Critical SQL Injection bug in Ally plugin threatens 400,000+ WordPress sites
2026-03-12T14:51:47Z•3ee982a74377e58dadeb64dd95bb246e2bbb8d0f0f953cf0ddf6cdd22430ad5f
Ally-pluginAruba-AOS-CXBell-AmbulanceCISACVE-2025-68613CVE-2026-23813CVE-2026-2413ENISAFortiGateKadNapMicrosoft-Patch-TuesdayStrykerandroid-malwarebanking-trojanbotnetcrypto-minerdata-breachexploitationhacktivismn8npackage-managerssql-injectionsupply-chainwordpress
What happened
Feed highlights multiple high-impact security events: an unauthenticated SQL injection in the Ally WordPress plugin (CVE-2026-2413, CVSS 7.5) threatens 400K+ sites; CISA added a critical n8n flaw (CVE-2025-68613, CVSS 10.0) to its KEV catalog; HPE patched a critical Aruba AOS-CX authentication bypass (CVE-2026-23813, CVSS 9.8). Other notable items include a 238K-person Bell Ambulance data breach, a disruptive hacktivist claim against Stryker, the BeatBanker Android banking/crypto-mining malware, a KadNap router-based proxy botnet of 14K+ devices, Microsoft’s March 2026 Patch Tuesday fixing 84+
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 3ee982a74377e58dadeb64dd95bb246e2bbb8d0f0f953cf0ddf6cdd22430ad5f
- Enrichment time
- 2026-03-12T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.