๐ต๏ธ RESEARCH & DEEP DIVES
-
EmbedPress plugin before 4.6.4 lets Contributors modify site-wide Google Reviews (CVE-2026-84927)
A missing authorization flaw in EmbedPress's Google Reviews REST API lets Contributor-level users alter site-wide review data.- Affects WordPress sites running the EmbedPress plugin versions 4.6.0 through 4.6.3 (fixed in 4.6.4).
- Missing authorization check (CWE-862) on a Google Reviews REST API route allows Contributor-role users and above to modify a site-wide store.
- Attackers can delete administrator-configured review entries and inject their own, which render publicly across the site.
- A related flaw (CVE-2026-84926) exposes administrator data via the same Google Reviews REST routes to contributor-level users.
- Issued as CVE-2026-84927, assigned by WPScan; credited to Artus KG.
๐ Source: wpscan.com ยท ๐ Coverage: radar.offseq.com ยท ๐ via CVE ThreatInt
-
Eventin WordPress plugin before 4.1.22 lets contributors hijack site homepage via missing REST authorization
The Eventin WordPress plugin before 4.1.22 lacks authorization checks on event-management REST routes, letting contributor-level users hijack the site's front page.- Affects sites running the Eventin event management plugin (wp-event-solution) in versions before 4.1.22.
- Several event-management REST routes are missing authorization checks (CWE-862), tracked as CVE-2026-84901.
- Contributor-level users and above can change the site's front-page setting to an event they do not own.
- They can also create, edit and delete global event and speaker taxonomy terms they should not manage.
- Vulnerability found by Sai Praneeth Koti, coordinated by WPScan; a related path traversal flaw (CVE-2026-84898) affects versions before 4.1.21.
๐ Source: wpscan.com ยท ๐ Coverage: radar.offseq.com ยท ๐ via CVE ThreatInt
-
Divi through 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via... โ CVE ThreatInt
-
Welcart e-Commerce through 2.12.1 - Unauthenticated Arbitrary File Deletion via PH... โ CVE ThreatInt
-
Spam protection, Honeypot, Anti-Spam by CleanTalk through 6.86 - Unauthenticated S... โ CVE ThreatInt
-
Beaver Builder Plugin (Pro Version) through 2.11.0.1 - Reflected Cross-Site Script... โ CVE ThreatInt
-
YT Player before 2.1.0 - Contributor+ SQLi via ytp_ajaxThe Video Player for YouTub... โ CVE ThreatInt
-
EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumpti... โ CVE ThreatInt
-
HT Menu before 1.2.7 - Subscriber+ Stored XSS via Menu SettingsThe HT Menu WordPre... โ CVE ThreatInt
-
JCH Optimize before 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task OverrideT... โ CVE ThreatInt
-
Joli Table Of Contents before 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Th... โ CVE ThreatInt
-
CatFolders Document Gallery before 2.0.7 - Author+ Stored XSS via titleTag Block A... โ CVE ThreatInt
-
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Go... โ CVE ThreatInt
-
RE: https:// mastodon.social/@eff/117215319 335459732 I suspect a lot of people should transform their EFF donations to... โ @GossiTheDog@cyberplace.social
-
SonicWall NSM On-Prem RCE via OS Command Injection (CVE-2026-78327) โ thehackerwire.com (discovered)
-
Cyber Talk 13 Qualys: What Security Leaders Can Learn From Its Evolution From Vulnerability Scanning to Risk Operations โ securityboulevard.com (discovered)
๐ ADVISORIES
- ๐ Source for Divi WordPress theme โค4.27.6 vulnerable to DOM-based stored XSS via video slider image_src parameter โ wordfence.com