Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

21 / 21 results
Active filter:tag: #web-development✕ clear
Elementor Pro CVE-2026-32475 actively exploited for webshell uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Elementor Pro CVE-2026-32475 actively exploited for webshell uploads

Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.

CVE-2026-324753 Sep · 12:52 UTC
Critical WordPress plugin flaws enable auth bypass and RCE on popular sitescriticalbug_reportVulnerability
bug_reportVulnerability

Critical WordPress plugin flaws enable auth bypass and RCE on popular sites

WPMU DEV Dashboard plugin ≤5.0.1 (CVE-2026-76581), Avada theme ≤7.16 with Fusion Builder ≤3.16 (CVE-2026-18431), TranslatePress ≤3.3.1 with specific config (CVE-2026-19632), Pods plugin ≤3.3.9 (CVE-2026-19598), GiveWP plugin ≤4.16.7.1 (CVE-2026-82222…

CVE-2026-7658129 Aug · 14:25 UTC
Next.js critical RCE flaws in AVIF processing and Windows path traversalcriticalbug_reportVulnerability
bug_reportVulnerability

Next.js critical RCE flaws in AVIF processing and Windows path traversal

Next.js versions 13.4–15.5.23 and 16.0–16.3.2. CVE-2026-75604 (Windows path traversal, CVSS 9.0) affects Windows-hosted servers using Pages Router or App Router without Cache Components.

CVE-2026-7560427 Aug · 13:13 UTC
Avada WordPress theme RCE chain affects sites with theme + plugin activecriticalbug_reportVulnerability
bug_reportVulnerability

Avada WordPress theme RCE chain affects sites with theme + plugin active

Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously.

Avada26 Aug · 19:33 UTC
Elementor Pro WordPress plugin allows arbitrary file upload and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Elementor Pro WordPress plugin allows arbitrary file upload and RCE

Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.

Elementor20 Aug · 12:39 UTC
Forminator WordPress plugin RCE affects 600K+ sites via file upload bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Forminator WordPress plugin RCE affects 600K+ sites via file upload bypass

Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.

CVE-2026-1574817 Aug · 16:22 UTC
WordPress pre-auth XSS on login page enables RCE via admin interactionhighbug_reportVulnerability
bug_reportVulnerability

WordPress pre-auth XSS on login page enables RCE via admin interaction

WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.

CVE-2026-646387 Aug · 10:56 UTC
Terraform MCP, Veeam VSPC, Django patch 11 flaws including CVSS 10.0 bugcriticalbug_reportVulnerability
bug_reportVulnerability

Terraform MCP, Veeam VSPC, Django patch 11 flaws including CVSS 10.0 bug

HashiCorp Terraform MCP Server versions 0.2.1–1.0.0 (Streamable HTTP mode only); Veeam Service Provider Console versions 9.2.1.33875 and earlier (all version 9 builds before 9.3); Django versions prior to 6.0.8 and 5.2.17 (GeoDjango spatial field con…

HashiCorp5 Aug · 12:27 UTC
WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit

WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.

CVE-2026-6013722 Jul · 14:09 UTC
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".

WordPress18 Jul · 15:22 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress17 Jul · 19:20 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin22 Jun · 16:00 UTC
ShapedPlugin WordPress plugins compromised in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress plugins compromised in supply chain attack

Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.

ShapedPlugin18 Jun · 10:55 UTC
Critical vulnerability in Joomla Content Editor (JCE) requires urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in Joomla Content Editor (JCE) requires urgent patching

Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.

Joomla17 Jun · 12:39 UTC
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15 Jun · 15:37 UTC
Everest Forms Pro WordPress plugin under active exploit for site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Everest Forms Pro WordPress plugin under active exploit for site takeover

Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.

CVE-2026-33006 Jun · 12:09 UTC
Active exploitation of RCE flaw in Everest Forms Pro WordPress plugincriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of RCE flaw in Everest Forms Pro WordPress plugin

Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.

CVE-2026-33005 Jun · 06:38 UTC
WP Maps Pro plugin exploited to create rogue admin accounts on WordPresscriticalbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin exploited to create rogue admin accounts on WordPress

WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.

WP Maps Pro1 Jun · 06:45 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang23 May · 07:51 UTC
Critical SQL injection in Drupal Core requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical SQL injection in Drupal Core requires immediate patching

Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.

Drupal21 May · 14:42 UTC
React Server Components RCE flaw enables unauthenticated remote executioncriticalbug_reportVulnerability
bug_reportVulnerability

React Server Components RCE flaw enables unauthenticated remote execution

React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.

Meta4 Dec · 13:50 UTC