CVE-2026-63030
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Friday's disclosures center on dbgate, which accounts for three critical vulnerabilities including CVE-2026-47668 at CVSS 10, alongside a cluster of high-impact WordPress plugin flaws affecting Participants Database, SAML SSO Login, and GoDAM media management. The day brought 38 critical CVEs, up 245% from the prior day's 11, and 80 high-priority CVEs, up 176% from 29. Named critical issues include CVE-2026-47668 (dbgate) and CVE-2026-59555 (Roland Barker Participants Database), both scored CVSS 10, plus CVE-2026-15981 (CVSS 9.8) in the cyberlord92 SAML SSO Login plugin. The activity skews heavily toward web application and WordPress ecosystem components, with authentication bypass and remote code execution among the recurring attack patterns. Vendor patches were not yet reflected in the source data at disclosure time (0% patch availability), so teams should prioritize compensating controls and monitor affected vendors for updates.
Immediate action: Prioritize dbgate deployments and the affected WordPress plugins (Participants Database, SAML SSO Login, GoDAM), where multiple CVSS 9.0+ and two CVSS 10 flaws concentrate. With no vendor patches yet reflected for the critical items, apply available mitigations, restrict exposed interfaces, and monitor vendor advisories for fixes. Separately, verify remediation on the actively exploited SharePoint, Check Point SmartConsole, and WordPress Core issues.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
A critical vulnerability in Langflow allows unauthenticated remote attackers to execute arbitrary code via the /validate endpoint's exec_globals parameter.
DD-WRT is vulnerable to a stack-based buffer overflow in the UPnP service, which could allow an unauthenticated attacker to achieve remote code execution.
An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.
A deserialization vulnerability in Microsoft SharePoint allows an unauthenticated attacker to execute code over a network.
WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.
The SAML Single Sign On plugin for WordPress contains an authentication bypass flaw that allows unauthenticated users to gain access to any account, including administrative accounts.
A path traversal vulnerability in the DbGate database manager allows unauthenticated attackers to write arbitrary files to the filesystem.
The Customer Support Ticket System & Helpdesk WordPress plugin is vulnerable to unauthenticated code injection via the path parameter, allowing attackers to invoke arbitrary PHP functions.
DbGate is vulnerable to unauthenticated remote code execution via the JSON script runner endpoint, allowing attackers to inject and execute arbitrary JavaScript in a Node.js child process.
DbGate contains an authenticated remote code execution vulnerability in the /runners/load-reader endpoint, allowing attackers with valid credentials to execute OS commands as root.
SiYuan before v3.7.2 is vulnerable to stored cross-site scripting in Attribute View, which can be leveraged to achieve arbitrary command execution due to excessive renderer privileges.
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in its protocol handler, enabling remote code execution due to improper handling of user-supplied input in the tab header.
The GoDAM WordPress plugin suffers from an unrestricted arbitrary file upload vulnerability allowing unauthenticated remote code execution via insufficient file type validation.
The Participants Database WordPress plugin before version 2.7.8.4 is susceptible to an unauthenticated SQL injection vulnerability.
The Roland Barker Participants Database plugin for WordPress contains an unauthenticated arbitrary file deletion vulnerability due to improper path validation.
The Appriss Insights VINE application is vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication and access sensitive PII or user credentials.
Bold Reports Standalone Report Designer contains a path traversal vulnerability in its database download feature, allowing unauthenticated attackers to read arbitrary files from the server.
Thrive Quiz Builder contains an unauthenticated PHP Object Injection vulnerability in versions 10.9.3.0 and below, allowing remote attackers to execute arbitrary code via deserialization.
Avada Core versions 5.15.6 and below are vulnerable to an unauthenticated Cross-Site Request Forgery (CSRF) attack, potentially leading to unauthorized administrative actions.
The MountDev AI MCP Connector plugin for WordPress contains an authorization bypass flaw that allows unauthenticated attackers to obtain administrative OAuth tokens.
Cal.com (cal.diy) versions before 5.9.9 are vulnerable to unauthenticated remote code execution via insecure React Server Components request handling inherited from Next.js.
ManageEngine ADAudit Plus is vulnerable to unauthenticated remote code execution due to a flaw in the agent API, which fails to properly neutralize OS commands.
The WPLake Advanced Views WordPress plugin contains a code injection vulnerability allowing remote code execution for authenticated subscribers.
h2oGPT contains a path traversal vulnerability in its OpenAI-compatible files API, allowing unauthenticated attackers to read, write, or delete arbitrary files.
Quenary tugtainer contains a server-side template injection vulnerability in its notification template feature, allowing authenticated users to execute arbitrary OS commands as root.
Pronetiqs Panduit Intravue is vulnerable to an unintended proxy or intermediary flaw that allows unauthenticated attackers to bypass OT network segmentation.
JetBrains IntelliJ IDEA is susceptible to unauthorized input injection during Remote Development sessions, allowing unauthenticated remote attackers to manipulate application behavior.
JetBrains IntelliJ IDEA is vulnerable to unauthorized settings modification during Remote Development sessions, enabling unauthenticated attackers to alter critical application configurations.
9router allows remote code execution via a chain of vulnerabilities involving default credentials, host header spoofing, and insecure command execution in the plugin registration process.
Eclipse BaSyx Go Components contains an authorization bypass vulnerability where inconsistent trailing-slash handling allows attackers to circumvent ABAC security policies.
The SMS Alert Order Notifications WordPress plugin contains an unauthenticated privilege escalation vulnerability that allows attackers to gain unauthorized administrative access.
TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.
nebula-mesh fails to enforce proper authorization on multiple API endpoints, allowing low-privileged operators to perform unauthorized actions across different network segments.
The Easy Store extension for Joomla is vulnerable to an unauthenticated SQL injection, allowing remote attackers to access database credentials and session data.
The BuddyBoss Platform plugin for WordPress contains an unauthenticated SQL injection vulnerability that allows attackers to execute arbitrary database queries.
MapSVG contains an unauthenticated SQL injection vulnerability in versions 8.14.0 and prior, allowing remote attackers to execute arbitrary database queries.
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.
The Bookly WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 27.7 and prior, enabling attackers to execute arbitrary SQL commands.
The TrueBooker plugin for WordPress is vulnerable to an unauthenticated SQL injection, allowing remote attackers to extract sensitive data via crafted SQL commands.
A repository takeover vulnerability exists in the cal.diy GitHub Actions workflow, allowing attackers to execute arbitrary code via malicious pull requests and compromise the repository.
Bold Reports Standalone Report Designer is susceptible to an unauthenticated path traversal vulnerability, allowing remote attackers to read arbitrary files from the server filesystem.
Bold Reports Standalone Report Designer contains a path traversal vulnerability in its font processing feature, allowing unauthenticated attackers to read arbitrary files from the server filesystem.
The Ninja Forms File Uploads Extension for WordPress contains a Cross Site Request Forgery (CSRF) vulnerability that may allow an attacker to perform unauthorized actions on behalf of a user.
A vulnerability in the MongoDB Server MozJS scripting engine allows authenticated users to read arbitrary files from the host filesystem using the privileges of the mongod process.
A deserialization of untrusted data vulnerability in Johnson Controls victor allows an unauthenticated attacker to compromise system integrity.
The WPify Woo plugin for WordPress contains an improper privilege management vulnerability, allowing authenticated attackers with high privileges to escalate their access level.
An inclusion of functionality from an untrusted control sphere (CWE-829) in JetBrains PhpStorm allows for potential unauthorized system compromise.
JetBrains PhpStorm is susceptible to a vulnerability involving the inclusion of functionality from an untrusted control sphere, potentially leading to total system impact.
A security vulnerability exists in Oracle Platform Security for Java, allowing an authenticated low-privileged attacker to achieve full system takeover via the physical communication segment.
A privilege escalation vulnerability in Fujitsu Linux openFT and Oracle Solaris openFT allows local authenticated attackers to gain unauthorized privileges due to improper privilege management.
The MDJM Event Management plugin for WordPress suffers from an improper privilege management vulnerability, allowing authenticated users to escalate their privileges.
The WPO365 | Login plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, allowing unauthenticated attackers to perform unauthorized actions on behalf of a user.
An authentication bypass vulnerability in MongoDB Server allows authenticated users with low privileges to perform unauthorized data reads and writes by exploiting insufficient command parameter validation.
A heap-based buffer overflow in MongoDB Server occurs during aggregation pipeline processing when compute mode is enabled, potentially allowing for process termination or memory corruption.
A vulnerability in MongoDB Compass allows users to override connection options during the import process, potentially leading to OS command injection.
The BIND resolver contains an origin validation error where it incorrectly accepts NSEC records pointing outside the signer zone, potentially leading to unauthorized DNSSEC validation outcomes.
The Grav API Plugin contains an improper privilege management vulnerability that allows authenticated users to escalate privileges via invitations and groups.
The Grav API Plugin is susceptible to a missing authorization vulnerability that allows attackers to manipulate API functions due to broken access control.
The WP BASE Booking WordPress plugin contains a privilege escalation vulnerability that allows authenticated users with subscriber access to elevate their privileges.
Rapid7 InsightVM, Nexpose, and the Insight Agent contain an execution vulnerability that allows local users to run code with elevated privileges during authenticated assessments.
The decolua 9router application contains a Server-Side Request Forgery (SSRF) vulnerability in its v1 web fetch functionality.
The Create by Mediavine plugin for WordPress contains a SQL injection vulnerability that allows authenticated contributors to execute arbitrary database queries.
The eRoom plugin for WordPress contains a SQL injection vulnerability that allows authenticated contributors to execute arbitrary database queries.
The MapSVG plugin for WordPress contains a SQL injection vulnerability that allows authenticated contributors to execute arbitrary database queries.
The MapSVG plugin for WordPress contains an SQL injection vulnerability that allows authenticated contributors to execute malicious database queries.
The Quiz And Survey Master plugin for WordPress is susceptible to an SQL injection vulnerability, enabling authenticated contributors to perform unauthorized database operations.
The Visualizer plugin for WordPress contains an SQL injection vulnerability that allows authenticated contributors to execute arbitrary database queries.
The libIEC61850 library is susceptible to a heap-based buffer overflow, which can be triggered by a specially crafted MMS Initiate request.
Certain Hikvision camera models contain a heap buffer overflow vulnerability that may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
The Uncanny Automator WordPress plugin contains a SQL injection vulnerability that allows an authenticated administrator to manipulate database queries.
A SQL injection vulnerability in the Persian Woocommerce SMS plugin allows authenticated shop managers to execute arbitrary SQL commands via improper neutralization of user-supplied input.
A cross-site scripting (XSS) vulnerability exists in cal.diy, allowing authenticated users to inject malicious scripts via booking questions.
A cross-site scripting (XSS) vulnerability in cal.diy allows authenticated users to inject malicious scripts through booking questions, mirroring the characteristics of related security flaws.
Snowflake libsnowflakeclient contains multiple vulnerabilities, including stack-based buffer overflows, out-of-bounds writes, and server-side request forgery.
CyberPanel is vulnerable to an authorization bypass flaw allowing attackers to access unauthorized data through user-controlled keys.
Bold Reports Standalone Report Designer is susceptible to a path traversal vulnerability that can lead to remote code execution via file uploads.
JetBrains TeamCity is vulnerable to code injection (CWE-94) in versions prior to 2026.1.2 and 2025.11.6, potentially allowing authenticated attackers to execute arbitrary code.
Grav versions 1.7.0 through 2.0.8 are vulnerable to unsafe reflection (CWE-470), allowing an authenticated attacker to perform remote code execution via FlexDirectory.
The ApusListing WordPress theme through version 1.2.63 is susceptible to Cross-Site Request Forgery (CSRF) (CWE-352), which can lead to broken authentication.
A flaw in the odh-dashboard component of Red Hat OpenShift AI allows for an origin validation error, which may be exploited by an authenticated user to compromise system integrity.
A vulnerability in the entropy initialization for SiWx917 within the Silicon Labs Matter implementation causes the Deterministic Random Bit Generator (DRBG) to use a predictable seed.
The nebula-mesh self-hosted control plane is vulnerable to code injection, which may allow an authenticated attacker to execute arbitrary code within the mesh environment.
Shopper is affected by multiple vulnerabilities, including Cross-site Scripting, sensitive information exposure, and authorization bypass via user-controlled keys.
The Easy Store extension for Joomla is affected by an improper access control vulnerability that may allow unauthorized modification of store data.
NetApp ONTAP 9 software is vulnerable to security flaws that allow authenticated attackers to impact system integrity and availability.
Pronetiqs Panduit Intravue is susceptible to the exposure of sensitive system information to unauthorized actors.
Vanna AI Vanna suffers from a path traversal vulnerability via the FilesystemConversationStore, allowing unauthorized access to arbitrary files on the underlying system.
JetBrains PyCharm contains a vulnerability related to untrusted input, which could allow for unauthorized code execution or system impact when processing malicious project files.
JetBrains IntelliJ IDEA contains a vulnerability involving improper authorization, which may allow an attacker to bypass security checks and gain unauthorized access to sensitive information.
Exim versions 4.88 through 4.99.4 are vulnerable to a path traversal flaw, allowing unauthenticated attackers to potentially read or manipulate arbitrary files on the host system.
A vulnerability in JetBrains WebStorm versions prior to 2026.2 involves the inclusion of untrusted functionality or components, which could lead to unauthorized code execution.
A vulnerability in JetBrains WebStorm versions prior to 2026.2 allows for the inclusion of untrusted functionality, which could potentially lead to unauthorized system actions.
A vulnerability in JetBrains WebStorm allows for potential unauthorized access or system compromise due to improper inclusion of control functionality.
A vulnerability in Bosch Configuration Manager version 7 allows for the cleartext storage of sensitive information, potentially leading to unauthorized data exposure.
A stored cross-site scripting (XSS) vulnerability in n8n allows for the execution of malicious scripts via the cached result URL parameter.
The lib60870 library is vulnerable to an out-of-bounds read, potentially allowing an attacker to crash the parsing process and cause a denial of service.
Chatwoot versions prior to 4.16.0 are vulnerable to an authentication bypass that allows unauthenticated users to perform arbitrary blob creation via ActiveStorage direct uploads.
The Convert Forms extension for Joomla is vulnerable to improper access control and sensitive information exposure.
A DOM-based Cross-site Scripting (XSS) vulnerability exists in n8n due to improper neutralization of input within unsandboxed iframes.
A missing authorization vulnerability in the cancelBackupCreation handler of CyberPanel allows authenticated users to impact system availability and data integrity.
A code injection vulnerability (CWE-94) in JetBrains IntelliJ IDEA allows for potential remote code execution under specific conditions.
An unauthenticated authentication bypass vulnerability exists in the miniOrange Discord Integration plugin for WordPress, allowing unauthorized access to affected systems.
A vulnerability in Progress Telerik UI for ASP.NET AJAX allows attackers to use externally controlled input to select classes or code, potentially leading to unauthorized execution.
A deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allows remote attackers to execute arbitrary code by supplying malicious serialized data.
A path traversal vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to access restricted directories via improper pathname validation.
Progress Telerik UI for ASP.NET AJAX contains a vulnerability where unauthenticated attackers can use externally controlled input to select arbitrary code or classes for execution.
An unsafe deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to execute arbitrary code via malicious serialized objects.
Magarsus Consulting IDM-MFA contains an improper validation of specified type of input vulnerability, which may allow for unauthorized data manipulation.
The gpsd software is susceptible to code injection via the sky satellites used field, which may allow for arbitrary code execution.
FFmpeg contains an out-of-bounds write vulnerability in the tdsc video decoder, which may lead to memory corruption or arbitrary code execution.
FFmpeg versions 0 through 8.1.2 are susceptible to out-of-bounds write and integer underflow vulnerabilities that may allow for code execution.
FFmpeg versions 3.4 through 8.1.2 are vulnerable to an out-of-bounds write and incorrect buffer size calculation in the vf_floodfill filter, potentially leading to code execution.
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect filter, which may allow for arbitrary code execution via crafted NV12 frame processing.
JetBrains GoLand is susceptible to code injection, potentially allowing an attacker to execute arbitrary code via malicious input.
JetBrains GoLand contains a code injection vulnerability that may allow for arbitrary code execution if a user is induced to process malicious data.
JetBrains WebStorm is vulnerable to inclusion of functionality from an untrusted control sphere, which could lead to unauthorized code execution.
A vulnerability in JetBrains IntelliJ IDEA allows for potential file inclusion or manipulation due to improper inclusion of control functionality, identified as CWE-829.
The pardus-update utility is vulnerable to OS command injection due to improper neutralization of special elements, which could allow a local attacker to execute arbitrary commands.
A flaw in the Visual Studio Code Ansible Lightspeed extension allows for argument injection via the AnsiblePlaybookRunProvider.
A flaw in the Ansible Lightspeed Visual Studio Code extension allows for OS command injection.
A path traversal vulnerability in Traefik allows unauthenticated attackers to bypass authentication via the replacePathRegex middleware.
The Kali Forms plugin for WordPress allows authenticated subscribers to perform arbitrary file deletion via path traversal.
The n8n workflow automation tool contains an authorization bypass vulnerability that allows authenticated users to escalate privileges via user-controlled keys.