The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTT...
Description
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4
Remediation
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
---METADATA---
VENDOR: KUNBUS
PRODUCT: piControl
AFFECTED_VERSIONS: 0 through 2.6.2
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A race condition vulnerability in the configuration and process-image management of KUNBUS piControl versions 0 through 2.6.2 may allow local authenticated attackers to disrupt system operations.
Executive Summary:
A race condition vulnerability in KUNBUS piControl versions 0 through 2.6.2 enables locally authenticated attackers to compromise system integrity through improper resource synchronization.
Vulnerability Details
CVE-ID: CVE-2026-13197
Affected Software: KUNBUS piControl
Affected Versions: 0 through 2.6.2
Vulnerability: The software contains a race condition (CWE-362) within its configuration and process-image management modules, caused by improper synchronization when accessing shared resources. This allows a local attacker with low privileges (PR:L) to trigger the flaw under specific timing conditions.
Business Impact
A successful exploit could lead to inconsistent system states, denial of service, or unauthorized modification of process data. With a CVSS score of 7.3, this vulnerability threatens the reliability of the industrial processes managed by the piControl software.
Remediation Plan
Immediate Action: Consult the vendor for security patches that address synchronization issues in the configuration management module.
Proactive Monitoring: Monitor for unusual CPU spikes or synchronization errors in system logs that may correlate with attempts to exploit race conditions.
Compensating Controls: Implement strict access control policies to ensure that only trusted users have local access to the system, thereby reducing the attack surface.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 16, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Race conditions are often difficult to exploit reliably but can have significant impacts on sensitive process-control environments.
Analyst Recommendation
Immediate attention is required to patch this vulnerability to ensure the continued integrity of the piControl environment. Organizations should verify their current version and coordinate with KUNBUS support to apply the most current security updates.