ctipilot.ch

Wordfence Threat Intelligence

wordfence · B · candidate

https://www.wordfence.com/blog/

vulnsresearchlang: enfetch failures: 0quiet periods: 0last fetch: 2026-08-21

2026-08-21: added as this run's single new candidate to close a most-primary-source defect the source list itself caused. Wordfence is a CVE Naming Authority for the WordPress plugin ecosystem and was the originating discloser behind two entries published on 2026-08-19 (CVE-2026-15748 Forminator, CVE-2026-15826 User Profile Builder) — but because the publisher was untracked, both entries cite malware.news, a syndication mirror, rather than the original research. The FEED transport works and immediately surfaced an in-window unauthenticated file-upload disclosure in a 6-million-install plugin that no other tracked source carried; the ARTICLE BODY, however, is unreachable (direct bridge refused, reader pool exhausted, WebFetch empty, both intelligence-API paths unparseable), which is why that item went to the coverage backlog instead of being published thin. Needs an article-body recipe.

Cited in 6 entries

Citation cadence

Citation days per ISO week (4 weeks of coverage span, total 3).