🤖 vLLM Loader Flaw Enables Remote Code Execution
Teams running affected vLLM versions should upgrade as soon as possible and review untrusted models loaded by the service. Prioritize remediation for deployments that accept external model files.
CVE-2026-90553 is a remote code execution vulnerability in vLLM before 0.28.0 involving the LlavaOnevision2 processor loader ignoring the trust_remote_code parameter. Attackers can craft malicious models containing code that executes with vLLM process authority even when trust_remote_code is set to False. The vulnerability is HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD
📧 AVideo Scheduler Bug Exposes Email Jobs
AVideo administrators should patch affected deployments quickly and review scheduler activity for suspicious access. Internet-facing instances should be treated as higher priority.
CVE-2026-90537 affects WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 due to a missing authorization vulnerability in the scheduler email functionality. Unauthenticated attackers can access scheduler email jobs, read private live titles and email addresses, and trigger email sending by providing a valid daily token. The vulnerability is HIGH with CVSS 8.2.
🔗 Read more 🔗
Source: NVD
🔑 MemberPress Flaw Allows Administrator Account Takeover
WordPress administrators using affected MemberPress Corporate Accounts versions should update immediately and review administrator accounts for unexpected changes. Pay close attention to sites with many subscriber-level users.
CVE-2026-15451 is a privilege escalation vulnerability in the MemberPress Corporate Accounts plugin for WordPress through version 1.5.39. A mass assignment issue in the add_sub_account_user function can allow authenticated corporate account users to create administrator accounts or hijack existing administrator accounts. The vulnerability is HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
⚠️ YayPricing Plugin Enables Stored Script Attacks
Administrators using affected YayPricing versions should update immediately and review users with elevated access. Shared sites with many contributors should prioritize this fix.
CVE-2026-87888 affects the YayPricing WordPress plugin before 3.5.7 because a REST route that saves pricing rules lacks authorization checks. Users with subscriber access or higher can store JavaScript that executes in the browser of an administrator opening the settings page. The vulnerability is HIGH with CVSS 8.0.
🔗 Read more 🔗
Source: NVD
🔓 Zonify Plugin Leaks Authentication Tokens
Sites using Zonify should update immediately and rotate any exposed service account credentials or tokens. Review linked accounts for suspicious activity after remediation.
CVE-2026-87842 affects the Zonify WordPress plugin before 1.0.5 because it does not perform capability or authentication checks before returning stored account login tokens. Unauthenticated attackers can retrieve the tokens and authenticate to the site owner’s linked service account. The vulnerability is HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
👤 Add User Autocomplete Bug Grants Admin Roles
Multisite WordPress administrators should patch quickly and audit role assignments and pending invitations. Prioritize environments where subscriber accounts are widely available.
CVE-2026-87759 affects the Add User Autocomplete WordPress plugin before 1.2 because it lacks capability and nonce checks when creating pending site-membership invitations. Any authenticated user, including a subscriber, can grant themselves the administrator role on a multisite installation. The vulnerability is HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🚨 WP Component Flaw Allows Full Site Takeover
Remove or update affected WP Component installations immediately and investigate for unauthorized option changes. Treat exposed sites as potentially compromised until reviewed.
CVE-2026-85681 affects the WP Component WordPress plugin through 2.2.4 because an unauthenticated action lacks capability and nonce checks while accepting option names and values from requests. Unauthenticated attackers can overwrite site options, leading to a full takeover on single-site installations where registration can be enabled with an administrator default role. The vulnerability is CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
📤 piclect Upload Bug Enables Server Code Execution
Patch or remove the affected plugin immediately and inspect uploaded files for malicious content. Publicly accessible WordPress sites should be treated as urgent remediation targets.
CVE-2026-84171 affects the WP images upload on piclect WordPress plugin through 1.0 because uploaded files are not properly validated before being written to a public directory. Unauthenticated attackers can upload arbitrary files and execute arbitrary code on the server. The vulnerability is CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
💥 wpstorecart Deserialization Issue Risks Code Injection
WordPress administrators using wpstorecart should update or disable the affected component immediately. Monitor for signs of exploitation, especially on ecommerce sites.
CVE-2026-84099 affects the wpstorecart WordPress plugin through 5.0.7 because an add-on allows direct unauthenticated access to unsafe deserialization of user-supplied input. Attackers can inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain exists on the site. The vulnerability is HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD
🗄️ Album Cover Finder Plugin Exposes SQL Injection Risk
Site owners should update immediately and review database activity for suspicious queries. Public-facing installations using this plugin should be prioritized.
CVE-2026-84047 affects the Album Cover Finder WordPress plugin through 0.7.0 because a parameter used in a SQL query is not properly sanitized and escaped. Unauthenticated users can perform SQL injection attacks against affected sites. The vulnerability is HIGH with CVSS 8.6.
🔗 Read more 🔗
Source: NVD
🎓 Masteriyo LMS Vulnerability Enables Code Execution
Organizations using Masteriyo LMS should patch urgently and review user activity logs. This issue can result in server compromise if exploited.
CVE-2026-82845 affects the Masteriyo LMS WordPress plugin before 3.4.1 because user-supplied metadata can be deserialized without preventing unsafe objects. Users with a minimal account can inject arbitrary PHP objects that may allow writing and executing arbitrary code on the server, while a weaker unauthenticated path allows arbitrary file writes. The vulnerability is CRITICAL with CVSS 9.9.
🔗 Read more 🔗
Source: NVD
🧩 BE REST Endpoints Plugin Allows Script Injection
Administrators using this plugin should patch quickly and review stored widget content for malicious scripts. Public websites should treat this as a priority fix.
CVE-2026-81742 affects the BE REST Endpoints WordPress plugin through 1.0.0 because it lacks authorization checks and does not sanitize stored widget values. Unauthenticated users can inject arbitrary web scripts that execute in the browser of users visiting the site. The vulnerability is HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD