ion": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~&(?:Lt|lT|LT|Gt|gT|GT);~"}], "cve": "CVE-2026-84219", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84219", "description": "Kirki <6.3.0 stored XSS via case-variant HTML entity spellings bypassing render-time entity holdback in comment content", "mode": "block", "severity": 7.5, "slug": "kirki", "tags": ["xss", "stored", "unauthenticated", "entity-decoding-bypass"], "target": "plugin", "versions": "<6.3.0"}, "RULE-CVE-2026-8438-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/~"}, {"name": "REQUEST_URI", "type": "regex", "value": "~%3C(?:script|img|svg|iframe|object|embed|details|body|input|form|link|meta|style|marquee|video|audio|math|a(?:%20|\\\\+|%09|/|%2F))(?:%20|%09|%0[aAdD]|\\\\+|%3E|%2F|/)~i"}], "cve": "CVE-2026-8438", "description": "All-In-One Security (AIOS) <=5.4.7 unauthenticated stored XSS via URL-encoded HTML tags in REST API request path", "mode": "block", "severity": 7.2, "slug": "all-in-one-wp-security-and-firewall", "target": "plugin", "versions": "<=5.4.7"}, "RULE-CVE-2026-8438-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/~"}, {"name": "REQUEST_URI", "type": "regex", "value": "~%3C[a-zA-Z][^%]*(?:%20|\\\\+|%09|/)on(?:error|load|click|mouseover|focus|blur|submit|change|input|animationend|toggle)%3D~i"}], "cve": "CVE-2026-8438", "description": "All-In-One Security (AIOS) <=5.4.7 unauthenticated stored XSS via URL-encoded event handler in REST API request path", "mode": "block", "severity": 7.2, "slug": "all-in-one-wp-security-and-firewall", "target": "plugin", "versions": "<=5.4.7"}, "RULE-CVE-2026-84738-01": {"ajax_action": "AFTC_import_demo_data", "conditions": [{"name": "FILES:content_file:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-84738", "description": "AF Companion <2.2.0 unrestricted file upload via content_file parameter in AFTC_import_demo_data AJAX handler leads to RCE", "mode": "block", "slug": "af-companion", "target": "plugin", "versions": "<2.2.0"}, "RULE-CVE-2026-84738-02": {"ajax_action": "AFTC_import_demo_data", "conditions": [{"name": "FILES:widget_file:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-84738", "description": "AF Companion <2.2.0 unrestricted file upload via widget_file parameter in AFTC_import_demo_data AJAX handler leads to RCE", "mode": "block", "slug": "af-companion", "target": "plugin", "versions": "<2.2.0"}, "RULE-CVE-2026-84738-03": {"ajax_action": "AFTC_import_demo_data", "conditions": [{"name": "FILES:customizer_file:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-84738", "description": "AF Companion <2.2.0 unrestricted file upload via customizer_file parameter in AFTC_import_demo_data AJAX handler leads to RCE", "mode": "block", "slug": "af-companion", "target": "plugin", "versions": "<2.2.0"}, "RULE-CVE-2026-84752-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-post\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "rtmhub_callback"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-84752", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84752", "description": "RTMKit (Rometheme for Elementor) <=2.1.5 missing authorization on connector callback exchange (admin-post rtmhub_callback) enabling contributor-level PHP Object Injection chain", "mode": "block", "severity": 8.8, "slug": "rometheme-for-elementor", "tags": ["missing-authorization", "object-injection", "authenticated"], "target": "plugin", "versions": "<=2.1.5"}, "RULE-CVE-2026-84753-01": {"action": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~[OC]:[0-9]+:\\"[^\\"]*\\":[0-9]+:{~"}], "cve": "CVE-2026-84753", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84753", "description": "Mail Mint <=1.31.0 unauthenticated PHP object injection via untrusted unserialize() call (sink file/line and reaching entrypoint not attributed in available evidence; hardened in 1.31.1)", "mode": "block", "severity": 9.8, "slug": "mail-mint", "tags": ["object-injection", "deserialization", "unauthenticated"], "target": "plugin", "versions": "<=1.31.0"}, "RULE-CVE-2026-84759-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:/dateshow|capshow|usershow|typeshow|showaction|sourceshow/", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-84759", "description": "Activity Log <=2.13.1 CSRF-induced reflected XSS via unsanitized admin page filter parameters (dateshow/capshow/usershow/typeshow/showaction/sourceshow)", "mode": "block", "slug": "aryo-activity-log", "target": "plugin", "versions": "<=2.13.1"}, "RULE-CVE-2026-84761-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/litespeed/v3/err_domains[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:/main_domain|alias/", "type": "regex", "value": "~(?:^(?:file|gopher|dict|ftp|sftp|ldap|php|expect|jar|s3|glusterfs)://|^(?:https?://)?(?:127\\\\.0\\\\.0\\\\.1|localhost|0\\\\.0\\\\.0\\\\.0|10\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|172\\\\.(?:1[6-9]|2[0-9]|3[01])\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|192\\\\.168\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|169\\\\.254\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|\\\\[::1\\\\]|\\\\[fd[0-9a-f]{2}:))~i"}], "cve": "CVE-2026-84761", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84761", "description": "LiteSpeed Cache <=7.9 unauthenticated SSRF via err_domains REST callback main_domain/alias parameters (is_from_cloud IP check bypass)", "mode": "block", "severity": 7.2, "slug": "litespeed-cache", "tags": ["ssrf", "unauthenticated", "rest-api", "missing-authorization"], "target": "plugin", "versions": "<=7.9"}, "RULE-CVE-2026-84761-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/litespeed/v3/err_domains[\\\\\\\\/]*$~i"}, {"name": "ARGS:/main_domain|alias/", "type": "regex", "value": "~(?:^(?:file|gopher|dict|ftp|sftp|ldap|php|expect|jar|s3|glusterfs)://|^(?:https?://)?(?:127\\\\.0\\\\.0\\\\.1|localhost|0\\\\.0\\\\.0\\\\.0|10\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|172\\\\.(?:1[6-9]|2[0-9]|3[01])\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|192\\\\.168\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|169\\\\.254\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|\\\\[::1\\\\]|\\\\[fd[0-9a-f]{2}:))~i"}], "cve": "CVE-2026-84761", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84761", "description": "LiteSpeed Cache <=7.9 unauthenticated SSRF via err_domains REST callback main_domain/alias parameters (is_from_cloud IP check bypass)", "mode": "block", "severity": 7.2, "slug": "litespeed-cache", "tags": ["ssrf", "unauthenticated", "rest-api", "missing-authorization"], "target": "plugin", "versions": "<=7.9"}, "RULE-CVE-2026-84763-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:installed_template", "type": "regex", "value": "~(?:(?:javascript|data|vbscript)\\\\s*:|<\\\\/?script[\\\\s>/]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=)~i"}], "cve": "CVE-2026-84763", "description": "RTMKit (rometheme-for-elementor) <=2.1.5 unauthenticated reflected XSS via installed_template parameter on admin template view", "mode": "block", "slug": "rometheme-for-elementor", "target": "plugin", "versions": "<=2.1.5"}, "RULE-CVE-2026-84774-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~i"}, {"name": "ARGS:utm_campaign", "type": "regex", "value": "~(?:<(?:script|img|svg|iframe|body|input)[\\\\s/>]|on(?:error|load|click|mouseover|focus|blur|mouseenter)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-84774", "description": "WP Statistics <=14.16.11 unauthenticated reflected XSS via utm_campaign parameter rendered in admin report/metabox campaign tooltip", "mode": "block", "slug": "wp-statistics", "target": "plugin", "versions": "<=14.16.11"}, "RULE-CVE-2026-84813-01": {"action": "init", "conditions": [{"name": "ARGS:email", "type": "regex", "value": "~(?:UNION(?:/\\\\*.*?\\\\*/|\\\\s)+(?:ALL(?:/\\\\*.*?\\\\*/|\\\\s)+)?SELECT|\'\\\\s*(?:OR|AND|UNION)\\\\b|(?:OR|AND)(?:/\\\\*.*?\\\\*/|\\\\s)+[0-9]+\\\\s*=\\\\s*[0-9]+|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s)~i"}], "cve": "CVE-2026-84813", "description": "GeoDirectory <=2.8.174 unauthenticated SQL injection via POST email parameter in comment review-count filter", "mode": "block", "severity": 9.3, "slug": "geodirectory", "target": "plugin", "versions": "<=2.8.174"}, "RULE-CVE-2026-84820-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~i"}, {"name": "ARGS:action", "type": "equals", "value": "view"}, {"name": "ARGS:page", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-84820", "description": "Unlimited Elements For Elementor <2.0.18 unauthenticated-delivery reflected XSS via page parameter in form entry admin footer view", "mode": "block", "slug": "unlimited-elements-for-elementor", "target": "plugin", "versions": "<2.0.18"}, "RULE-CVE-2026-84829-01": {"ajax_action": "optml_fetch_logs", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-84829", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84829", "description": "Optimole <4.2.12 authenticated information disclosure via optml_fetch_logs AJAX handler missing capability check (deterministically evidenced authorization gap; documented unauthenticated srcset-attribute XSS path remains unlocalized in available artefacts)", "mode": "block", "severity": 8.8, "slug": "optimole-wp", "tags": ["missing-authorization", "information-disclosure", "authenticated"], "target": "plugin", "versions": "<4.2.12"}, "RULE-CVE-2026-84909-01": {"action": "init", "conditions": [{"name": "ARGS:content", "type": "regex", "value": "~\\\\[custom-twitter-feeds\\\\b[^\\\\]]{0,500}?(?:buttoncolor|buttontextcolor|buttontext)\\\\s*=\\\\s*([\'\\"])(?:(?!\\\\1).){0,200}?(?:on\\\\w+\\\\s*=|]|javascript\\\\s*:)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-8494", "description": "Permalink Manager Lite <=2.5.3.3 stored XSS via post title injection through wp-admin/post.php", "mode": "block", "severity": 6.4, "slug": "permalink-manager", "target": "plugin", "versions": "<=2.5.3.3"}, "RULE-CVE-2026-8494-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:title", "type": "regex", "value": "~(?:on(?:focus|blur|click|mouse(?:over|out|enter)|load|error|animat(?:ion(?:end|start|iteration)|ioncancel)|key(?:down|up|press)|change|input|submit|reset|drag(?:start|end|over)?|drop|(?:before)?copy|cut|paste|contextmenu|wheel|scroll|resize|select|toggle|transitionend)\\\\s*=|<\\\\s*(?:script|iframe|embed|object|svg|img|details|marquee|math|video|audio|body|form|isindex|meta|link|style|base|applet|layer|ilayer|bgsound)[\\\\s/>]|javascript\\\\s*:)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-8494", "description": "Permalink Manager Lite <=2.5.3.3 stored XSS via post title injection through REST API /wp/v2/posts", "mode": "block", "severity": 6.4, "slug": "permalink-manager", "target": "plugin", "versions": "<=2.5.3.3"}, "RULE-CVE-2026-85017-01": {"ajax_action": "unitecreator_elementor_import_template", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-85017", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85017", "description": "Unlimited Elements For Elementor <2.0.20 missing capability check on unitecreator_elementor_import_template AJAX action allows subscriber+ PHP object injection via deserialized template data", "mode": "block", "severity": 7.5, "slug": "unlimited-elements-for-elementor", "tags": ["missing-authorization", "object-injection", "deserialization", "authenticated"], "target": "plugin", "versions": "<2.0.20"}, "RULE-CVE-2026-85116-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^(?!/wp-admin/|/wp-login\\\\.php|/wp-cron\\\\.php|/xmlrpc\\\\.php).*$~i"}, {"name": "ARGS", "type": "regex", "value": "~\\\\[[a-zA-Z_][a-zA-Z0-9_-]*\\\\s+[a-zA-Z_][a-zA-Z0-9_-]*\\\\s*=\\\\s*[\\"\'][^\\"\'\\\\]]*[\\"\'][^\\\\]]*\\\\]~"}], "cve": "CVE-2026-85116", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85116", "description": "Simple CAPTCHA with Cloudflare Turnstile >=1.2.2 <1.42.3 unauthenticated arbitrary shortcode execution via do_shortcode() over rendered Contact Form 7 content", "mode": "block", "severity": 6.5, "slug": "simple-cloudflare-turnstile", "tags": ["shortcode-injection", "unauthenticated", "injection"], "target": "plugin", "versions": ">=1.2.2 <1.42.3"}, "RULE-CVE-2026-85130-01": {"ajax_action": "gdpr_log_consent_action", "conditions": [{"name": "ARGS:/subSiteId|currentSite|gdpr_user_action|cookie_list|consent_forward/", "type": "regex", "value": "~(?:]|
<]*(?:=6.5.0 <=11.0.0"}, "TEST-HEARTBEAT": {"action": "init", "conditions": [{"type": "probabilistic", "value": "0.0002"}], "cve": "TEST-HEARTBEAT", "mode": "pass", "severity": 0.1, "target": "core", "versions": ">=1.0.0"}, "TEST-RULE": {"action": "init", "conditions": [{"name": "ARGS:test-rule", "type": "equals", "value": "b3d45e60-53a5-4959-b911-5178baaef7ac"}], "cve": "TEST-CVE", "mode": "block", "severity": 2.0, "target": "core", "versions": ">=1.0.0"}}}', true );