CVE-2026-3620
The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, a
CVSS
4.4
Medium
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Published: Jun 2, 2026 · Last modified: Jul 22, 2026 · CWE-20
0.2%EPSS · 30 days0.2%
2026-07-312026-08-27
The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/tags/0.4/word-replacer.php#L191
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/tags/0.4/word-replacer.php#L230
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/tags/0.4/word-replacer.php#L339
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/tags/0.4/word-replacer.php#L343
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/trunk/word-replacer.php#L191
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/trunk/word-replacer.php#L230
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/trunk/word-replacer.php#L339
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/word-replacer/trunk/word-replacer.php#L343
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/b827f0e1-b8ee-4015-a608-45505f43b324?source=cve
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-55068——
———free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum values, heartBeatTimer ranges, mandatory profile fields, or nfServices.ipEndPoints address constraints. The invalid profiles are persisted in the MongoDB NfProfile collection and returned by NFDiscover, allowing an attacker with SBI access to advertise attacker-controlled network-function endpoints and redirect control-plane signaling. This can expose credentials and signaling, alter service discovery integrity, and deny service across network functions that trust the NRF. This issue is fixed in version 4.2.3.16hCVE-2026-78009——
——0An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.16hCVE-2026-593226.3 MED—
——0The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier13hCVE-2026-81827——
——0Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object.
Consequently, malformed attacker-controlled email input could continue through the login process and be written to security-relevant logs. The vulnerable code inserted the supplied email into both a warning log and the custom audit logger. Since CR/LF characters were not escaped, an unauthenticated attacker could potentially inject additional physical log lines or forge misleading log entries.
The patch corrects the validation call to Email()(form, form.email), changes the standard logging call to parameterized logging, and introduces _sanitize_log_fragment() so carriage returns and line feeds are encoded instead of creating new records.
Version impacted >=3.3.020hCVE-2026-817079.8 CRI—
——0openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.2dCVE-2026-816866.2 MED—
——0openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call Set without authorization and set MaxConcurrentOperations (to 0/negative, causing the concurrency gate to refuse all subsequent operations, or to a huge value removing the limit) or the unbounded DefaultTimeout, resulting in a persistent denial of service of the root daemon. The D-Bus service exists only on the 1.4.x line and was removed in 1.5.x.17h