CVE-2026-73998 — Subscriber: SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. CVSSv3.1 8.5 (HIGH)
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. CVSSv3.1 9.8 (CRITICAL)
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. CVSSv3.1 9.9 (CRITICAL)
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. CVSSv3.1 9.3 (CRITICAL)
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. CVSSv3.1 9.1 (CRITICAL)
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Capella <= 2.5.5 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. CVSSv3.1 8.1 (HIGH)
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resul CVSSv3.1 9.1 (CRITICAL)
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to CVSSv3.1 9.6 (CRITICAL)
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. CVSSv3.1 8.0 (HIGH)
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface. CVSSv3.1 9.8 (CRITICAL)
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. CVSSv3.1 8.8 (HIGH)
SliverMirage is a Crystal Palace PICO loader for Sliver C2 that implements dual-layer AMSI bypass (CLR string corruption + VEH hardware breakpoints), ETW silencing via DR1 hardware breakpoints, and AES-256-CBC encrypted payloads. It provides six delivery variants (staged/stageless EXE, DLL, shellcode) with clean IAT, no memory patching of system DLLs, and entropy-controlled stageless payloads.
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover. CVSSv3.1 9.8 (CRITICAL)