View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

SonicWall NSM On-Prem RCE via OS Command Injection (CVE-2026-78327)

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • EmbedPress plugin before 4.6.4 lets Contributors modify site-wide Google Reviews (CVE-2026-84927)
    A missing authorization flaw in EmbedPress's Google Reviews REST API lets Contributor-level users alter site-wide review data.

    • Affects WordPress sites running the EmbedPress plugin versions 4.6.0 through 4.6.3 (fixed in 4.6.4).
    • Missing authorization check (CWE-862) on a Google Reviews REST API route allows Contributor-role users and above to modify a site-wide store.
    • Attackers can delete administrator-configured review entries and inject their own, which render publicly across the site.
    • A related flaw (CVE-2026-84926) exposes administrator data via the same Google Reviews REST routes to contributor-level users.
    • Issued as CVE-2026-84927, assigned by WPScan; credited to Artus KG.
      ๐Ÿ“„ Source: wpscan.com ยท ๐Ÿ“Ž Coverage: radar.offseq.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Eventin WordPress plugin before 4.1.22 lets contributors hijack site homepage via missing REST authorization
    The Eventin WordPress plugin before 4.1.22 lacks authorization checks on event-management REST routes, letting contributor-level users hijack the site's front page.

    • Affects sites running the Eventin event management plugin (wp-event-solution) in versions before 4.1.22.
    • Several event-management REST routes are missing authorization checks (CWE-862), tracked as CVE-2026-84901.
    • Contributor-level users and above can change the site's front-page setting to an event they do not own.
    • They can also create, edit and delete global event and speaker taxonomy terms they should not manage.
    • Vulnerability found by Sai Praneeth Koti, coordinated by WPScan; a related path traversal flaw (CVE-2026-84898) affects versions before 4.1.21.
      ๐Ÿ“„ Source: wpscan.com ยท ๐Ÿ“Ž Coverage: radar.offseq.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Divi through 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via... โ€” CVE ThreatInt

  • Welcart e-Commerce through 2.12.1 - Unauthenticated Arbitrary File Deletion via PH... โ€” CVE ThreatInt

  • Spam protection, Honeypot, Anti-Spam by CleanTalk through 6.86 - Unauthenticated S... โ€” CVE ThreatInt

  • Beaver Builder Plugin (Pro Version) through 2.11.0.1 - Reflected Cross-Site Script... โ€” CVE ThreatInt

  • YT Player before 2.1.0 - Contributor+ SQLi via ytp_ajaxThe Video Player for YouTub... โ€” CVE ThreatInt

  • EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumpti... โ€” CVE ThreatInt

  • HT Menu before 1.2.7 - Subscriber+ Stored XSS via Menu SettingsThe HT Menu WordPre... โ€” CVE ThreatInt

  • JCH Optimize before 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task OverrideT... โ€” CVE ThreatInt

  • Joli Table Of Contents before 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Th... โ€” CVE ThreatInt

  • CatFolders Document Gallery before 2.0.7 - Author+ Stored XSS via titleTag Block A... โ€” CVE ThreatInt

  • EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Go... โ€” CVE ThreatInt

  • RE: https:// mastodon.social/@eff/117215319 335459732 I suspect a lot of people should transform their EFF donations to... โ€” @GossiTheDog@cyberplace.social

  • SonicWall NSM On-Prem RCE via OS Command Injection (CVE-2026-78327) โ€” thehackerwire.com (discovered)

  • Cyber Talk 13 Qualys: What Security Leaders Can Learn From Its Evolution From Vulnerability Scanning to Risk Operations โ€” securityboulevard.com (discovered)

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Divi WordPress theme โ‰ค4.27.6 vulnerable to DOM-based stored XSS via video slider image_src parameter โ€” wordfence.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check