Wordfence Threat Intelligence
wordfence · B · candidate
https://www.wordfence.com/blog/
2026-08-21: added as this run's single new candidate to close a most-primary-source defect the source list itself caused. Wordfence is a CVE Naming Authority for the WordPress plugin ecosystem and was the originating discloser behind two entries published on 2026-08-19 (CVE-2026-15748 Forminator, CVE-2026-15826 User Profile Builder) — but because the publisher was untracked, both entries cite malware.news, a syndication mirror, rather than the original research. The FEED transport works and immediately surfaced an in-window unauthenticated file-upload disclosure in a 6-million-install plugin that no other tracked source carried; the ARTICLE BODY, however, is unreachable (direct bridge refused, reader pool exhausted, WebFetch empty, both intelligence-API paths unparseable), which is why that item went to the coverage backlog instead of being published thin. Needs an article-body recipe.
Cited in 6 entries
Citation cadence
Citation days per ISO week (4 weeks of coverage span, total 3).
- Technology & SaaS supply chain — the week's busiest victim class2026-06-29
- ShapedPlugin's official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft2026-06-29
- ShapedPlugin build pipeline compromised — three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell2026-06-23
- CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch2026-06-08
- CVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation campaign2026-06-08
- CVE-2026-3300 — Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale2026-06-08