Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
2026-08-30T01:24:00Z•3057d92c88938ee4f4154d6c3adc4d1c4046447a316a7ca2074427c898ce516d
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640active-exploitationai-securityapt28authentication-bypassbrowser-extensionscosmos-evmcritical-vulnerabilitiescvesdata-exfiltrationhardware-securityiot-securitymalwarenextjsowncloudpapercutransomwareremote-code-executionroot-accessservicenowsupply-chain-securitywordpress
What happened
The feed reports multiple critical and actively exploited vulnerabilities affecting WordPress plugins, Cosmos EVM blockchains, PaperCut, ownCloud, ServiceNow, ZBT routers, cPanel, Next.js, Unitree robots, and other widely deployed technologies. It also covers ransomware/extortion, malware campaigns, supply-chain compromises, APT28-linked activity, malicious browser extensions, AI prompt injection, and novel hardware attacks. Several issues enable unauthenticated remote code execution, root access, authentication bypass, account takeover, cryptocurrency theft, or data exfiltration; confirmed or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 3057d92c88938ee4f4154d6c3adc4d1c4046447a316a7ca2074427c898ce516d
- Enrichment time
- 2026-08-30T01:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.