Posts of last 24 hours
A vulnerability described as critical has been identified in stylemix Motors Plugin up to 1.4.111 on WordPress. This vulnerability affects the function stm_mark_as_sold_car. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-12435. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/375423
A vulnerability marked as problematic has been reported in thimpress LearnPress Plugin up to 4.4.0 on WordPress. Affected by this vulnerability is the function FilterCourseTemplate::sections of the file /filter-courses/layout of the component Shortcode Handler. This manipulation of the argument class_wrapper_form causes cross site scripting.
This vulnerability appears as CVE-2026-12732. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/375464
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow
https://buaq.net/go-426377.html
RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk […]
https://securityaffairs.com/194556/malware/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow.html
A simple implementation flaw allowed email verification to be completed without ever opening the ver
https://buaq.net/go-426385.html
A simple implementation flaw allowed email verification to be completed without ever opening the ver
https://buaq.net/go-426358.html
A vulnerability labeled as critical has been found in cozyvision1 SMS Alert Plugin up to 3.9.5 on WordPress. Affected by this issue is some unknown functionality of the component Password Reset Handler. The manipulation results in improper authentication.
This vulnerability is known as CVE-2026-11387. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/375421
A vulnerability marked as problematic has been reported in rilwis Slim SEO Plugin up to 4.9.8 on WordPress. This affects the function Data::get_post_content of the file /wp-json/slim-seo/meta-tags/ai of the component REST API Endpoint. This manipulation of the argument object.ID causes information disclosure.
This vulnerability is handled as CVE-2026-12408. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/375422
A vulnerability, which was classified as critical, was found in qodeinteractive Qi Blocks Plugin up to 1.4.9 on WordPress. The impacted element is an unknown function of the component Endpoint. The manipulation of the argument page_id results in authorization bypass.
This vulnerability is identified as CVE-2026-10096. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/375427
A vulnerability described as problematic has been identified in codename065 Download Manager Plugin up to 3.3.60 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. Such manipulation of the argument no_data_msg leads to cross site scripting.
This vulnerability is traded as CVE-2026-13733. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/375465