Continue reading the full briefing.
CVE-2026-3141: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion…
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to delete arbitrary…
Why it matters: CVE-2026-3141 may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
Operational focus: Confirm whether the vulnerable route, plugin, framework, or API behavior is enabled and public.
Open the original NIST National Vulnerability Database record
CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
## Summary `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. A confirmed gadget in `publicApiCheck()` causes this to bypass authorization on all piece-type REST API endpoints for every subsequent unauthenticated request, for the lifetime of the Node.js process. — ## Details ### Root Cause…
Why it matters: GitHub Advisory Database apostrophe participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Patch the component, test authentication and authorization boundaries, and review suspicious requests.
CVE-2026-15052: The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for…
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a…
Why it matters: CVE-2026-15052 may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
Operational focus: Use a WAF as temporary risk reduction where appropriate, but keep the permanent software fix owned.
Open the original NIST National Vulnerability Database record
CVE-2026-15988: The AI Engine – The Chatbot, AI Framework & MCP for WordPress…
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via…
Why it matters: CVE-2026-15988 may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
Operational focus: Confirm whether the vulnerable route, plugin, framework, or API behavior is enabled and public.
Open the original NIST National Vulnerability Database record
CVE-2026-58185: The Apache Traffic Server intercept plugin has a use-after-free. This issue affects…
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Why it matters: CVE-2026-58185 may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
Operational focus: Patch the component, test authentication and authorization boundaries, and review suspicious requests.
Open the original NIST National Vulnerability Database record
Application response plan
Confirm that the affected route or component is actually enabled, then patch the permanent cause. Use temporary filtering only as a bridge and review requests for evidence of attempted abuse.
- Inventory WordPress core, plugins, themes, frameworks, and public API versions.
- Prioritize unauthenticated injection, authorization bypass, file access, and remote execution paths.
- Patch affected components and remove unused or abandoned extensions.
- Review web, application, authentication, and administrative change logs for abuse.
- Validate security headers, least-privilege roles, backups, and recovery after remediation.
Requests and control signals
Check route reachability, authentication state, roles, request patterns, component versions, and recovery readiness.
- Confirm whether the vulnerable route, plugin, framework, or API behavior is enabled and public.
- Patch the component, test authentication and authorization boundaries, and review suspicious requests.
- Use a WAF as temporary risk reduction where appropriate, but keep the permanent software fix owned.
Web security takeaway
Permanent web risk reduction comes from fixing the vulnerable component or authorization path, then validating the result with request evidence and recovery checks.
References used in this briefing
- CISA Known Exploited Vulnerabilities: CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- NIST National Vulnerability Database: CVE-2026-8457: The WooCommerce – Social Login plugin for WordPress is vulnerable to Authentication…
- NIST National Vulnerability Database: CVE-2026-15964: The Single Sign On For TNG plugin for WordPress is vulnerable to…
- NIST National Vulnerability Database: CVE-2026-3141: The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion…
- GitHub Advisory Database: CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
- NIST National Vulnerability Database: CVE-2026-15052: The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for…
- NIST National Vulnerability Database: CVE-2026-15988: The AI Engine – The Chatbot, AI Framework & MCP for WordPress…
- NIST National Vulnerability Database: CVE-2026-58185: The Apache Traffic Server intercept plugin has a use-after-free. This issue affects…
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.


