,

Vulnerability Watch No43

📂 Biagiotti Core Vulnerable to Unauthenticated Local File Inclusion
Administrators running Biagiotti Core <= 2.1.1 should remediate promptly because exploitation does not require authentication.
CVE-2026-66657 is an unauthenticated local file inclusion vulnerability affecting Biagiotti Core versions <= 2.1.1. An attacker does not need an authenticated account to target the flaw. It is rated HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD

💉 Reviewer Subscriber Accounts Can Trigger SQL Injection
Reviewer users on versions <= 3.14.2 should patch quickly, particularly in environments where subscriber accounts are readily available.
CVE-2026-66658 is a subscriber-level SQL injection vulnerability affecting Reviewer versions <= 3.14.2. A user with subscriber privileges can reach the vulnerable functionality. The issue is rated HIGH with CVSS 8.5.
🔗 Read more 🔗
Source: NVD

🔐 Multicluster Engine Tenant Isolation Flaw Enables Cross-Tenant Access
Organizations using Multicluster Engine in multi-tenant environments should prioritize remediation because the flaw can break tenant isolation and allow access across tenant boundaries.
CVE-2026-73266 affects the clusterclaims-controller component of Multicluster Engine. An authenticated tenant can manipulate ClusterClaim labels to force a cluster to join a ManagedClusterSet belonging to another tenant, potentially enabling unauthorized policy and workload injection. The vulnerability is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD

💉 WP Directory Kit Hit by Unauthenticated SQL Injection
Administrators running WP Directory Kit <= 1.5.4 should patch promptly because the SQL injection flaw is reachable without authentication.
CVE-2026-27538 is an unauthenticated SQL injection vulnerability affecting WP Directory Kit versions <= 1.5.4. The flaw can be targeted without authentication. It is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD

🚨 Critical Unauthenticated SQL Injection Affects WP Directory Kit
Users of WP Directory Kit <= 1.5.4 should treat this as an urgent patching priority due to its critical severity and unauthenticated attack path.
CVE-2026-28001 is an unauthenticated SQL injection vulnerability affecting WP Directory Kit versions <= 1.5.4. Attackers do not need authentication to target the flaw. The vulnerability is rated CRITICAL with CVSS 9.3.
🔗 Read more 🔗
Source: NVD

💉 CubeWP Subscriber Accounts Can Reach SQL Injection Flaw
Organizations using CubeWP <= 1.1.30 should patch quickly, especially where subscriber accounts are widely available, since that privilege level is sufficient to reach the flaw.
CVE-2026-28168 is a subscriber-level SQL injection vulnerability affecting CubeWP versions <= 1.1.30. Exploitation requires subscriber access. The vulnerability is rated HIGH with CVSS 8.5.
🔗 Read more 🔗
Source: NVD

🧨 WP-Stats Vulnerable to Unauthenticated Cross-Site Scripting
Administrators using WP-Stats <= 2.56 should update promptly because unauthenticated users can reach the vulnerable functionality.
CVE-2026-66426 is an unauthenticated cross-site scripting vulnerability affecting WP-Stats versions <= 2.56. The XSS condition can be targeted without an authenticated account. It is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD

🚨 RealPress Faces Critical Unauthenticated SQL Injection
RealPress users on versions <= 1.1.2 should patch urgently because this is a critical SQL injection vulnerability that does not require authentication.
CVE-2026-66458 is an unauthenticated SQL injection vulnerability affecting RealPress versions <= 1.1.2. No authenticated account is required to target the flaw. The issue is rated CRITICAL with CVSS 9.3.
🔗 Read more 🔗
Source: NVD

📂 Foton Core Exposes Unauthenticated Local File Inclusion
Users of Foton Core <= 1.1.1 should patch promptly because the local file inclusion flaw is accessible without authentication.
CVE-2026-66656 is an unauthenticated local file inclusion vulnerability affecting Foton Core versions <= 1.1.1. The vulnerable functionality can be targeted without authentication. The issue is rated HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD

⬆️ Directories Pro Subscriber Flaw Enables Privilege Escalation
Organizations using Directories Pro <= 2.0.5 should patch promptly, especially where subscriber accounts are broadly available, because the flaw enables privilege escalation from that access level.
CVE-2026-66661 is a subscriber privilege escalation vulnerability affecting Directories Pro versions <= 2.0.5. A subscriber can exploit the flaw to escalate privileges beyond the intended account level. The vulnerability is rated HIGH with CVSS 7.7.
🔗 Read more 🔗
Source: NVD

🚨 CryptoPro Secure Disk Flaw Allows Unsigned Code Execution
Organizations using CryptoPro Secure Disk for Bitlocker before v7.7.4 should upgrade urgently because the flaw defeats the stated IMA policy protection and permits unsigned code execution.
CVE-2025-59326 affects CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4. The product fails to enforce IMA policy protections across temporary file systems, allowing unsigned code to execute from those locations. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🧨 Welcart e-Commerce Exposed to Unauthenticated XSS
Welcart e-Commerce administrators on versions <= 2.11.31 should patch promptly because the cross-site scripting flaw is reachable without authentication.
CVE-2026-27539 is an unauthenticated cross-site scripting vulnerability affecting Welcart e-Commerce versions <= 2.11.31. An attacker does not need an authenticated account to target the XSS condition. The vulnerability is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD