#vuln — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.
-
CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: https://radar.offseq.com/threat/cve-2026-85681-cwe-269-improper-privilege-management-in-wp-component-ee74cec7c7b526ed #OffSeq #WordPress #Vuln #BlueTeam
-
CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: https://radar.offseq.com/threat/cve-2026-85681-cwe-269-improper-privilege-management-in-wp-component-ee74cec7c7b526ed #OffSeq #WordPress #Vuln #BlueTeam
-
CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: https://radar.offseq.com/threat/cve-2026-85681-cwe-269-improper-privilege-management-in-wp-component-ee74cec7c7b526ed #OffSeq #WordPress #Vuln #BlueTeam
-
CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. https://radar.offseq.com/threat/cve-2026-86781-cwe-287-improper-authentication-in-ssl-zen-ssl-certificate-installer-https-redirects-fc40efb64c1b1964 #OffSeq #WordPress #Vuln #TLS
-
CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. https://radar.offseq.com/threat/cve-2026-86781-cwe-287-improper-authentication-in-ssl-zen-ssl-certificate-installer-https-redirects-fc40efb64c1b1964 #OffSeq #WordPress #Vuln #TLS
-
CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. https://radar.offseq.com/threat/cve-2026-86781-cwe-287-improper-authentication-in-ssl-zen-ssl-certificate-installer-https-redirects-fc40efb64c1b1964 #OffSeq #WordPress #Vuln #TLS
-
CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. https://radar.offseq.com/threat/cve-2026-86781-cwe-287-improper-authentication-in-ssl-zen-ssl-certificate-installer-https-redirects-fc40efb64c1b1964 #OffSeq #WordPress #Vuln #TLS
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce