPress WPKoi Templates for Elementor plugin vulnerable

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • WordPress WPKoi Templates for Elementor plugin through 3.7.2 vulnerable to DOM-based XSS (CVE-2026-85302)
    A DOM-based cross-site scripting vulnerability (CVE-2026-85302) was disclosed in the WordPress WPKoi Templates for Elementor plugin affecting all versions through 3.7.2.

    • Affects WordPress sites using the WPKoi Templates for Elementor plugin, an Elementor addon with 400+ page templates and creative widgets, in all versions from n/a through 3.7.2.
    • The flaw is CWE-79 improper input neutralization during web page generation, allowing DOM-based cross-site scripting (XSS).
    • CVSS 3.1 score is 6.5 (medium): network vector, low attack complexity, low privileges required, user interaction required, scope changed.
    • The vulnerability was assigned by Patchstack and reported by Abdullah Kareem 'cyberkareem' via the Patchstack Bug Bounty Program; it was published 2026-09-03.
    • A fix is available in plugin version 3.7.3, per the WordPress.org plugin directory.
      πŸ“„ Source: patchstack.com Β· πŸ“Ž Coverage: radar.offseq.com Β· πŸ‘ via CVE ThreatInt
  • CrowdStrike Launches SafeMind AI Initiative With Models Trained for Cybersecurity
    CrowdStrike has launched SafeMind, an AI initiative built on models purpose-trained for cybersecurity.

    • Applies to CrowdStrike customers and security teams following announcements at the Fal.Con 2026 event.
    • The SafeMind initiative centers on a family of purpose-built AI models and harnesses designed specifically for cybersecurity.
    • At its core is a pair of models, each trained to launch and to defend against cyberattacks.
      πŸ“Ž Coverage: securityboulevard.com Β· πŸ‘ via securityboulevard.com (discovered)
  • Reddit thread asks for opinions on TryHackMe's new AI Security certification
    A Reddit user asked the cybersecurity community for opinions on TryHackMe's new AI Security certification.

    • Posted in r/cybersecurity by user SonicDasherX asking whether anyone has taken TryHackMe's newly launched AI Security certification
    • The poster asked whether any companies already require or request the certification in job applications
    • The thread had not drawn notable answers in the clustered feed material, so no assessments of the certification's value were available
      πŸ“Ž Coverage: reddit.com Β· πŸ‘ via r/cybersecurity

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • HPE patches critical ArubaOS-CX remote code execution flaw β€” BleepingComputer

  • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root β€” The Hacker News

  • BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory β€” The Hacker News

  • Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data β€” The Hacker News

  • VU#889462: Casdoor authentication server is vulnerable to authorization bypass β€” CERT/CC Vulnerability Notes

  • ASCII smuggling crosses over from AI prompt injection to phishing evasion β€” Microsoft Security Blog

  • itsourcecode Online Medicine Delivery System Customer Controller controller.p... β€” CVE ThreatInt

  • WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) ... β€” CVE ThreatInt

  • WordPress SureForms plugin through 2.12.5 - Insecure Direct Object References (IDO... β€” CVE ThreatInt

  • WordPress KP Agent Ready plugin before 1.2.08 - Sensitive Data Exposure vulnerabil... β€” CVE ThreatInt

  • OpenList: Authenticated arbitrary file write via Content-Disposition path tra... β€” CVE ThreatInt

  • WordPress MountDev AI MCP Connector for WordPress plugin through 1.6.5 - Broken Ac... β€” CVE ThreatInt

  • WordPress Booking and Rental Manager plugin through 2.7.7 - Cross Site Scripting (... β€” CVE ThreatInt

  • WordPress Quick Event Manager plugin through 9.17 - Cross Site Scripting (XSS) vul... β€” CVE ThreatInt

  • WordPress WC Ukraine Shipping plugin through 1.22.3 - Insecure Direct Object Refer... β€” CVE ThreatInt

  • WordPress JobSearch plugin through 3.2.0 - PHP Object Injection vulnerabilityUnaut... β€” CVE ThreatInt

  • WordPress Bricksforge plugin through 3.1.8.8 - Privilege Escalation vulnerabilityS... β€” CVE ThreatInt

  • WordPress GeoDirectory plugin through 2.8.174 - SQL Injection vulnerabilityUnauthe... β€” CVE ThreatInt

  • WordPress BP Better Messages plugin through 2.15.27 - Cross Site Scripting (XSS) v... β€” CVE ThreatInt

  • WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin through 1.51.0 -... β€” CVE ThreatInt

  • WordPress Migrate Guru – Site Migration & Cloning plugin through 6.65 - Denial of ... β€” CVE ThreatInt

  • WordPress Really Simple SSL plugin through 9.8.0 - 2FA Bypass vulnerabilityUnauthe... β€” CVE ThreatInt

  • Signature Optional - Analysis of CVE-2026-28323 β€” Bishop Fox Blog

  • LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access β€” Cyber Security News

  • BTS #81 – Infratrust Pulse, AI’s Role in Security β€” securityboulevard.com (discovered)

  • What Are the Main Types of AI Gateways? LLM, MCP, and Agent Gateways Explained β€” securityboulevard.com (discovered)

  • The Harness Advantage in Autonomous Red Teaming: Why Frontier LLMs Alone Fail Offensive Security and How RidgeGen Solves the Alignment Dilemma β€” securityboulevard.com (discovered)

  • The Honor System Is Ending: Four Places Trust Went Cryptographic β€” securityboulevard.com (discovered)

  • A Stop AI Rogue Act has been introduced. β€” @metacurity@infosec.exchange

  • I'm really tired of all the Hugging Face post-mortems, but this is worth a listen. β€” @metacurity@infosec.exchange

  • β€˜Not perfectly aligned’ with human values: Anthropic admits security failures behind AI hacking incidents | US owner of Claude chatbot previously said its models had hacked three organisations during testing β€” r/cybersecurity

  • Designing a Fail-Closed & Bare-Metal Zeroization Engine: Architectural Challenges β€” r/cybersecurity

  • What do you guys use for quick cybersecurity news? β€” r/cybersecurity

  • Splunk Dashboards and Alerte β€” r/cybersecurity

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check