Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

12 / 12 results
Active filter:tag: #web-development✕ clear
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Scope appears to be remote code execution vulnerabilities in core WordPress installation.

WordPress15:22 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress19:20 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin16:00 UTC
ShapedPlugin WordPress plugins compromised in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress plugins compromised in supply chain attack

Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.

ShapedPlugin10:55 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla12:39 UTC
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15:37 UTC
Everest Forms Pro WordPress plugin under active exploit for site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Everest Forms Pro WordPress plugin under active exploit for site takeover

Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.

CVE-2026-330012:09 UTC
Active exploitation of RCE flaw in Everest Forms Pro WordPress plugincriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of RCE flaw in Everest Forms Pro WordPress plugin

Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.

CVE-2026-330006:38 UTC
WP Maps Pro plugin exploited to create rogue admin accounts on WordPresscriticalbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin exploited to create rogue admin accounts on WordPress

WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.

WP Maps Pro06:45 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang07:51 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal14:42 UTC
React Server Components RCE flaw enables unauthenticated remote executioncriticalbug_reportVulnerability
bug_reportVulnerability

React Server Components RCE flaw enables unauthenticated remote execution

React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.

Meta13:50 UTC