🧩 Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin
WordPress operators running this plugin should update as soon as a fixed release is available, especially on sites using supported form builders that populate the vulnerable action list. The lack of an authentication requirement makes internet-facing installations a priority.
CVE-2026-16145 affects the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin through version 5.1. An unauthenticated attacker can abuse the ‘action’ parameter to store malicious JavaScript that executes when users visit an affected page. The vulnerability is rated HIGH with CVSS 7.2.
🔗 Read more 🔗
Source: NVD
🍪 Cookie Consent Plugin Exposes WordPress Sites to Stored XSS
Sites using this plugin should patch promptly, with extra urgency where Google Consent Mode support is enabled. Administrators should also review low-privilege accounts because the affected AJAX handler lacks nonce and capability checks.
CVE-2026-13360 affects the Cookie Banner for GDPR / CCPA – WPLP Cookie Consent WordPress plugin through version 4.3.5. The ‘regionArray’ parameter can be used for stored cross-site scripting because of inadequate sanitization and output escaping, with exploitation requiring the ‘Support Google Consent Mode (GCM)’ setting to be enabled. The vulnerability is rated HIGH with CVSS 7.2.
🔗 Read more 🔗
Source: NVD
📤 MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE
Any internet-facing WordPress site using MaxUpload should patch immediately or disable the plugin until a fix is deployed. Unauthenticated arbitrary file upload with a path to remote code execution warrants emergency treatment.
CVE-2026-15965 affects the MaxUpload – Big File Uploads – Increase Maximum File Upload Size WordPress plugin through version 1.4.0. A filename-validation mismatch allows unauthenticated attackers to bypass extension and MIME checks when chunks are assembled, potentially placing executable files on the server and enabling remote code execution. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🔓 User Session Synchronizer Bug Allows Full WordPress Account Takeover
Treat this as an emergency patch for every exposed WordPress installation using the plugin. Because exploitation requires no authentication and can yield administrator access, disabling the plugin until a fixed version is installed is prudent where immediate patching is not possible.
CVE-2026-15341 affects the User Session Synchronizer WordPress plugin through version 1.4.0. Weak and predictable cryptographic handling combined with missing nonce, capability and shared-secret validation lets unauthenticated attackers forge synchronization requests and authenticate as a targeted user, including an administrator. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
⬆️ Propovoice Manager Accounts Can Escalate to WordPress Administrator
Organizations using Propovoice should patch promptly and review which users hold the plugin’s manager role. This is especially important on sites where CRM staff have been delegated manager privileges without full WordPress administrative trust.
CVE-2026-15312 affects the Propovoice: All-in-One Client Management System WordPress plugin through version 1.7.8. Its user-creation REST endpoint fails to restrict the supplied ‘role’ value or require the ‘promote_users’ capability, allowing users with ‘ndpv_manager’-level access or higher to create administrator accounts. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🚨 6Storage Rentals Authentication Bypass Exposes WordPress Admin Accounts
Patch or disable this plugin immediately on every reachable WordPress site. The flaw provides unauthenticated administrator-level account takeover with minimal prerequisites, making it a top-priority incident-prevention issue.
CVE-2026-15303 affects the 6Storage Rentals WordPress plugin through version 2.27.0. An unauthenticated AJAX handler accepts an attacker-supplied email address and sets WordPress authentication state for the matching account without nonce, credential, capability or ownership checks. Attackers can therefore log in as any existing user, including administrators; the vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
💉 Object Sync for Salesforce REST Route Allows Unauthenticated SQL Injection
Sites using Object Sync for Salesforce should patch urgently or restrict access to the affected REST route until fixed. Because no WordPress authentication or Salesforce connection is required, public installations should be considered directly exposed.
CVE-2026-15162 affects the Object Sync for Salesforce WordPress plugin through its ‘/wp-json/object-sync-for-salesforce/push/’ REST route. The ‘wordpress_object_type’ parameter is inserted into a database query without prepared statements, while the route lacks meaningful authentication checks, allowing unauthenticated time-based blind SQL injection and potential extraction of sensitive data such as password hashes. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🎟️ bLoyal Plugin Chain Lets Subscribers Hijack WordPress Administrator Sessions
WordPress sites using bLoyal should patch urgently and review Subscriber-level accounts for suspicious activity. The ability for a low-privilege account to pivot to full administrator access makes this considerably more serious than a typical authenticated flaw.
CVE-2026-15001 affects the bLoyal: Loyalty & Promotions by bLoyal WordPress plugin through version 3.1.611.78. Subscriber-level users can modify unprotected plugin configuration to point the bLoyal API at an attacker-controlled service, then abuse the ‘/cart’ REST route to supply a chosen customer identifier and obtain authentication as another WordPress user, including an administrator. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🗑️ RapiSafe File Deletion Flaw Can Lead to WordPress RCE
Patch or disable RapiSafe immediately on affected sites, particularly where its upload field appears on public Contact Form 7 pages. Unauthenticated arbitrary file deletion with a plausible route to remote code execution should be treated as an emergency.
CVE-2026-14484 affects the RapiSafe – Secure Multi File Upload for Contact Form 7 WordPress plugin through version 1.0.4. Insufficient path validation allows unauthenticated attackers to delete arbitrary server files, and the required nonce is exposed to visitors in public-facing JavaScript. Deleting critical files such as ‘wp-config.php’ can create a path to remote code execution; the vulnerability is rated CRITICAL with CVSS 9.1.
🔗 Read more 🔗
Source: NVD
📅 vcita Booking Plugin Vulnerable to Unauthenticated Stored XSS
Operators using the vcita booking plugin should patch promptly, particularly on public booking sites with significant administrator traffic. Stored XSS reachable without authentication can be useful for session theft, malicious redirects and administrative compromise.
CVE-2026-14433 affects the Online Booking & Scheduling Calendar for WordPress by vcita plugin through version 4.6.0. Insufficient sanitization and output escaping of the ‘business_id’ parameter allows unauthenticated attackers to store arbitrary JavaScript that executes when users visit the affected page. The vulnerability is rated HIGH with CVSS 7.2.
🔗 Read more 🔗
Source: NVD
🔐 Laravel Socialite Facebook Provider Allows OIDC Token Replay
Applications using Laravel Socialite with Facebook OIDC login should update promptly and review their token-handling flow. Prioritize services where captured tokens could be replayed against sensitive or privileged accounts.
CVE-2026-73683 affects Laravel Socialite’s Facebook provider. Missing nonce validation in ‘getUserByOIDCToken()’ allows an unauthenticated attacker who obtains a valid, unexpired OIDC ‘id_token’ for the same Facebook App ID to replay it and gain unauthorized access to the victim’s account. The vulnerability is rated HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD
🛡️ Microsoft Defender Malware Protection Engine Hit by ShieldBreak Privilege Escalation
Defender administrators should monitor Microsoft’s advisory closely and deploy the security update as soon as it becomes available. Until then, keep Defender components current and treat affected endpoints as requiring heightened attention because a complete fix is not yet described in the entry.
CVE-2026-69414 is an elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender and is publicly referred to as ‘ShieldBreak’. Microsoft says it is developing a security update and will add further information to the CVE when the update is available. The vulnerability is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD