Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
2026-08-29T19:24:00Z•7054f5ec8409af7fbada9f0348fc4b13a4ac5777604a3e0fa69ed914bfd3ca65
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76581CVE-2026-76639CVE-2026-76640APT28-HOOKEDGE המ?AndroidCosmos-EVMIoTNext.jsPaperCutServiceNowWordPressaccount-takeoveractive-exploitationauthentication-bypassbrowser-extensionscPanelcryptocurrency-theftdata-exfiltrationmalwareownCloudransomware-extortionremote-code-executionroot-accessroutersunauthenticated-accessvulnerabilitiesweb-application-securityzero-day
What happened
A collection of cybersecurity reports covering actively exploited vulnerabilities, critical flaws, malware campaigns, supply-chain compromises, data extortion, and emerging attacks against WordPress, PaperCut, ownCloud, Next.js, ServiceNow, routers, cPanel, Cosmos EVM, Android, robotics, browser extensions, GPUs, and AI development tools. Several issues enable unauthenticated remote code execution, root access, authentication bypass, account takeover, data theft, or cryptocurrency theft; multiple vulnerabilities are reportedly exploited in the wild or listed in CISA KEV.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7054f5ec8409af7fbada9f0348fc4b13a4ac5777604a3e0fa69ed914bfd3ca65
- Enrichment time
- 2026-08-29T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.