L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin14 menções
incransom8 menções
safepay8 menções
Wallstreet7 menções
threeam7 menções
everest6 menções
emperador5 menções
medusalocker4 menções
N0n3 menções
Panzer3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
N0nPrecision Facades LtdGB · Manufacturing · 2026-09-29
netrunnerM*** P**** M***MY · Not Found · 2026-09-28
lockbit5camorim.com.brBR · Retail & E-Commerce · 2026-09-29
qilinArnold CenterUS · Not Found · 2026-09-28
threeamsafescaffolding.netGB · Manufacturing · 2026-09-28
threeamcoosalud.comCO · Healthcare · 2026-09-28
threeampistonespersan.com.arAR · Manufacturing · 2026-09-28
threeammidwestbit.comUS · Technology · 2026-09-28
threeamapexus.comUS · Technology · 2026-09-28
threeambhn-expertise.comDE · Professional Services · 2026-09-28
threeamstjames.wa.edu.auAU · Education · 2026-09-28
DoommageddonGoodrich Logistics— · Transportation · 2026-09-28
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

8621 REGISTROS ENCONTRADOSFEED 2026-09-22
CVE-2026-88798MEDIUM

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-87966MEDIUM

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-87965MEDIUM

The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.21%
CVE-2026-87775HIGH

The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.32%
CVE-2026-87774HIGH

The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.32%
CVE-2026-87771HIGH

The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.32%
CVE-2026-87770HIGH

The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.32%
CVE-2026-87767HIGH

The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.32%
CVE-2026-85350MEDIUM

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-85127HIGH

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.30%
CVE-2026-85123MEDIUM

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-85122HIGH

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.34%
CVE-2026-85009MEDIUM

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.20%
CVE-2026-84904LOW

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.

AFFECTED SURFACEProduct not specified
CVSS 3.8EPSS 0.19%
CVE-2026-84903LOW

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access.

AFFECTED SURFACEProduct not specified
CVSS 2.7EPSS 0.23%
CVE-2026-84902MEDIUM

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.

AFFECTED SURFACEProduct not specified
CVSS 6.8EPSS 0.29%
CVE-2026-84738CRITICAL

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.56%
CVE-2026-81810HIGH

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.32%
CVE-2026-81340LOW

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.

AFFECTED SURFACEProduct not specified
CVSS 3.8EPSS 0.23%
CVE-2026-18912HIGH

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

AFFECTED SURFACEProduct not specified
CVSS 7.7EPSS 1.50%
CVE-2026-18911HIGH

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 1.06%
CVE-2026-17086HIGH

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.89%
CVE-2026-93468HIGH

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.46%
CVE-2026-93467CRITICAL

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.52%