malware.news
malware-news · C · candidate
Discourse forum auto-syndicating multiple vendor security-research RSS feeds verbatim (added 2026-08-19 as this run's single new candidate). Value is as a RECOVERY TRANSPORT, not an original source: wordfence.com refuses every transport available to this pipeline (WebFetch returns an empty body, the direct bridge an HTTP 202 anti-bot challenge shell, and the reader pool is credit-exhausted), and this host reproduces Wordfence Intelligence posts in full — mechanism text, researcher credit, bounty amount and disclosure timeline. Verified this run character-for-character against the CVE descriptions Wordfence supplied as CNA for CVE-2026-15748 and CVE-2026-15826. FETCH -> webfetch the per-topic /t/<slug>/<id> URL. CAUTION: the forum interleaves its own affiliate-marketing text into syndicated posts, so quote only from the syndicated body. Aggregator/mirror, so reliability C and never a substitute for the originating publisher when that publisher is reachable. Promote to active after 3 contributing runs.
Cited in 3 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 2).
- CVE-2026-15826 — User Profile Builder: a 61-to-70-character username makes WordPress return an error object, absint() turns it into the integer 1, and the plugin logs the caller in as user ID 1 (CVSS 9.8)2026-08-19
- CVE-2026-15748 — Forminator Forms (600,000+ WordPress sites): a forged Select-field value overrides the upload allow-list, and the root cause went public seventeen days after the patch (CVSS 9.8)2026-08-19
- CVE-2026-10795 — UpdraftPlus WordPress backup plugin: unauthenticated authentication bypass to RCE2026-06-14