Recycled NVD feed posts; no PoC, KEV, or defender signals; pure disclosure chatter.
What: Directory traversal in Bit Integrations WordPress plugin (≤2.9.0) allowing unauthenticated attackers to read arbitrary server files; CVSS 7.5 HIGH.
Why it matters: Published today with no KEV listing or public PoC reported yet. Social chatter is automated vulnerability feed syndication rather than exploitation signals. Plugin affects WordPress deployments widely, but no defender triage or urgent vendor patching advisories visible in the posts. Early-stage disclosure with moderate impact if exploited.
Where it's seen: Vulnerability feeds (Patchstack radar, The Hacker Wire) republishing the NVD entry same-day; generic infosec social alerts with no exploitation context or patch availability mentioned.
Published hours ago, high CVSS, no PoC/KEV yet, but exploitation is straightforward and inevitable.
What: FormGent WordPress plugin (≤1.9.2) allows unauthenticated arbitrary file deletion via unauth REST API endpoint; path traversal can delete wp-config.php, enabling site takeover. CVSS 9.1 CRITICAL.
Why it matters: Published today with high CVSS score and clear exploitation path (no auth required, REST endpoint exposed). NVD details confirm complete site takeover risk on default Linux installs. Not yet KEV-listed but imminent risk to thousands of WordPress sites running the plugin.
Where it's seen: Multilingual social chatter (Hebrew, Russian, Japanese) on Bluesky amplifying disclosure same-day; posts describe practical exploitation scenarios. No public PoC or in-the-wild reports visible yet, but vulnerability is trivial to exploit (REST endpoint + file deletion + no checks).
Fresh advisory, vendor patch released same day, high install base, but no wild PoC or in-the-wild reports yet.
What: Cross-Site Request Forgery (CSRF) in AI Engine WordPress plugin (versions ≤3.6.5) enabling unauthenticated attackers to create administrator accounts via admin-click social engineering. CVSS 8.8 HIGH.
Why it matters: Plugin deployed on 100,000+ WordPress sites; flaw requires no attacker account, only admin click on malicious link; allows full account takeover. Published today with patched version 3.6.6 available. No KEV listing yet but high-impact scope drives immediate patch urgency.
Where it's seen: Bluesky posts echoing NVD advisory within 2 hours of publication; plugin vendor patching actively signaled; chatter emphasizes scale (100k+ sites) and ease of exploitation (social engineering + method override).
Also trending
- 4 CVE-2026-18236 score 1 · 1 posthype unscored hack
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.
- 5 CVE-2026-59247 score 1 · 1 posthype unscored hack
Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency resolution Gleam fetches package metadata from the signature-verified Hex repository, which covers each release's dependency requirements and SHA-256 outer_checksum. After resolving versions, gleam_cli::dependencies::lookup_package makes a second request to the unsigned Hex API through gleam_core::hex::get_package_release and records the outer_checksum and dependency names from that JSON response into manifest.toml, instead of the values from the verified repository metadata. The Hex repository signature does not cover the API response. An adversary in the middle who can intercept TLS with a certificate trusted by the Gleam process (for example a TLS-inspecting proxy using a CA in the operating system trust store or added through GLEAM_CACERTS_PATH), and who can modify both the API release response and the corresponding repository tarball, can supply a package archive with a matching forged checksum without the Hex repository signing key. Gleam verifies the forged tarball against the forged checksum, accepts it, and extracts it as a dependency source, resulting in loss of integrity of the downloaded package contents. Only projects that resolve or update Hex dependencies are affected, which happens when the manifest is missing, a dependency is added or updated, or dependency requirements change. Builds that reuse an unchanged, known-good manifest.toml continue to verify tarballs against its pinned checksum. This issue affects gleam: from 0.18.0 before 1.18.0.
- 6 CVE-2026-64816 MEDIUM · 6.5 score 1 · 1 posthype unscored hack
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The vulnerable code path is reachable through two vectors: community presets fetched automatically from the remote preset repository when the victim opens the Community tab, and individual preset files imported directly by the victim via the preset import feature (handle_import_presets_from_file in file_management.rs). The second vector does not require control of the community preset repository and is triggered when a user imports a preset file shared through Discord, forums, or similar channels.
- 7 CVE-2025-69134 HIGH · 7.5 score 1 · 1 posthype unscored hack
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
- 8 CVE-2026-60201 HIGH · 8.1 score 1 · 1 posthype unscored hack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).