ion": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~&(?:Lt|lT|LT|Gt|gT|GT);~"}], "cve": "CVE-2026-84219", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84219", "description": "Kirki <6.3.0 stored XSS via case-variant HTML entity spellings bypassing render-time entity holdback in comment content", "mode": "block", "severity": 7.5, "slug": "kirki", "tags": ["xss", "stored", "unauthenticated", "entity-decoding-bypass"], "target": "plugin", "versions": "<6.3.0"}, "RULE-CVE-2026-8438-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/~"}, {"name": "REQUEST_URI", "type": "regex", "value": "~%3C(?:script|img|svg|iframe|object|embed|details|body|input|form|link|meta|style|marquee|video|audio|math|a(?:%20|\\\\+|%09|/|%2F))(?:%20|%09|%0[aAdD]|\\\\+|%3E|%2F|/)~i"}], "cve": "CVE-2026-8438", "description": "All-In-One Security (AIOS) <=5.4.7 unauthenticated stored XSS via URL-encoded HTML tags in REST API request path", "mode": "block", "severity": 7.2, "slug": "all-in-one-wp-security-and-firewall", "target": "plugin", "versions": "<=5.4.7"}, "RULE-CVE-2026-8438-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/~"}, {"name": "REQUEST_URI", "type": "regex", "value": "~%3C[a-zA-Z][^%]*(?:%20|\\\\+|%09|/)on(?:error|load|click|mouseover|focus|blur|submit|change|input|animationend|toggle)%3D~i"}], "cve": "CVE-2026-8438", "description": "All-In-One Security (AIOS) <=5.4.7 unauthenticated stored XSS via URL-encoded event handler in REST API request path", "mode": "block", "severity": 7.2, "slug": "all-in-one-wp-security-and-firewall", "target": "plugin", "versions": "<=5.4.7"}, "RULE-CVE-2026-84738-01": {"ajax_action": "AFTC_import_demo_data", "conditions": [{"name": "FILES:content_file:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-84738", "description": "AF Companion <2.2.0 unrestricted file upload via content_file parameter in AFTC_import_demo_data AJAX handler leads to RCE", "mode": "block", "slug": "af-companion", "target": "plugin", "versions": "<2.2.0"}, "RULE-CVE-2026-84738-02": {"ajax_action": "AFTC_import_demo_data", "conditions": [{"name": "FILES:widget_file:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-84738", "description": "AF Companion <2.2.0 unrestricted file upload via widget_file parameter in AFTC_import_demo_data AJAX handler leads to RCE", "mode": "block", "slug": "af-companion", "target": "plugin", "versions": "<2.2.0"}, "RULE-CVE-2026-84738-03": {"ajax_action": "AFTC_import_demo_data", "conditions": [{"name": "FILES:customizer_file:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-84738", "description": "AF Companion <2.2.0 unrestricted file upload via customizer_file parameter in AFTC_import_demo_data AJAX handler leads to RCE", "mode": "block", "slug": "af-companion", "target": "plugin", "versions": "<2.2.0"}, "RULE-CVE-2026-84752-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-post\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "rtmhub_callback"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-84752", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84752", "description": "RTMKit (Rometheme for Elementor) <=2.1.5 missing authorization on connector callback exchange (admin-post rtmhub_callback) enabling contributor-level PHP Object Injection chain", "mode": "block", "severity": 8.8, "slug": "rometheme-for-elementor", "tags": ["missing-authorization", "object-injection", "authenticated"], "target": "plugin", "versions": "<=2.1.5"}, "RULE-CVE-2026-84753-01": {"action": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~[OC]:[0-9]+:\\"[^\\"]*\\":[0-9]+:{~"}], "cve": "CVE-2026-84753", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84753", "description": "Mail Mint <=1.31.0 unauthenticated PHP object injection via untrusted unserialize() call (sink file/line and reaching entrypoint not attributed in available evidence; hardened in 1.31.1)", "mode": "block", "severity": 9.8, "slug": "mail-mint", "tags": ["object-injection", "deserialization", "unauthenticated"], "target": "plugin", "versions": "<=1.31.0"}, "RULE-CVE-2026-84759-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:/dateshow|capshow|usershow|typeshow|showaction|sourceshow/", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-84759", "description": "Activity Log <=2.13.1 CSRF-induced reflected XSS via unsanitized admin page filter parameters (dateshow/capshow/usershow/typeshow/showaction/sourceshow)", "mode": "block", "slug": "aryo-activity-log", "target": "plugin", "versions": "<=2.13.1"}, "RULE-CVE-2026-84761-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/litespeed/v3/err_domains[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:/main_domain|alias/", "type": "regex", "value": "~(?:^(?:file|gopher|dict|ftp|sftp|ldap|php|expect|jar|s3|glusterfs)://|^(?:https?://)?(?:127\\\\.0\\\\.0\\\\.1|localhost|0\\\\.0\\\\.0\\\\.0|10\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|172\\\\.(?:1[6-9]|2[0-9]|3[01])\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|192\\\\.168\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|169\\\\.254\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|\\\\[::1\\\\]|\\\\[fd[0-9a-f]{2}:))~i"}], "cve": "CVE-2026-84761", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84761", "description": "LiteSpeed Cache <=7.9 unauthenticated SSRF via err_domains REST callback main_domain/alias parameters (is_from_cloud IP check bypass)", "mode": "block", "severity": 7.2, "slug": "litespeed-cache", "tags": ["ssrf", "unauthenticated", "rest-api", "missing-authorization"], "target": "plugin", "versions": "<=7.9"}, "RULE-CVE-2026-84761-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/litespeed/v3/err_domains[\\\\\\\\/]*$~i"}, {"name": "ARGS:/main_domain|alias/", "type": "regex", "value": "~(?:^(?:file|gopher|dict|ftp|sftp|ldap|php|expect|jar|s3|glusterfs)://|^(?:https?://)?(?:127\\\\.0\\\\.0\\\\.1|localhost|0\\\\.0\\\\.0\\\\.0|10\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|172\\\\.(?:1[6-9]|2[0-9]|3[01])\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|192\\\\.168\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|169\\\\.254\\\\.[0-9]{1,3}\\\\.[0-9]{1,3}|\\\\[::1\\\\]|\\\\[fd[0-9a-f]{2}:))~i"}], "cve": "CVE-2026-84761", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84761", "description": "LiteSpeed Cache <=7.9 unauthenticated SSRF via err_domains REST callback main_domain/alias parameters (is_from_cloud IP check bypass)", "mode": "block", "severity": 7.2, "slug": "litespeed-cache", "tags": ["ssrf", "unauthenticated", "rest-api", "missing-authorization"], "target": "plugin", "versions": "<=7.9"}, "RULE-CVE-2026-84763-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:installed_template", "type": "regex", "value": "~(?:(?:javascript|data|vbscript)\\\\s*:|<\\\\/?script[\\\\s>/]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=)~i"}], "cve": "CVE-2026-84763", "description": "RTMKit (rometheme-for-elementor) <=2.1.5 unauthenticated reflected XSS via installed_template parameter on admin template view", "mode": "block", "slug": "rometheme-for-elementor", "target": "plugin", "versions": "<=2.1.5"}, "RULE-CVE-2026-84774-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~i"}, {"name": "ARGS:utm_campaign", "type": "regex", "value": "~(?:<(?:script|img|svg|iframe|body|input)[\\\\s/>]|on(?:error|load|click|mouseover|focus|blur|mouseenter)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-84774", "description": "WP Statistics <=14.16.11 unauthenticated reflected XSS via utm_campaign parameter rendered in admin report/metabox campaign tooltip", "mode": "block", "slug": "wp-statistics", "target": "plugin", "versions": "<=14.16.11"}, "RULE-CVE-2026-84813-01": {"action": "init", "conditions": [{"name": "ARGS:email", "type": "regex", "value": "~(?:UNION(?:/\\\\*.*?\\\\*/|\\\\s)+(?:ALL(?:/\\\\*.*?\\\\*/|\\\\s)+)?SELECT|\'\\\\s*(?:OR|AND|UNION)\\\\b|(?:OR|AND)(?:/\\\\*.*?\\\\*/|\\\\s)+[0-9]+\\\\s*=\\\\s*[0-9]+|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s)~i"}], "cve": "CVE-2026-84813", "description": "GeoDirectory <=2.8.174 unauthenticated SQL injection via POST email parameter in comment review-count filter", "mode": "block", "severity": 9.3, "slug": "geodirectory", "target": "plugin", "versions": "<=2.8.174"}, "RULE-CVE-2026-84820-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~i"}, {"name": "ARGS:action", "type": "equals", "value": "view"}, {"name": "ARGS:page", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-84820", "description": "Unlimited Elements For Elementor <2.0.18 unauthenticated-delivery reflected XSS via page parameter in form entry admin footer view", "mode": "block", "slug": "unlimited-elements-for-elementor", "target": "plugin", "versions": "<2.0.18"}, "RULE-CVE-2026-84829-01": {"ajax_action": "optml_fetch_logs", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-84829", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-84829", "description": "Optimole <4.2.12 authenticated information disclosure via optml_fetch_logs AJAX handler missing capability check (deterministically evidenced authorization gap; documented unauthenticated srcset-attribute XSS path remains unlocalized in available artefacts)", "mode": "block", "severity": 8.8, "slug": "optimole-wp", "tags": ["missing-authorization", "information-disclosure", "authenticated"], "target": "plugin", "versions": "<4.2.12"}, "RULE-CVE-2026-84909-01": {"action": "init", "conditions": [{"name": "ARGS:content", "type": "regex", "value": "~\\\\[custom-twitter-feeds\\\\b[^\\\\]]{0,500}?(?:buttoncolor|buttontextcolor|buttontext)\\\\s*=\\\\s*([\'\\"])(?:(?!\\\\1).){0,200}?(?:on\\\\w+\\\\s*=|]|javascript\\\\s*:)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-8494", "description": "Permalink Manager Lite <=2.5.3.3 stored XSS via post title injection through wp-admin/post.php", "mode": "block", "severity": 6.4, "slug": "permalink-manager", "target": "plugin", "versions": "<=2.5.3.3"}, "RULE-CVE-2026-8494-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:title", "type": "regex", "value": "~(?:on(?:focus|blur|click|mouse(?:over|out|enter)|load|error|animat(?:ion(?:end|start|iteration)|ioncancel)|key(?:down|up|press)|change|input|submit|reset|drag(?:start|end|over)?|drop|(?:before)?copy|cut|paste|contextmenu|wheel|scroll|resize|select|toggle|transitionend)\\\\s*=|<\\\\s*(?:script|iframe|embed|object|svg|img|details|marquee|math|video|audio|body|form|isindex|meta|link|style|base|applet|layer|ilayer|bgsound)[\\\\s/>]|javascript\\\\s*:)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-8494", "description": "Permalink Manager Lite <=2.5.3.3 stored XSS via post title injection through REST API /wp/v2/posts", "mode": "block", "severity": 6.4, "slug": "permalink-manager", "target": "plugin", "versions": "<=2.5.3.3"}, "RULE-CVE-2026-85017-01": {"ajax_action": "unitecreator_elementor_import_template", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-85017", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85017", "description": "Unlimited Elements For Elementor <2.0.20 missing capability check on unitecreator_elementor_import_template AJAX action allows subscriber+ PHP object injection via deserialized template data", "mode": "block", "severity": 7.5, "slug": "unlimited-elements-for-elementor", "tags": ["missing-authorization", "object-injection", "deserialization", "authenticated"], "target": "plugin", "versions": "<2.0.20"}, "RULE-CVE-2026-85116-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^(?!/wp-admin/|/wp-login\\\\.php|/wp-cron\\\\.php|/xmlrpc\\\\.php).*$~i"}, {"name": "ARGS", "type": "regex", "value": "~\\\\[[a-zA-Z_][a-zA-Z0-9_-]*\\\\s+[a-zA-Z_][a-zA-Z0-9_-]*\\\\s*=\\\\s*[\\"\'][^\\"\'\\\\]]*[\\"\'][^\\\\]]*\\\\]~"}], "cve": "CVE-2026-85116", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85116", "description": "Simple CAPTCHA with Cloudflare Turnstile >=1.2.2 <1.42.3 unauthenticated arbitrary shortcode execution via do_shortcode() over rendered Contact Form 7 content", "mode": "block", "severity": 6.5, "slug": "simple-cloudflare-turnstile", "tags": ["shortcode-injection", "unauthenticated", "injection"], "target": "plugin", "versions": ">=1.2.2 <1.42.3"}, "RULE-CVE-2026-85130-01": {"ajax_action": "gdpr_log_consent_action", "conditions": [{"name": "ARGS:/subSiteId|currentSite|gdpr_user_action|cookie_list|consent_forward/", "type": "regex", "value": "~(?:]|<]*(?:]*>|on[a-zA-Z]+\\\\s*=|javascript\\\\s*:|&(?:lt|#x3c|#60);)~i"}], "cve": "CVE-2026-85414", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85414", "description": "FooGallery <=3.3.2 contributor+ stored XSS via custom_settings shortcode attribute in post content", "mode": "block", "severity": 6.4, "slug": "foogallery", "tags": ["xss", "stored", "shortcode", "authenticated"], "target": "plugin", "versions": "<=3.3.2"}, "RULE-CVE-2026-85530-01": {"ajax_action": "give_confirm_email_for_donations_access", "conditions": [{"name": "ARGS:email", "type": "regex", "value": "~(?:<[^>]*>|[\\\\x00-\\\\x1F]|[ ]{2,})~"}], "cve": "CVE-2026-85530", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85530", "description": "GiveWP <4.16.8.1 unauthenticated donor identity resolution mismatch via anomalous email parameter in give_confirm_email_for_donations_access enabling account takeover", "mode": "block", "severity": 8.1, "slug": "give", "tags": ["privilege-escalation", "unauthenticated", "improper-authorization", "account-takeover"], "target": "plugin", "versions": "<4.16.8.1"}, "RULE-CVE-2026-85574-01": {"action": "admin_post_set_unbounce_domains", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-85574", "description": "Unbounce Landing Pages >=1.1.1 <1.1.5 missing authorization on set_unbounce_domains allows subscriber+ reverse-proxy target hijack", "mode": "block", "slug": "unbounce", "target": "plugin", "versions": ">=1.1.1 <1.1.5"}, "RULE-CVE-2026-85574-02": {"action": "admin_post_flush_unbounce_pages", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-85574", "description": "Unbounce Landing Pages >=1.1.1 <1.1.5 missing authorization on flush_unbounce_pages allows subscriber+ unauthorized cache state change", "mode": "block", "slug": "unbounce", "target": "plugin", "versions": ">=1.1.1 <1.1.5"}, "RULE-CVE-2026-85652-01": {"action": "init", "conditions": [{"name": "ARGS:content", "type": "regex", "value": "~album_id\\\\s*=\\\\s*(?:\\"|"|\')[^\\"\'\\\\]]*?(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\b|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|/\\\\*.*?\\\\*/|--\\\\s|#)~i"}], "cve": "CVE-2026-85652", "description": "Photo Gallery by 10Web <=1.8.44 author+ stored time-based SQL injection via album_id shortcode attribute", "mode": "block", "slug": "photo-gallery", "target": "plugin", "versions": "<=1.8.44"}, "RULE-CVE-2026-85658-01": {"ajax_action": "pp_ajax_editprofile", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\[[a-zA-Z][a-zA-Z0-9_-]{1,30}(?:\\\\s+[a-zA-Z_][a-zA-Z0-9_-]*\\\\s*=\\\\s*(?:\\"[^\\"]*\\"|\'[^\']*\'))+\\\\s*/?\\\\]~i"}], "cve": "CVE-2026-85658", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-85658", "description": "ProfilePress (wp-user-avatar) <=4.17.2 authenticated (subscriber+) arbitrary shortcode execution via pp_ajax_editprofile AJAX action", "mode": "block", "severity": 8.1, "slug": "wp-user-avatar", "tags": ["code-injection", "shortcode-execution", "authenticated"], "target": "plugin", "versions": "<=4.17.2"}, "RULE-CVE-2026-85680-01": {"action": "um_submit_form_profile", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|[\\"\']\\\\s*>\\\\s*<|[\\"\']\\\\s*\\\\)\\\\s*;)~i"}], "cve": "CVE-2026-86311", "description": "Photo Gallery by 10Web <=1.8.44 Author+ stored XSS via shortcode attribute values submitted to the shortcode_bwg AJAX handler", "mode": "block", "slug": "photo-gallery", "target": "plugin", "versions": "<=1.8.44"}, "RULE-CVE-2026-86406-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "regex", "value": "~^user_registration_membership_~i"}, {"name": "ARGS:current_membership_id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-86406", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86406", "description": "User Registration & Membership >=4.4.6 <5.2.8 privilege escalation via unauthorized membership purchase AJAX family lacking capability and payment/plan validation", "mode": "block", "severity": 7.5, "slug": "user-registration", "tags": ["privilege-escalation", "missing-authorization", "authenticated"], "target": "plugin", "versions": ">=4.4.6 <5.2.8"}, "RULE-CVE-2026-86444-01": {"action": "init", "conditions": [{"name": "ARGS:lp-order-received", "type": "exists"}, {"name": "ARGS:key", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|[\\"\'<>])~i"}], "cve": "CVE-2026-86444", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86444", "description": "LearnPress <4.4.7 unauthenticated reflected XSS via key parameter on public order-received page", "mode": "block", "severity": 7.1, "slug": "learnpress", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<4.4.7"}, "RULE-CVE-2026-86583-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/profile\\\\.php~i"}, {"name": "ARGS:action", "type": "equals", "value": "update"}, {"name": "ARGS:/display_name|nickname/", "type": "regex", "value": "~\\\\\\\\+$~"}], "cve": "CVE-2026-86583", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86583", "description": "Import and export users and customers <=2.4.17 privilege escalation via CSV escape-character desync in display_name/nickname profile fields", "mode": "block", "severity": 8.8, "slug": "import-users-from-csv-with-meta", "tags": ["privilege-escalation", "csv-injection", "authenticated"], "target": "plugin", "versions": "<=2.4.17"}, "RULE-CVE-2026-8705-01": {"ajax_action": "clearsale_total_push", "conditions": [{"name": "ARGS:pagseguro[metodo]", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|\\\\bAND\\\\s+(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML|IF)\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|SELECT)\\\\s|\\\\bOR\\\\s+[0-9]+\\\\s*=\\\\s*[0-9]+|/\\\\*[^*]*\\\\*/|\\\\bAND\\\\s+\\\\(\\\\s*SELECT\\\\b)~i"}], "cve": "CVE-2026-8705", "description": "ClearSale Total <=3.4.2 unauthenticated SQL injection via pagseguro[metodo] in clearsale_total_push AJAX handler", "mode": "block", "severity": 7.5, "slug": "clearsale-total", "target": "plugin", "versions": "<=3.4.2"}, "RULE-CVE-2026-87067-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/xmlrpc\\\\.php~i"}, {"name": "ARGS", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]+\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-87067", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-87067", "description": "Forminator Forms <1.57.2.1 authenticated PHP object injection via unrestricted class instantiation during XML-RPC request deserialization", "mode": "block", "severity": 8.5, "slug": "forminator", "tags": ["object-injection", "deserialization", "xmlrpc", "remote-code-execution"], "target": "plugin", "versions": "<1.57.2.1"}, "RULE-CVE-2026-87068-01": {"ajax_action": "forminator_save_import_quiz_popup", "conditions": [{"name": "ARGS:importable", "type": "regex", "value": "~\\"(?:user_role|default_role|assigned_role|new_user_role|role)\\"\\\\s*:\\\\s*\\"(?:administrator|editor|author|shop_manager)\\"~i"}], "cve": "CVE-2026-87068", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-87068", "description": "Forminator Forms >=1.57.0 <1.57.2.1 authenticated privilege escalation via unvalidated registration role in imported quiz (forminator_save_import_quiz_popup)", "mode": "block", "severity": 8.8, "slug": "forminator", "tags": ["privilege-escalation", "authenticated", "role-manipulation"], "target": "plugin", "versions": ">=1.57.0 <1.57.2.1"}, "RULE-CVE-2026-8719-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mwai/v1/tools(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-8719", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-8719", "description": "AI Engine <=3.4.9 unauthorized MCP tool enumeration via REST API allows low-privilege users to list admin-level tools", "mode": "block", "severity": 8.8, "slug": "ai-engine", "tags": ["missing-authorization", "information-disclosure", "rest-api"], "target": "plugin", "versions": "<=3.4.9"}, "RULE-CVE-2026-8719-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mcp-oauth(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-8719", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-8719", "description": "AI Engine <=3.4.9 unauthorized MCP OAuth authorization allows non-admin users to authorize MCP applications", "mode": "block", "severity": 8.8, "slug": "ai-engine", "tags": ["missing-authorization", "privilege-escalation", "rest-api"], "target": "plugin", "versions": "<=3.4.9"}, "RULE-CVE-2026-8761-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/dokan/v1/customers[\\\\\\\\/]*(?:[?&]|$)~i"}, {"type": "missing_capability", "value": "manage_woocommerce"}], "cve": "CVE-2026-8761", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-8761", "description": "Dokan (dokan-lite) <=5.0.1 privilege escalation via vendor-only permission check on re-registered dokan/v1/customers REST route", "mode": "block", "severity": 8.8, "slug": "dokan-lite", "tags": ["missing-authorization", "privilege-escalation", "idor", "rest-api"], "target": "plugin", "versions": "<=5.0.1"}, "RULE-CVE-2026-8761-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/dokan/v1/customers[\\\\\\\\/]*$~i"}, {"type": "missing_capability", "value": "manage_woocommerce"}], "cve": "CVE-2026-8761", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-8761", "description": "Dokan (dokan-lite) <=5.0.1 privilege escalation via vendor-only permission check on re-registered dokan/v1/customers REST route", "mode": "block", "severity": 8.8, "slug": "dokan-lite", "tags": ["missing-authorization", "privilege-escalation", "idor", "rest-api"], "target": "plugin", "versions": "<=5.0.1"}, "RULE-CVE-2026-87902-01": {"action": "init", "conditions": [{"name": "ARGS:pagename", "type": "regex", "value": "~(?:\\\\.|%2e|%252e){2}(?:/|\\\\\\\\|%2f|%5c|%252f|%255c)~i"}], "cve": "CVE-2026-87902", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp", "description": "Unauthenticated path traversal in WordPress core page-template resolution leading to conditional local file inclusion / RCE (GHSA-7hp8-65ch-5whp, CVSS 9.2). get_page_template() in wp-includes/template.php urldecodes the pagename query var and, when the decoded value differs from the raw value, appends the candidate template page-{pagename_decoded}.php WITHOUT calling validate_file(); locate_template() then resolves that name against the active theme directory and includes it, so a decoded value carrying ../ climbs out of the theme. When the active theme has a top-level directory whose name starts with page- (e.g. page-templates in Twenty Twelve/Fourteen, Neve, Hestia, Sydney) the page- prefix and the trailing .php are consumed by the traversal, allowing inclusion of any readable local .php (pearcmd.php gives RCE where register_argc_argv=On). Reaching the branch requires the query var to still contain a percent sign after WordPress\' own decode, so the traversal is double URL-encoded on the wire. Fixed across all branches at 7.1.2 / 7.0.6 / 6.9.9 / 6.8.10 / ... / 4.7.37 by guarding the decoded branch with validate_file() and constraining locate_template() to the theme directories. This rule matches encoded or literal directory traversal in the pagename argument.", "mode": "block", "severity": 9.2, "tags": ["path-traversal", "lfi", "rce", "wp-core", "unauthenticated"], "target": "core", "versions": ">=4.7.0 <7.1.2"}, "RULE-CVE-2026-87902-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[?&]pagename=[^&#]*(?:\\\\.\\\\.[\\\\\\\\/]|%2e%2e(?:%2f|%5c))~i"}], "cve": "CVE-2026-87902", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp", "description": "Unauthenticated path traversal in WordPress core page-template resolution leading to conditional local file inclusion / RCE (GHSA-7hp8-65ch-5whp, CVSS 9.2). get_page_template() in wp-includes/template.php urldecodes the pagename query var and, when the decoded value differs from the raw value, appends the candidate template page-{pagename_decoded}.php WITHOUT calling validate_file(); locate_template() then resolves that name against the active theme directory and includes it, so a decoded value carrying ../ climbs out of the theme. When the active theme has a top-level directory whose name starts with page- (e.g. page-templates in Twenty Twelve/Fourteen, Neve, Hestia, Sydney) the page- prefix and the trailing .php are consumed by the traversal, allowing inclusion of any readable local .php (pearcmd.php gives RCE where register_argc_argv=On). Reaching the branch requires the query var to still contain a percent sign after WordPress\' own decode, so the traversal is double URL-encoded on the wire. Fixed across all branches at 7.1.2 / 7.0.6 / 6.9.9 / 6.8.10 / ... / 4.7.37 by guarding the decoded branch with validate_file() and constraining locate_template() to the theme directories. Defence-in-depth carrier: the engine double-decodes REQUEST_URI, so the fully decoded ../ traversal in the pagename carrier is visible even when the argument-level view is still single-encoded. This rule matches a decoded directory-traversal sequence in the pagename request carrier.", "mode": "block", "severity": 9.2, "tags": ["path-traversal", "lfi", "rce", "wp-core", "unauthenticated"], "target": "core", "versions": ">=4.7.0 <7.1.2"}, "RULE-CVE-2026-87915-01": {"ajax_action": "pum_sub_form", "conditions": [{"name": "ARGS:values[/.+/]", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur|mouseenter|mouseout)\\\\s*=|javascript\\\\s*:|&#(?:0*106|x0*6a);?)~i"}], "cve": "CVE-2026-87915", "description": "Popup Maker <=1.24.0 unauthenticated stored XSS via values[] array parameter in pum_sub_form AJAX handler", "mode": "block", "slug": "popup-maker", "target": "plugin", "versions": "<=1.24.0"}, "RULE-CVE-2026-87917-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/mc4wp/v1/form[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS", "type": "regex", "value": "~\\\\b(?:javascript|vbscript|data)\\\\s*:~i"}], "cve": "CVE-2026-87917", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-87917", "description": "MC4WP Mailchimp for WordPress <=4.14.0 unauthenticated reflected XSS via disallowed URL protocol in \'data\' dynamic content tag rendered by the public /mc4wp/v1/form REST endpoint", "mode": "block", "severity": 6.1, "slug": "mailchimp-for-wp", "tags": ["xss", "reflected", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=4.14.0"}, "RULE-CVE-2026-87917-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/mc4wp/v1/form[\\\\\\\\/]*$~i"}, {"name": "ARGS", "type": "regex", "value": "~\\\\b(?:javascript|vbscript|data)\\\\s*:~i"}], "cve": "CVE-2026-87917", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-87917", "description": "MC4WP Mailchimp for WordPress <=4.14.0 unauthenticated reflected XSS via disallowed URL protocol in \'data\' dynamic content tag rendered by the public /mc4wp/v1/form REST endpoint", "mode": "block", "severity": 6.1, "slug": "mailchimp-for-wp", "tags": ["xss", "reflected", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=4.14.0"}, "RULE-CVE-2026-8809-01": {"action": "init", "conditions": [{"name": "ARGS:_acf_post_id", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~^administrator$~i"}], "cve": "CVE-2026-8809", "description": "ACF Extended <=0.9.2.5 unauthenticated privilege escalation via validation bypass in frontend form _acf_post_id parameter", "mode": "block", "severity": 9.8, "slug": "acf-extended", "target": "plugin", "versions": "<=0.9.2.5"}, "RULE-CVE-2026-8848-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/pum/v1/connect/install(?:[/?]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-8848", "description": "Popup Maker <=1.22.0 missing authorization on REST connect/install endpoint allows editor-level users to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution", "mode": "block", "severity": 7.2, "slug": "popup-maker", "target": "plugin", "versions": "<=1.22.0"}, "RULE-CVE-2026-8848-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/pum/v1/connect/info(?:[/?]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-8848", "description": "Popup Maker <=1.22.0 missing authorization on legacy REST connect/info endpoint allows editor-level users to obtain the bearer token later used to satisfy the install endpoint\'s only non-spoofable validation check", "mode": "block", "severity": 7.2, "slug": "popup-maker", "target": "plugin", "versions": "<=1.22.0"}, "RULE-CVE-2026-8901-01": {"ajax_action": "integrazo_fwcrm_form_errorlog_show_action", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-8901", "description": "Integration for Freshsales <=1.0.15 stored XSS via error log - missing capability check on errorlog_show_action allows subscriber+ to trigger stored XSS payloads", "mode": "block", "severity": 7.2, "slug": "crm-integration-freshworks-any-form", "target": "plugin", "versions": "<=1.0.15"}, "RULE-CVE-2026-89064-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_HEADERS:Authorization", "type": "regex", "value": "~^Basic\\\\s+~i"}, {"name": "", "type": "missing_capability", "value": "ai1wm_export_site"}, {"name": "", "type": "missing_capability", "value": "ai1wm_import_site"}], "cve": "CVE-2026-89064", "description": "All-in-One WP Migration and Backup <=7.110 unauthenticated HTTP Basic credential harvesting via unguarded admin_init credential capture in Ai1wm_Main_Controller::init()", "mode": "block", "severity": 5.3, "slug": "all-in-one-wp-migration", "target": "plugin", "versions": "<=7.110"}, "RULE-CVE-2026-89080-01": {"ajax_action": "change_method_to_email", "conditions": [{"name": "ARGS:user_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2026-89080", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-89080", "description": "Really Simple Security <9.8.1 missing authorization on change_method_to_email AJAX handler allows resetting another user\'s completed 2FA enrolment via user_id parameter", "mode": "block", "severity": 7.5, "slug": "really-simple-ssl", "tags": ["authentication-bypass", "missing-authorization", "two-factor-authentication", "idor"], "target": "plugin", "versions": "<9.8.1"}, "RULE-CVE-2026-89080-02": {"ajax_action": "resend_email_code_profile", "conditions": [{"name": "ARGS:user_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2026-89080", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-89080", "description": "Really Simple Security <9.8.1 missing authorization on resend_email_code_profile AJAX handler allows resetting another user\'s completed 2FA enrolment via user_id parameter", "mode": "block", "severity": 7.5, "slug": "really-simple-ssl", "tags": ["authentication-bypass", "missing-authorization", "two-factor-authentication", "idor"], "target": "plugin", "versions": "<9.8.1"}, "RULE-CVE-2026-8912-01": {"ajax_action": "post_cg_gallery_form_upload", "conditions": [{"name": "ARGS:form_input", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\b\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|/\\\\*.*\\\\*/|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-8912", "description": "Contest Gallery <=28.1.6 unauthenticated SQL injection via form_input parameter in post_cg_gallery_form_upload", "mode": "block", "severity": 7.5, "slug": "contest-gallery", "target": "plugin", "versions": "<=28.1.6"}, "RULE-CVE-2026-89141-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/mwai/v1/simpleTranscribeAudio[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:mediaId", "type": "exists"}, {"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-89141", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-89141", "description": "AI Engine <=3.7.7 IDOR via mediaId parameter on simpleTranscribeAudio REST endpoint allows subscriber-level access to other users\' private audio transcriptions", "mode": "block", "severity": 6.5, "slug": "ai-engine", "tags": ["idor", "broken-access-control", "rest-api", "authenticated"], "target": "plugin", "versions": "<=3.7.7"}, "RULE-CVE-2026-89141-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/mwai/v1/simpleTranscribeAudio[\\\\\\\\/]*$~i"}, {"name": "ARGS:mediaId", "type": "exists"}, {"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-89141", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-89141", "description": "AI Engine <=3.7.7 IDOR via mediaId parameter on simpleTranscribeAudio REST endpoint allows subscriber-level access to other users\' private audio transcriptions", "mode": "block", "severity": 6.5, "slug": "ai-engine", "tags": ["idor", "broken-access-control", "rest-api", "authenticated"], "target": "plugin", "versions": "<=3.7.7"}, "RULE-CVE-2026-89274-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-comments-post\\\\.php~"}, {"name": "ARGS:comment", "type": "regex", "value": "~\\\\[/?[a-zA-Z_][\\\\w-]*(?:\\\\s+[a-zA-Z_][\\\\w-]*\\\\s*=\\\\s*(?:\\"[^\\"]{0,200}\\"|\'[^\']{0,200}\'))+\\\\s*/?\\\\]|\\\\[[a-zA-Z_][\\\\w-]*\\\\s*/\\\\]|\\\\[/[a-zA-Z_][\\\\w-]*\\\\]~i"}], "cve": "CVE-2026-89274", "description": "WP Recipe Maker <=10.8.1 unauthenticated arbitrary shortcode execution via comment_post comment field consumed as reviewBody metadata", "mode": "block", "slug": "wp-recipe-maker", "target": "plugin", "versions": "<=10.8.1"}, "RULE-CVE-2026-89333-01": {"action": "init", "conditions": [{"name": "ARGS:student_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2026-89333", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-89333", "description": "Tutor LMS <=4.0.8 authenticated IDOR via student_id parameter discloses arbitrary users\' email and phone", "mode": "block", "severity": 6.5, "slug": "tutor", "tags": ["idor", "broken-access-control", "information-disclosure", "authenticated"], "target": "plugin", "versions": "<=4.0.8"}, "RULE-CVE-2026-89406-01": {"action": "init", "conditions": [{"name": "ARGS:modula_gallery_id", "type": "exists"}, {"name": "ARGS:modula_image_id", "type": "exists"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-89406", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-89406", "description": "Modula Image Gallery <=3.0.1 unauthenticated disclosure of private gallery/image metadata via modula_gallery_id and modula_image_id GET parameters read on wp_head", "mode": "pass", "severity": 7.5, "slug": "modula-best-grid-gallery", "tags": ["missing-authorization", "information-disclosure", "idor", "unauthenticated"], "target": "plugin", "versions": "<=3.0.1"}, "RULE-CVE-2026-89412-01": {"ajax_action": "trp_get_translations_domchanges", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|<\\\\s*script|�*60;\\\\s*script|�*3c;\\\\s*script|on(?:load|error|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-89412", "description": "TranslatePress <=3.3.5 unauthenticated stored XSS via trp_get_translations_domchanges seeding of Translation Memory original strings later rendered via v-html", "mode": "block", "slug": "translatepress-multilingual", "target": "plugin", "versions": "<=3.3.5"}, "RULE-CVE-2026-900001-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/popup-anything-on-click/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support / Essential Plugin supply chain attack: unauthenticated RCE via wpos-analytics REST endpoint. Compromised analytics.essentialplugin.com returns malicious serialized PHP object through unserialize() in class-anylc-admin.php, leading to arbitrary file_put_contents (dropper: wp-comments-posts.php, wp-config.php injection). Shared SDK affects 22 plugins (~200k installs). No CVE assigned; tracked as CAMPAIGN-WPOS-SUPPLY-CHAIN.", "method": "POST", "mode": "block", "severity": 10.0, "slug": "popup-anything-on-click", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "ssrf", "backdoor", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-logo-showcase-responsive-slider/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Logo Showcase plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-logo-showcase-responsive-slider-slider", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/countdown-timer-ultimate/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Countdown Timer Ultimate plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "countdown-timer-ultimate", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wprps-post-slider/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Responsive Recent Post Slider plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-responsive-recent-post-slider", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-05": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-news-and-scrolling-widgets/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in SP News and Widget plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "sp-news-and-widget", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-06": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-slick-slider-and-image-carousel/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Slick Slider plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-slick-slider-and-image-carousel", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-07": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/album-and-image-gallery-plus-lightbox/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Album and Image Gallery plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "album-and-image-gallery-plus-lightbox", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-08": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-testimonials-with-rotator-widget/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Testimonial with Widget plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-testimonial-with-widget", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-09": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-blog-and-widget/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Blog and Widgets plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-blog-and-widgets", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-10": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/blog-designer-post-and-widget/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Blog Designer for Post and Widget plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "blog-designer-for-post-and-widget", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-11": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/meta-slider-and-carousel-with-lightbox/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Meta Slider and Carousel plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "meta-slider-and-carousel-with-lightbox", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-12": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/post-grid-and-filter-ultimate/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Post Grid and Filter Ultimate plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "post-grid-and-filter-ultimate", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-13": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/timeline-and-history-slider/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Timeline and History Slider plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "timeline-and-history-slider", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-14": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-responsive-faq-with-category-plugin/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in SP FAQ plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "sp-faq", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-15": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-team-showcase-and-slider/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Team Showcase plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-team-showcase-and-slider", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-17": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-trending-post-slider-and-widget/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Trending Post Slider plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-trending-post-slider-and-widget", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-18": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/featured-post-creative/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Featured Post Creative plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "featured-post-creative", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-19": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/portfolio-and-projects/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Portfolio and Projects plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "portfolio-and-projects", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-20": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/ticker-ultimate/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in Ticker Ultimate plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "ticker-ultimate", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-21": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/video-gallery-and-player/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in HTML5 Video Gallery plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "html5-videogallery-plus-player", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-900001-22": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-featured-content-and-slider/v1/analytics(?:[/?]|$)~"}], "cve": "CAMPAIGN-WPOS-SUPPLY-CHAIN", "description": "WP Online Support supply chain \\u2014 unauthenticated RCE via wpos-analytics REST endpoint in WP Featured Content and Slider plugin", "method": "POST", "mode": "block", "severity": 10.0, "slug": "wp-featured-content-and-slider", "tags": ["supply-chain", "unauthenticated", "rce", "deserialization", "rest-api"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2026-91011-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~]+class=[\\"\'][^\\"\']*(?:\\\\$\\\\{?[0-9]|\\\\\\\\[0-9])[^\\"\']*[\\"\']~i"}], "cve": "CVE-2026-91011", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-91011", "description": "EWWW Image Optimizer <8.7.7 Author+ stored XSS via unescaped preg_replace backreference in image class attribute during ExactDN page rewrite", "mode": "block", "severity": 6.8, "slug": "ewww-image-optimizer", "tags": ["xss", "stored", "authenticated", "preg-replace-injection"], "target": "plugin", "versions": "<8.7.7"}, "RULE-CVE-2026-9109-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/gptranslate/v1/request(?:/|\\\\?|$)~"}, {"name": "ARGS", "type": "regex", "value": "~]|on(?:error|load|toggle|mouseover|focus|click|change)\\\\s*=|javascript\\\\s*:|]|]|]+\\\\bon[a-z]~i"}], "cve": "CVE-2026-9109", "description": "GPTranslate <=2.31 unauthenticated stored XSS via REST API translation storage", "mode": "block", "severity": 7.2, "slug": "gptranslate", "target": "plugin", "versions": "<=2.31"}, "RULE-CVE-2026-9125-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~presto_player_overlay[^\\\\]]*link_url\\\\s*=\\\\s*[\\"\']?\\\\s*(?:j[\\\\s]*a[\\\\s]*v[\\\\s]*a[\\\\s]*s[\\\\s]*c[\\\\s]*r[\\\\s]*i[\\\\s]*p[\\\\s]*t[\\\\s]*:|&#[xX]?0*(?:6[Aa]|106);?|data[\\\\s]*:(?![\\\\s]*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-9125", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-9125", "description": "Presto Player <=4.2.0 contributor+ stored XSS via javascript: URI in presto_player_overlay shortcode link_url attribute (classic editor)", "mode": "block", "severity": 6.4, "slug": "presto-player", "tags": ["xss", "stored", "shortcode", "authenticated"], "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2026-9125-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~presto_player_overlay[^\\\\]]*link_url\\\\s*=\\\\s*[\\"\']?\\\\s*(?:j[\\\\s]*a[\\\\s]*v[\\\\s]*a[\\\\s]*s[\\\\s]*c[\\\\s]*r[\\\\s]*i[\\\\s]*p[\\\\s]*t[\\\\s]*:|&#[xX]?0*(?:6[Aa]|106);?|data[\\\\s]*:(?![\\\\s]*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-9125", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-9125", "description": "Presto Player <=4.2.0 contributor+ stored XSS via javascript: URI in presto_player_overlay shortcode link_url attribute (REST API)", "mode": "block", "severity": 6.4, "slug": "presto-player", "tags": ["xss", "stored", "shortcode", "authenticated", "rest-api"], "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2026-9134-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[foogallery[^\\\\]]*custom_attribute_key\\\\s*=\\\\s*[\\"\']?on[a-z]+~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-9134", "description": "FooGallery <=3.1.31 stored XSS via custom_attribute_key shortcode parameter through post editor", "mode": "block", "severity": 6.4, "slug": "foogallery", "target": "plugin", "versions": "<=3.1.31"}, "RULE-CVE-2026-9134-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages)(?:/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[foogallery[^\\\\]]*custom_attribute_key\\\\s*=\\\\s*[\\"\']?on[a-z]+~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-9134", "description": "FooGallery <=3.1.31 stored XSS via custom_attribute_key shortcode parameter through REST API", "mode": "block", "severity": 6.4, "slug": "foogallery", "target": "plugin", "versions": "<=3.1.31"}, "RULE-CVE-2026-9178-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v3/user/list/[0-9]+(?:/|\\\\?|$)~"}, {"name": "REQUEST_HEADERS:Username", "type": "exists"}], "cve": "CVE-2026-9178", "description": "WP Forms Connector <=1.8 unauthenticated sensitive user data exposure via wp/v3/user/list REST endpoint", "mode": "block", "severity": 7.5, "slug": "wp-forms-connector", "target": "plugin", "versions": "<=1.8"}, "RULE-CVE-2026-9179-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v3/post/list(?:[/?&]|$)~"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|\\\\bCASE\\\\s+WHEN\\\\b|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bEXTRACTVALUE\\\\s*\\\\(|\\\\bUPDATEXML\\\\s*\\\\(|\\\\(\\\\s*SELECT\\\\b|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|--\\\\s|/\\\\*|#)~i"}], "cve": "CVE-2026-9179", "description": "WP Forms Connector <=1.8 unauthenticated SQL injection via order parameter in /wp-json/wp/v3/post/list REST endpoint", "mode": "block", "severity": 7.5, "slug": "wp-forms-connector", "target": "plugin", "versions": "<=1.8"}, "RULE-CVE-2026-92229-01": {"ajax_action": "forminator_load_quiz", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:[\\"\']\\\\s*\\\\]\\\\s*\\\\[|[0-9]\\\\]\\\\[)\\\\s*[a-zA-Z_][\\\\w-]*~i"}], "cve": "CVE-2026-92229", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-92229", "description": "Forminator <=1.57.2 unauthenticated arbitrary shortcode execution via forminator_load_quiz AJAX handler", "mode": "block", "severity": 9.1, "slug": "forminator", "tags": ["code-injection", "shortcode-injection", "unauthenticated"], "target": "plugin", "versions": "<=1.57.2"}, "RULE-CVE-2026-92229-02": {"ajax_action": "forminator_reload_quiz", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:[\\"\']\\\\s*\\\\]\\\\s*\\\\[|[0-9]\\\\]\\\\[)\\\\s*[a-zA-Z_][\\\\w-]*~i"}], "cve": "CVE-2026-92229", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-92229", "description": "Forminator <=1.57.2 unauthenticated arbitrary shortcode execution via forminator_reload_quiz AJAX handler", "mode": "block", "severity": 9.1, "slug": "forminator", "tags": ["code-injection", "shortcode-injection", "unauthenticated"], "target": "plugin", "versions": "<=1.57.2"}, "RULE-CVE-2026-92249-01": {"action": "init", "conditions": [{"name": "ARGS:s", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]|]+onerror)~i"}], "cve": "CVE-2026-92249", "description": "Qi Addons For Elementor <=1.11 unauthenticated reflected XSS via \'s\' search parameter reflected by Table of Contents widget heading scan on search results pages", "mode": "block", "slug": "qi-addons-for-elementor", "target": "plugin", "versions": "<=1.11"}, "RULE-CVE-2026-9243-01": {"ajax_action": "elementor_ajax", "conditions": [{"name": "ARGS", "type": "regex", "value": "~carousel_direction[^}]*(?:on(?:focus|blur|mouse(?:over|enter|move|out)|click|dblclick|key(?:down|up|press)|load|error|focusin|focusout|pointerover|touchstart|animationend)\\\\s*=|style\\\\s*=\\\\s*[^\\"]*(?:position|expression))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-9243", "description": "The Plus Addons for Elementor <=6.4.15 contributor+ stored XSS via carousel_direction unquoted attribute injection", "mode": "block", "severity": 6.4, "slug": "the-plus-addons-for-elementor-page-builder", "target": "plugin", "versions": "<=6.4.15"}, "RULE-CVE-2026-92540-01": {"ajax_action": "acui_import_users_batch", "conditions": [{"name": "ARGS:form[caller_can_promote_users]", "type": "regex", "value": "~^(?:1|true|on)$~i"}, {"type": "missing_capability", "value": "promote_users"}], "cve": "CVE-2026-92540", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-92540", "description": "Import and export users and customers <2.5.2 privilege escalation to administrator via caller_can_promote_users in acui_import_users_batch AJAX handler", "mode": "block", "severity": 7.2, "slug": "import-users-from-csv-with-meta", "tags": ["privilege-escalation", "missing-authorization", "csv-import"], "target": "plugin", "versions": ">=2.4.16 <2.5.2"}, "RULE-CVE-2026-92541-01": {"ajax_action": "acui_import_users_batch", "conditions": [{"type": "missing_capability", "value": "promote_users"}], "cve": "CVE-2026-92541", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-92541", "description": "Import and export users and customers <2.5.2 authenticated create_users role privilege escalation via acui_import_users_batch missing promote_users check", "mode": "block", "severity": 7.2, "slug": "import-users-from-csv-with-meta", "tags": ["privilege-escalation", "missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<2.5.2"}, "RULE-CVE-2026-92619-01": {"ajax_action": "wpbc_ajax_option_save", "conditions": [{"name": "ARGS:data_name", "type": "regex", "value": "~^(?:default_role|users_can_register|siteurl|home|active_plugins|template|stylesheet|admin_email|wp_user_roles)$~i"}, {"name": "missing_capability", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-92619", "description": "Booking Calendar <=11.8.2 privilege escalation via wpbc_ajax_option_save unrestricted core WordPress option write", "mode": "block", "slug": "booking", "target": "plugin", "versions": "<=11.8.2"}, "RULE-CVE-2026-92714-01": {"action": "admin_init", "conditions": [{"name": "ARGS:wpdm_duplicate", "type": "exists"}, {"name": "ARGS:__copynonce", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-92714", "description": "Download Manager <=3.3.68 IDOR in package duplicate() allows Contributor+ to duplicate arbitrary protected packages via wpdm_duplicate/__copynonce on admin_init", "mode": "block", "severity": 6.5, "slug": "download-manager", "target": "plugin", "versions": "<=3.3.68"}, "RULE-CVE-2026-9290-01": {"action": "init", "conditions": [{"name": "ARGS:wpum_profile", "type": "exists"}, {"name": "ARGS:tab", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\\\\\/]|\\\\.\\\\. %2[fF]|\\\\.\\\\. %5[cC]|\\\\.\\\\. %252[fF]|%2[eE]%2[eE](?:%2[fF]|%5[cC])|%252[eE]%252[eE]%252[fF]|%00)~"}], "cve": "CVE-2026-9290", "description": "WP User Manager <=2.9.17 unauthenticated LFI via tab query parameter on profile page", "mode": "block", "severity": 7.5, "slug": "wp-user-manager", "target": "plugin", "versions": "<=2.9.17"}, "RULE-CVE-2026-9290-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)profile/[^/]+/(?:\\\\.\\\\.[\\\\\\\\\\\\/]|\\\\.\\\\. %2[fF]|\\\\.\\\\. %5[cC]|\\\\.\\\\. %252[fF]|%2[eE]%2[eE](?:%2[fF]|%5[cC])|%252[eE]%252[eE]|%00)~i"}], "cve": "CVE-2026-9290", "description": "WP User Manager <=2.9.17 unauthenticated LFI via tab path segment in profile permalink", "mode": "block", "severity": 7.5, "slug": "wp-user-manager", "target": "plugin", "versions": "<=2.9.17"}, "RULE-CVE-2026-93485-001": {"action": "init", "block_policy": "never_block", "companion_for": "RULE-CVE-2026-93485-01", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-comments-post\\\\.php~i"}, {"name": "ARGS:comment", "type": "regex", "value": "~=4.7.0 <7.1.1"}, "RULE-CVE-2026-93485-002": {"action": "rest_api_init", "block_policy": "never_block", "companion_for": "RULE-CVE-2026-93485-02", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/wp/v2/comments[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:content", "type": "regex", "value": "~=4.7.0 <7.1.1"}, "RULE-CVE-2026-93485-003": {"action": "rest_api_init", "block_policy": "never_block", "companion_for": "RULE-CVE-2026-93485-03", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/wp/v2/comments[\\\\\\\\/]*$~i"}, {"name": "ARGS:content", "type": "regex", "value": "~=4.7.0 <7.1.1"}, "RULE-CVE-2026-93485-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-comments-post\\\\.php~i"}, {"name": "ARGS:comment", "type": "regex", "value": "~\\\\r\\\\n]{0,400}[\\\\r\\\\n]~i"}], "cve": "CVE-2026-93485", "cve_link": "https://wordpress.org/documentation/wordpress-version/version-7-1-1/", "description": "Unauthenticated stored XSS in WordPress core comment rendering leading to conditional RCE, nicknamed Comment2Shell (CVE-2026-93485, CVSS 7.1). wpautop() in wp-includes/formatting.php unwraps a paragraph-wrapped blockquote with the regex

]*)> whose [^>]* stops at the first greater-than character. Before that runs, wp_replace_in_html_tags() rewrites any newline that sits INSIDE an HTML tag to a placeholder that itself contains a greater-than character, so an allowlisted blockquote opening tag carrying a line break inside an attribute (such as cite) is split by the unwrap regex, relocating attacker-controlled text into live markup; wptexturize() then closes an injected event-handler attribute with autofocus, so script runs on page load for any viewer, and a logged-in administrator viewing the page can have their session used to install a plugin web shell. The construct survives wp_kses() because a newline inside a permitted tag is not something the sanitiser strips. Fixed across all branches at 7.1.1 / 7.0.5 / 6.9.8 / 6.8.9 / ... / 4.7.36 with a quote-aware wpautop() pattern. This rule matches a blockquote opening tag that contains a line break before it is closed, on the classic comment submission endpoint (/wp-comments-post.php, comment field).", "mode": "block", "severity": 7.1, "tags": ["xss", "stored-xss", "rce", "wp-core", "comments", "unauthenticated"], "target": "core", "versions": ">=4.7.0 <7.1.1"}, "RULE-CVE-2026-93485-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/wp/v2/comments[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\r\\\\n]{0,400}[\\\\r\\\\n]~i"}], "cve": "CVE-2026-93485", "cve_link": "https://wordpress.org/documentation/wordpress-version/version-7-1-1/", "description": "Unauthenticated stored XSS in WordPress core comment rendering leading to conditional RCE, nicknamed Comment2Shell (CVE-2026-93485, CVSS 7.1). wpautop() in wp-includes/formatting.php unwraps a paragraph-wrapped blockquote with the regex

]*)> whose [^>]* stops at the first greater-than character. Before that runs, wp_replace_in_html_tags() rewrites any newline that sits INSIDE an HTML tag to a placeholder that itself contains a greater-than character, so an allowlisted blockquote opening tag carrying a line break inside an attribute (such as cite) is split by the unwrap regex, relocating attacker-controlled text into live markup; wptexturize() then closes an injected event-handler attribute with autofocus, so script runs on page load for any viewer, and a logged-in administrator viewing the page can have their session used to install a plugin web shell. The construct survives wp_kses() because a newline inside a permitted tag is not something the sanitiser strips. Fixed across all branches at 7.1.1 / 7.0.5 / 6.9.8 / 6.8.9 / ... / 4.7.36 with a quote-aware wpautop() pattern. This rule matches a blockquote opening tag that contains a line break before it is closed, on the REST comment submission endpoint (/wp/v2/comments, URI carrier for pretty and rest_route forms, content field).", "mode": "block", "severity": 7.1, "tags": ["xss", "stored-xss", "rce", "wp-core", "comments", "unauthenticated"], "target": "core", "versions": ">=4.7.0 <7.1.1"}, "RULE-CVE-2026-93485-03": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/wp/v2/comments[\\\\\\\\/]*$~i"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\r\\\\n]{0,400}[\\\\r\\\\n]~i"}], "cve": "CVE-2026-93485", "cve_link": "https://wordpress.org/documentation/wordpress-version/version-7-1-1/", "description": "Unauthenticated stored XSS in WordPress core comment rendering leading to conditional RCE, nicknamed Comment2Shell (CVE-2026-93485, CVSS 7.1). wpautop() in wp-includes/formatting.php unwraps a paragraph-wrapped blockquote with the regex

]*)> whose [^>]* stops at the first greater-than character. Before that runs, wp_replace_in_html_tags() rewrites any newline that sits INSIDE an HTML tag to a placeholder that itself contains a greater-than character, so an allowlisted blockquote opening tag carrying a line break inside an attribute (such as cite) is split by the unwrap regex, relocating attacker-controlled text into live markup; wptexturize() then closes an injected event-handler attribute with autofocus, so script runs on page load for any viewer, and a logged-in administrator viewing the page can have their session used to install a plugin web shell. The construct survives wp_kses() because a newline inside a permitted tag is not something the sanitiser strips. Fixed across all branches at 7.1.1 / 7.0.5 / 6.9.8 / 6.8.9 / ... / 4.7.36 with a quote-aware wpautop() pattern. This rule matches a blockquote opening tag that contains a line break before it is closed, on the REST comment submission endpoint (/wp/v2/comments, source-parsed rest_route carrier, content field).", "mode": "block", "severity": 7.1, "tags": ["xss", "stored-xss", "rce", "wp-core", "comments", "unauthenticated"], "target": "core", "versions": ">=4.7.0 <7.1.1"}, "RULE-CVE-2026-93526-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/edit\\\\.php~i"}, {"name": "ARGS:qr_checked_in", "type": "regex", "value": "~(?:[\\"\'<>]|javascript\\\\s*:|on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-93526", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-93526", "description": "Event Tickets <=5.29.4 unauthenticated reflected XSS via qr_checked_in parameter reflected unescaped in QR check-in admin notice on wp-admin/edit.php", "mode": "block", "severity": 7.1, "slug": "event-tickets", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=5.29.4"}, "RULE-CVE-2026-93836-01": {"action": "init", "conditions": [{"name": "ARGS:woosb_ids", "type": "regex", "value": "~(?:]|]|]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|data:text/html)~i"}], "cve": "CVE-2026-94504", "description": "Ninja Forms <=3.15.3 unauthenticated stored XSS via nf_ajax_submit formData textarea value rendered unescaped in legacy submission editor", "mode": "block", "slug": "ninja-forms", "target": "plugin", "versions": "<=3.15.3"}, "RULE-CVE-2026-95515-01": {"action": "admin_init", "conditions": [{"name": "ARGS:nf-deactivated", "type": "regex", "value": "~(?:]|<();]|=6.5.0 <=11.0.0"}, "TEST-HEARTBEAT": {"action": "init", "conditions": [{"type": "probabilistic", "value": "0.0002"}], "cve": "TEST-HEARTBEAT", "mode": "pass", "severity": 0.1, "target": "core", "versions": ">=1.0.0"}, "TEST-RULE": {"action": "init", "conditions": [{"name": "ARGS:test-rule", "type": "equals", "value": "b3d45e60-53a5-4959-b911-5178baaef7ac"}], "cve": "TEST-CVE", "mode": "block", "severity": 2.0, "target": "core", "versions": ">=1.0.0"}}}', true );