Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61808 – Missing Authentication (Unauthenticated API Access) – LightRAG before 1.5.5rc1

CVE-2026-61808 is a critical missing-authentication vulnerability (CWE-306) in HKUDS LightRAG, a retrieval-augmented generation tool. By default the LightRAG API server binds to all network interfaces with authentication disabled, allowing an unauthenticated remote attacker to reach sensitive API endpoints. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-16038 – Payment Bypass (Missing Authorization) – MStore API WordPress Plugin before 4.21.0

CVE-2026-16038 is a missing authorization (CWE-862) vulnerability in the MStore API WordPress plugin. The plugin does not verify payments with the payment gateway before marking an order as paid, allowing an unauthenticated attacker to mark an arbitrary order as fully paid without paying. It carries a critical CVSS v3.1 base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-16620 – Unauthenticated Price Manipulation – WPC Name Your Price for WooCommerce before 2.2

CVE-2026-16620 is an unauthenticated price manipulation vulnerability in the WPC Name Your Price for WooCommerce WordPress plugin in all versions before 2.2.5. The plugin fails to enforce server-side price validation for products in "Select" price mode, letting attackers complete orders at arbitrary prices below merchant-defined limits. It carries a HIGH severity CVSS v3.1 base score of 7.5.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-14364 – Account Takeover (Unauthenticated) – TrueBooker – Appointment Booking and Scheduler

CVE-2026-14364 is an unauthenticated account takeover vulnerability in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress (vendor themetechmount), affecting all versions up to and including 1.2.3. The plugin fails to properly validate a user's identity before resetting their password, allowing attackers to seize arbitrary accounts, including administrators. It carries a CRITICAL CVSS v3.1 base score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-14365 – Unauthenticated Account Takeover (Password Reset / Missing Authorization) – TrueBoo

CVE-2026-14365 is a critical missing-authorization vulnerability (CWE-862) in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress. The flaw lets an unauthenticated attacker reset the password of any account, including an administrator, resulting in full account takeover. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-14812 – Unauthenticated Backdoor (Hidden Admin / RCE / SSRF) – Premium SEO WordPress Plugin

CVE-2026-14812 is a maximum-severity (CVSS 10.0) flaw in the Premium SEO WordPress plugin, which ships with an embedded malicious backdoor. The plugin allows an unauthenticated, remote attacker to create a hidden administrator account and, in some builds, to achieve remote code execution, server-side request forgery, and arbitrary front-end content injection — resulting in full site compromise.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-16054 – Unauthenticated Arbitrary File Deletion – Drag and Drop Multiple File Upload for Wo

CVE-2026-16054 is an unauthenticated arbitrary file deletion vulnerability in the Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before version 1.1.8. Because the plugin's file-deletion routine is gated only by a nonce that unauthenticated users can obtain, anonymous attackers can delete files staged in its upload directory and irreversibly destroy customers' pending order attachments. It is rated Critical with a CVSS base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-17032 – Supply-Chain Backdoor / Full Site Takeover – Supsystic Pro Plugins (Google Maps Eas

CVE-2026-17032 is a critical supply-chain compromise (CWE-912, Hidden Functionality) in which multiple Supsystic Pro WordPress plugins — including Google Maps Easy Pro — were distributed with malicious code through the vendor's compromised update server. An unauthenticated attacker can leverage the embedded backdoor to deploy a second-stage payload, exfiltrate credentials and other sensitive data, and gain full control of affected sites. The issue carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-11976 – Supply Chain Backdoor / Remote Code Execution – MonsterInsights Pro 10.2.0 and 10.2

CVE-2026-11976 is a critical supply chain compromise affecting MonsterInsights Pro, a Google Analytics plugin for WordPress. Attackers breached the plugin's official AWS S3 update distribution bucket and injected a malicious class-system-check.php file into releases 10.2.0 and 10.2.2, creating a covert backdoor (CWE-912: Hidden Functionality) that grants full remote control of affected sites. Severity is rated 10.0 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-64665 – Authentication Bypass (OAuth Account Takeover) – Statamic CMS < 5.74.1 and 6.0.0–6.

CVE-2026-64665 is an authentication bypass (account takeover) vulnerability in Statamic CMS. When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker can sign in as an existing user — potentially a super admin — by spoofing that user's email address. It is rated High severity (CVSS 8.1).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-63637 – DQL Injection – Dgraph prior to 25.3.8

CVE-2026-63637 is a DQL injection vulnerability in Dgraph, an open-source distributed GraphQL database. The GraphQL query rewriter fails to sanitize regexp filter arguments before converting them into DQL, allowing an unauthenticated network attacker to inject DQL operators and bypass intended filters. It carries a CVSS v3.1 base score of 8.6 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-66662 – Unauthenticated Privilege Escalation – Frontend Admin by DynamiApps WordPress Plugi

CVE-2026-66662 is an unauthenticated privilege escalation vulnerability in the Frontend Admin by DynamiApps WordPress plugin (slug acf-frontend-form-element) in all versions up to and including 3.29.10. The flaw stems from incorrect privilege assignment (CWE-266) and allows an unauthenticated, network-based attacker to gain elevated permissions. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-66447 – Unauthenticated SQL Injection – WordPress File Upload plugin <= 5.1.7

CVE-2026-66447 is an unauthenticated SQL injection vulnerability in the WordPress File Upload plugin for WordPress. Affecting all versions up to and including 5.1.7, it allows a remote, unauthenticated attacker to inject arbitrary SQL through the plugin. It is rated Critical with a CVSS v3.1 base score of 9.3.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65574 – Unauthenticated PHP Object Injection – Abogado WordPress Theme <= 1.18

CVE-2026-65574 is an unauthenticated PHP Object Injection (deserialization of untrusted data) vulnerability in the AncoraThemes "Abogado" WordPress theme. It affects all versions up to and including 1.18 and carries a CVSS v3.1 base score of 9.8 (Critical). An unauthenticated, remote attacker can trigger deserialization of attacker-controlled data, potentially leading to full site compromise.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65579 – Unauthenticated PHP Object Injection (RCE) – Agricola WordPress Theme <= 1.21.0

CVE-2026-65579 is an unauthenticated PHP Object Injection (deserialization of untrusted data, CWE-502) vulnerability in the Agricola WordPress theme by AxiomThemes. It affects Agricola versions up to and including 1.21.0 and carries a CVSS v3.1 base score of 9.8 (Critical). An unauthenticated, remote attacker can exploit it, potentially leading to full site compromise.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-16940 – Unauthenticated Arbitrary File Deletion / Full Site Takeover – Custom Fields WordPr

CVE-2026-16940 is a critical unauthenticated arbitrary file deletion vulnerability in the Custom Fields WordPress plugin in all versions before 1.5.1. The plugin fails to validate a user-supplied file path before deletion, allowing unauthenticated attackers to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover. It carries a maximum CVSS v3.1 base score of 10.0 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-3430 – Unauthenticated SQL Injection – Creative Mail WordPress Plugin 1.6.5–1.6.9

CVE-2026-3430 is an unauthenticated SQL injection vulnerability in the Creative Mail WordPress plugin, affecting versions 1.6.5 through 1.6.9. An unauthenticated attacker can inject arbitrary SQL through the plugin's abandoned cart email functionality, exposing sensitive database contents. It is rated High severity with a CVSS v3.1 base score of 8.6.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65546 – Unauthenticated SQL Injection – Qode Tours WordPress Plugin <= 3.1.3.1

CVE-2026-65546 is an unauthenticated SQL injection vulnerability in the Qode Tours WordPress plugin affecting all versions up to and including 3.1.3.1. An unauthenticated, remote attacker can inject malicious SQL into a database query, exposing sensitive data held by the WordPress site. It carries a CVSS v3.1 base score of 9.3 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65576 – Unauthenticated PHP Object Injection – Adrena WordPress Theme <= 1.2.14

CVE-2026-65576 is an unauthenticated PHP Object Injection vulnerability in the Adrena WordPress theme by AncoraThemes, affecting all versions up to and including 1.2.14. The flaw stems from deserialization of untrusted data (CWE-502) and carries a CVSS v3.1 base score of 9.8 (Critical), allowing complete compromise of an affected site.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-16734 – Payment Amount Tampering (Missing Authorization) – Stripe Payment Forms by WP Full

CVE-2026-16734 is a missing authorization vulnerability (CWE-862) in the Stripe Payment Forms by WP Full Pay WordPress plugin in all versions before 8.5.2. The plugin fails to verify that the caller owns the Stripe payment intent referenced in two unauthenticated payment-form AJAX actions, allowing an unauthenticated attacker to tamper with payment amounts. It carries a CVSS v3.1 base score of 7.5 (HIGH).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-13154 – Unauthenticated Information Exposure – Essential Blocks WordPress Plugin before 6.4

CVE-2026-13154 is an unauthenticated information exposure vulnerability (CWE-200) in the Gutenberg Essential Blocks WordPress plugin in all versions before 6.4.0. A public REST API route fails to verify that a requested post type is publicly viewable, allowing attackers to read published content from post types registered as non-public. The issue carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-13153 – Unauthenticated Information Disclosure – Essential Blocks WordPress Plugin before 6

CVE-2026-13153 is an unauthenticated information disclosure vulnerability in the Essential Blocks WordPress plugin (Gutenberg Essential Blocks) in all versions before 6.4.0. The plugin fails to restrict access to a public REST route, allowing unauthenticated attackers to read a non-public WooCommerce sales metric. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-66710 – Unauthenticated Local File Inclusion – e2pdf WordPress Plugin <= 1.32.40

CVE-2026-66710 is an unauthenticated Local File Inclusion (LFI) vulnerability in the e2pdf WordPress plugin affecting versions up to and including 1.32.40. An unauthenticated remote attacker can cause the plugin to include local files, leading to disclosure of sensitive data and potential code execution. It is rated HIGH severity with a CVSS v3.1 base score of 8.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-66665 – Unauthenticated Arbitrary File Upload – Type Hub WordPress Plugin ≤ 2.0.6

CVE-2026-66665 is an unauthenticated arbitrary file upload vulnerability in the Type Hub WordPress plugin (by Brandexponents) affecting all versions up to and including 2.0.6. Because unauthenticated attackers can upload files of dangerous types, the flaw can lead to full remote server compromise and carries a critical severity rating of 10.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65556 – Unauthenticated PHP Object Injection – WPBruiser {no-Captcha anti-Spam} WordPress P

CVE-2026-65556 is an unauthenticated PHP Object Injection vulnerability in the WPBruiser {no-Captcha anti-Spam} WordPress plugin (package goodbye-captcha) by MihChe, affecting all versions up to and including 3.1.43. The flaw stems from deserialization of untrusted data (CWE-502) and carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65577 – Unauthenticated PHP Object Injection – Advice WordPress Theme <= 1.18.0

CVE-2026-65577 is an unauthenticated PHP Object Injection (insecure deserialization) vulnerability in the AncoraThemes "Advice" WordPress theme affecting all versions up to and including 1.18.0. It carries a CVSS v3.1 base score of 9.8 (Critical), as it can be exploited over the network without authentication or user interaction.

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge