π΅οΈ RESEARCH & DEEP DIVES
-
LearnDash LMS through 5.1.5 vulnerable to subscriber-level arbitrary file upload (CVE-2026-12483) The LearnDash LMS WordPress plugin versions up to 5.1.5 allow authenticated users to upload arbitrary disallowed files, including PHP, via the assignment upload handler.
- Affects WordPress sites running StellarWP LearnDash LMS plugin versions up to and including 5.1.5 with assignment uploads enabled.
- Insufficient validation in the 'learndash_fileupload_process' function validates only the first file in an array, allowing upload of disallowed files including PHP to wp-content/uploads/learndash/assignments/.
- Attackers need subscriber-level access or above and must be enrolled in a course with assignment uploads enabled.
- Remote Code Execution is possible only if server configuration has been changed to allow execution of uploaded files.
- CVSS 3.1 score 7.5 High (AV:N/AC:H/PR:L/UI:N); CWE-434, assigned by Wordfence, credited to Nguyen Ngoc Duc (duc193). π Source: wordfence.com Β· π Coverage: cve.threatint.com Β· π via CVE ThreatInt
-
Critical Citrix NetScaler auth bypass now leveraged in attacks β BleepingComputer
-
Microsoft says some users canβt open the Teams desktop client β BleepingComputer
-
39 New Methods That Compromise Passkey Authentication β BleepingComputer
-
Nvidiaβs $12.9B Hugging Face deal could benefit enterprises β Cybersecurity Dive
-
OpenAI pledges $1 billion to provide resources, training for frontline cyber defenders β Cybersecurity Dive
-
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic β The Hacker News
-
Possible XSS in the SNS web administration panelItβs possible to run a stored... β CVE ThreatInt
-
Langflow is vulnerable to arbitrary file write and arbitrary file deletion du... β CVE ThreatInt
-
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to ... β CVE ThreatInt
-
User Enumeration in GastroMenum's GastroMenum Web PanelObservable response di... β CVE ThreatInt
-
HTML Injection via Improper Input Sanitization in Yordam Informatics's Librar... β CVE ThreatInt
-
Missing Authorization Allows Unauthorized Access to Critical POS Functions in... β CVE ThreatInt
-
Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu SystemImproper neu... β CVE ThreatInt
-
valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob ou... β CVE ThreatInt
-
Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library A... β CVE ThreatInt
-
Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Met... β CVE ThreatInt
-
code-projects Vehicle Management System SQL Database Backup File vehicle_mana... β CVE ThreatInt
-
code-projects Vehicle Management System busprofile.php sql injectionA vulnera... β CVE ThreatInt
-
(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open... β CVE ThreatInt
-
StackStorm st2 API Key auth.py privileges managementA security vulnerability ... β CVE ThreatInt
-
StackStorm st2 NoOp RBAC backend actionexecutions.py privileges managementA w... β CVE ThreatInt
-
GFI Exinda AI before 7.6.5 Argument Injection via Tools Iperf ClientGFI Exinda AI ... β CVE ThreatInt
-
GFI Exinda AI before 7.6.5 Path Traversal via Diagnostic File Deletion HandlerGFI ... β CVE ThreatInt
-
GFI Exinda AI before 7.6.5 Path Traversal via Configuration Download HandlerGFI Ex... β CVE ThreatInt
-
Hackers Use Popular Messaging Services to Control New Windows Backdoors β Cyber Security News
-
NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots β Cyber Security News
-
Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails β Cyber Security News
-
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you β r/netsec
-
Getting Agents to tell on themselves β r/netsec
-
153 Million Reasons Document Verification Isnβt Identity Assurance β securityboulevard.com (discovered)
-
OpenAI Pledges $1 Billion in AI Cybersecurity Tools to Protect Critical Infrastructure β securityboulevard.com (discovered)
-
Researcher Releases Exploit of Claimed CrowdStrike Falcon Zero-Day β securityboulevard.com (discovered)
-
How Much Does ISO 27001 Certification Cost for a Startup? β securityboulevard.com (discovered)
-
Before you head out for the last true weekend of summer in the Northern Hemisphere, don't miss today's Metacurity for... β @metacurity@infosec.exchange