PULSE
FEED
ransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Servicesransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Services
← Todos los CVEs
CVE Watch6 oct 2026

CVE-2026-105701

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render f

CVSS

8.8

Alto

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-434

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-105868—
—
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.51m
CVE-2026-1058628.7 ALT
—
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.51m
CVE-2026-1040697.2 ALT
—
———HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.4h
CVE-2026-3977010.0 CRÍ
—
———Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.6h
CVE-2026-397599.9 CRÍ
—
———Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.6h
CVE-2026-397579.9 CRÍ
—
———Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.6h