Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

WORDFENCE-dc1ae2c7-1eff-4976-8f88-f0b97a5cf323Wordfence

Vulnerability Summary

WordPress Core is vulnerable to Missing Authorization via the wp_ajax_activate_plugin() AJAX action in various versions up to, and including, 7.1 due to a missing manage_network_plugins capability check when activating a network-only plugin, and a path-normalization mismatch between is_network_only_plugin() and activate_plugin(). This makes it possible for authenticated attackers with site-administrator access on a Multisite network to network-activate an installed network-only plugin.
Severity Level
LOW(2.7)
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVSS v3.1 Base Metrics — Score 2.7 (LOW)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone

Affected & Patched Versions

Affected Versions
  • WordPress * - 6.6.7
  • WordPress 6.7 - 6.7.7
  • WordPress 6.8 - 6.8.8
  • WordPress 6.9 - 6.9.7
  • WordPress 7.0 - 7.0.4
  • WordPress 7.1 - 7.1
Patched Versions
  • WordPress 1
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.