Wordfence Threat Intelligence
wordfence · B · active
https://www.wordfence.com/blog/
2026-08-21: added as this run's single new candidate to close a most-primary-source defect the source list itself caused. Wordfence is a CVE Naming Authority for the WordPress plugin ecosystem and was the originating discloser behind two entries published on 2026-08-19 (CVE-2026-15748 Forminator, CVE-2026-15826 User Profile Builder), but because the publisher was untracked, both entries cite malware.news, a syndication mirror, rather than the original research. The FEED transport works and immediately surfaced an in-window unauthenticated file-upload disclosure in a 6-million-install plugin that no other tracked source carried; the ARTICLE BODY, however, is unreachable (direct bridge refused, reader pool exhausted, WebFetch empty, both intelligence-API paths unparseable), which is why that item went to the coverage backlog instead of being published thin. Needs an article-body recipe.
Cited in 5 entries
Citation cadence
Citation days per ISO week (16 weeks of coverage span, total 3).
- CVE-2026-87902, WordPress Core: unauthenticated page-template path traversal to conditional remote code execution, weaponised within a day (CVSS4.0 9.2)2026-09-24
- ShapedPlugin build pipeline compromised, three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell2026-06-23
- CVE-2026-49200 / CVE-2026-49201, Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch2026-06-08
- CVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation campaign2026-06-08
- CVE-2026-3300, Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale2026-06-08