Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

2026-08-30T07:23:59Z6f2c0031d9860b95e57c3d75078d556b75700d051210a52906b99b2ae2c88c49
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640account-takeoveractive-exploitationai-securityandroidapt28arbitrary-code-executionauthentication-bypassbrowser-extensionscosmos-evmcpanelcritical-vulnerabilitycryptocurrency-theftgocaracalhookedgenextjsowncloudpapercutremote-code-executionservicenowspark-ratsupply-chain-attackvulnerabilitywordpresszbt-routerszero-day

What happened

A security news digest covering actively exploited vulnerabilities, critical product flaws, malware campaigns, supply-chain compromises, and emerging AI, IoT, robotics, blockchain, and privacy security issues. The most urgent items include unauthenticated remote code execution in PaperCut, Next.js, ServiceNow, cPanel, ZBT routers, and WordPress components; exploitation of an ownCloud flaw and a Cosmos EVM vulnerability; and targeted malware activity linked to APT28 and Dark Caracal.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
6f2c0031d9860b95e57c3d75078d556b75700d051210a52906b99b2ae2c88c49
Enrichment time
2026-08-30T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE · Baitaphish