alue": "~^/wp-json/give-api/v2/admin/forms/(trash|restore|delete|duplicate|edit)(/|\\\\?|$)~i"}, {"name": "ARGS:ids", "type": "exists"}, {"type": "missing_capability", "value": "edit_give_forms"}], "cve": "CVE-2024-5977", "method": "PUT", "mode": "block", "severity": 5.4, "slug": "give", "target": "plugin", "versions": "<=3.13.0"}, "RULE-CVE-2024-5977-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/give-api/v2/admin/forms/(trash|restore|delete|duplicate|edit)(/|\\\\?|$)~i"}, {"name": "ARGS:ids", "type": "exists"}, {"type": "missing_capability", "value": "edit_give_forms"}], "cve": "CVE-2024-5977", "method": "PATCH", "mode": "block", "severity": 5.4, "slug": "give", "target": "plugin", "versions": "<=3.13.0"}, "RULE-CVE-2024-6028-01": {"action": "init", "conditions": [{"name": "ARGS:ays_questions", "type": "regex", "value": "~(?:[^0-9, ].*[^0-9, ]|(?:UNION|SELECT|SLEEP|BENCHMARK|OR|AND|INSERT|UPDATE|DELETE|DROP|CONCAT|CHAR|0x[0-9a-fA-F]{2}|/\\\\*|\\\\*/|--)\\\\s)~i"}], "cve": "CVE-2024-6028", "method": "POST", "mode": "block", "severity": 9.8, "slug": "quiz-maker", "target": "plugin", "versions": "<=6.5.8.3"}, "RULE-CVE-2024-6088-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-json/learnpress/v1/(?:users/)?register(?:[/?]|$)|[?&]rest_route=/learnpress/v1/(?:users/)?register(?:[/?]|$))~i"}], "cve": "CVE-2024-6088", "method": "POST", "mode": "block", "severity": 5.3, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.8.1"}, "RULE-CVE-2024-6265-01": {"action": "init", "conditions": [{"name": "ARGS:uwp_sort_by", "type": "detectSQLi"}], "cve": "CVE-2024-6265", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6265", "description": "UsersWP <=1.2.10 unauthenticated SQL injection via uwp_sort_by parameter on front-end users page", "mode": "block", "severity": 9.8, "slug": "userswp", "tags": ["sql-injection", "unauthenticated", "order-by-injection"], "target": "plugin", "versions": "<=1.2.10"}, "RULE-CVE-2024-6265-02": {"ajax_action": "uwp_ajax_user_sorting_action", "conditions": [{"name": "ARGS:uwp_sort_by", "type": "detectSQLi"}], "cve": "CVE-2024-6265", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6265", "description": "UsersWP <=1.2.10 unauthenticated SQL injection via uwp_sort_by on AJAX user sorting handler", "mode": "block", "severity": 9.8, "slug": "userswp", "tags": ["sql-injection", "unauthenticated", "order-by-injection", "ajax"], "target": "plugin", "versions": "<=1.2.10"}, "RULE-CVE-2024-6328-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/api/flutter_user/firebase_sms_login(/|\\\\?|&|$)~"}], "cve": "CVE-2024-6328", "method": "POST", "mode": "block", "severity": 9.8, "slug": "mstore-api", "target": "plugin", "versions": "<=4.14.7"}, "RULE-CVE-2024-6328-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/api/flutter_user/firebase_sms_login_v2(/|\\\\?|&|$)~"}], "cve": "CVE-2024-6328", "method": "POST", "mode": "block", "severity": 9.8, "slug": "mstore-api", "target": "plugin", "versions": "<=4.14.7"}, "RULE-CVE-2024-6330-01": {"ajax_action": "gmw_info_window_init", "conditions": [{"name": "ARGS:form[info_window_template][content_path]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]|[a-z]+://|^/)~i"}], "cve": "CVE-2024-6330", "method": "POST", "mode": "block", "severity": 9.8, "slug": "geo-my-wp", "target": "plugin", "versions": "<4.5.0.2"}, "RULE-CVE-2024-6353-01": {"ajax_action": "draw_wallet_transaction_details_table", "conditions": [{"name": "ARGS:search[value]", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d|SLEEP\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|CONCAT\\\\s*\\\\(\\\\s*0x|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2024-6353", "description": "Wallet for WooCommerce <=1.5.4 authenticated SQL injection via search[value] in draw_wallet_transaction_details_table", "mode": "block", "severity": 8.8, "slug": "woo-wallet", "target": "plugin", "versions": "<=1.5.4"}, "RULE-CVE-2024-6353-02": {"ajax_action": "draw_wallet_transaction_details_table", "conditions": [{"name": "ARGS:order[0][column]", "type": "regex", "value": "~(?:SELECT\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|IF\\\\s*\\\\(|CASE\\\\s+WHEN\\\\s|\\\\(SELECT\\\\s)~i"}], "cve": "CVE-2024-6353", "description": "Wallet for WooCommerce <=1.5.4 authenticated SQL injection via order[0][column] in draw_wallet_transaction_details_table", "mode": "block", "severity": 8.8, "slug": "woo-wallet", "target": "plugin", "versions": "<=1.5.4"}, "RULE-CVE-2024-6353-03": {"ajax_action": "draw_wallet_transaction_details_table", "conditions": [{"name": "ARGS:order[0][dir]", "type": "regex", "value": "~(?:,\\\\s*\\\\(?SELECT\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|IF\\\\s*\\\\(|CASE\\\\s+WHEN\\\\s|(?:^|\\\\s)(?!ASC$|DESC$)[A-Z]{3,}\\\\s)~i"}], "cve": "CVE-2024-6353", "description": "Wallet for WooCommerce <=1.5.4 authenticated SQL injection via order[0][dir] in draw_wallet_transaction_details_table", "mode": "block", "severity": 8.8, "slug": "woo-wallet", "target": "plugin", "versions": "<=1.5.4"}, "RULE-CVE-2024-6353-04": {"ajax_action": "draw_wallet_transaction_details_table", "conditions": [{"name": "ARGS:start", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|SELECT\\\\s.*FROM\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s)~i"}], "cve": "CVE-2024-6353", "description": "Wallet for WooCommerce <=1.5.4 authenticated SQL injection via start parameter in draw_wallet_transaction_details_table", "mode": "block", "severity": 8.8, "slug": "woo-wallet", "target": "plugin", "versions": "<=1.5.4"}, "RULE-CVE-2024-6353-05": {"ajax_action": "draw_wallet_transaction_details_table", "conditions": [{"name": "ARGS:length", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|SELECT\\\\s.*FROM\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s)~i"}], "cve": "CVE-2024-6353", "description": "Wallet for WooCommerce <=1.5.4 authenticated SQL injection via length parameter in draw_wallet_transaction_details_table", "mode": "block", "severity": 8.8, "slug": "woo-wallet", "target": "plugin", "versions": "<=1.5.4"}, "RULE-CVE-2024-6365-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "wootablepress"}, {"name": "ARGS:settings[order]", "type": "regex", "value": "~<\\\\?(?:php|=|\\\\s)|\\\\?>|<%|\\\\beval\\\\b|\\\\bassert\\\\b|\\\\bsystem\\\\b|\\\\bexec\\\\b|\\\\bpassthru\\\\b|\\\\bshell_exec\\\\b|\\\\bproc_open\\\\b|\\\\bpopen\\\\b|\\\\bbase64_decode\\\\b~i"}], "cve": "CVE-2024-6365", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6365", "description": "Product Table by WBW <=2.0.1 unauthenticated RCE via PHP code injection in settings[order] written to customTitle.php", "method": "POST", "mode": "block", "severity": 9.8, "slug": "woo-product-tables", "tags": ["remote-code-execution", "arbitrary-file-write", "unauthenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.0.1"}, "RULE-CVE-2024-6365-02": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "wootablepress"}, {"type": "missing_capability", "value": "manage_options"}, {"name": "ARGS", "type": "regex", "value": "~<\\\\?(?:php|=|\\\\s)|\\\\?>|<%|\\\\beval\\\\b|\\\\bassert\\\\b|\\\\bsystem\\\\b|\\\\bexec\\\\b|\\\\bpassthru\\\\b|\\\\bshell_exec\\\\b|\\\\bproc_open\\\\b|\\\\bpopen\\\\b|\\\\bbase64_decode\\\\b~i"}], "cve": "CVE-2024-6365", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6365", "description": "Product Table by WBW <=2.0.1 unauthenticated RCE via PHP code injection in settings phrase parameters written to customTitle.php", "method": "POST", "mode": "block", "severity": 9.8, "slug": "woo-product-tables", "tags": ["remote-code-execution", "arbitrary-file-write", "unauthenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.0.1"}, "RULE-CVE-2024-6366-02": {"ajax_action": "query-attachments", "conditions": [{"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2024-6366", "method": "POST", "mode": "block", "severity": 9.1, "slug": "profile-builder", "target": "plugin", "versions": "<=3.11.7"}, "RULE-CVE-2024-6451-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "equals", "value": "/wp-admin/options.php"}, {"name": "ARGS:logs_path", "type": "exists"}, {"name": "ARGS:logs_path", "type": "regex", "value": "~\\\\.(?:php|php[0-9]+|phtml)\\\\b~i"}], "cve": "CVE-2024-6451", "method": "POST", "mode": "block", "severity": 7.2, "slug": "ai-engine", "target": "plugin", "versions": "<=2.5.0"}, "RULE-CVE-2024-6451-02": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "equals", "value": "/wp-admin/options.php"}, {"name": "ARGS:logs_path", "type": "exists"}, {"name": "ARGS:logs_path", "type": "regex", "value": "~^(?![^\\\\n]*\\\\.log$)[^\\\\n]+$~"}], "cve": "CVE-2024-6451", "method": "POST", "mode": "block", "severity": 7.2, "slug": "ai-engine", "target": "plugin", "versions": "<=2.5.0"}, "RULE-CVE-2024-6455-01": {"ajax_action": "ekit_widgetarea_content", "conditions": [{"name": "ARGS:post_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2024-6455", "description": "ElementsKit Lite <=3.2.0 unauthenticated information exposure via ekit_widgetarea_content AJAX action exposing drafts, pending and private posts", "mode": "block", "severity": 5.3, "slug": "elementskit-lite", "target": "plugin", "versions": "<=3.2.0"}, "RULE-CVE-2024-6460-01": {"ajax_action": "tm_load_data", "conditions": [{"name": "ARGS:component", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]|^/|(?:php|data|expect|phar|zip)://)~i"}], "cve": "CVE-2024-6460", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6460", "description": "Grow by Tradedoubler <=2.0.21 unauthenticated Local File Inclusion via tm_load_data AJAX component parameter", "mode": "block", "severity": 9.8, "slug": "tradedoubler-affiliate-tracker", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=2.0.21"}, "RULE-CVE-2024-6500-01": {"action": "parse_request", "conditions": [{"name": "ARGS:easypack_download", "type": "regex", "value": "~(\\\\.\\\\.(?:[/\\\\\\\\]|%2f|%5c)|%2e(?:%2e|\\\\.(?:%2f|%5c|[/\\\\\\\\]))|%2e%2e(?:%2f|/|%5c|\\\\\\\\)|^/|^[A-Za-z]:)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2024-6500", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6500", "description": "InPost for WooCommerce <=1.4.4 unauthenticated arbitrary file read/delete via easypack_download query var", "mode": "block", "severity": 10.0, "slug": "inpost-for-woocommerce", "tags": ["missing-authorization", "path-traversal", "arbitrary-file-read", "unauthenticated"], "target": "plugin", "versions": "<=1.4.4"}, "RULE-CVE-2024-6522-01": {"ajax_action": "mec_fes_form", "conditions": [{"name": "ARGS:post_id", "type": "exists"}, {"name": "ARGS:name", "type": "exists"}, {"name": "ARGS:value", "type": "exists"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2024-6522", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6522", "description": "Modern Events Calendar Lite <=7.12.1 authenticated (subscriber+) SSRF via mec_fes_form AJAX action", "method": "POST", "mode": "block", "severity": 9.6, "slug": "modern-events-calendar-lite", "tags": ["ssrf", "server-side-request-forgery", "authenticated", "cwe-918"], "target": "plugin", "versions": "<=7.12.1"}, "RULE-CVE-2024-6589-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/wp/v2/posts(?:/\\\\d+)?$~"}, {"name": "ARGS:content", "type": "regex", "value": "~wp:learnpress/[^>]*\\"template\\"\\\\s*:\\\\s*\\"[^\\"]*(?:\\\\.\\\\./|\\\\.\\\\.\\\\\\\\)[^\\"]*\\"~i"}], "cve": "CVE-2024-6589", "method": "POST", "mode": "block", "severity": 8.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.8.2"}, "RULE-CVE-2024-6589-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~wp:learnpress/[^>]*\\"template\\"\\\\s*:\\\\s*\\"[^\\"]*(?:\\\\.\\\\./|\\\\.\\\\.\\\\\\\\)[^\\"]*\\"~i"}], "cve": "CVE-2024-6589", "method": "POST", "mode": "block", "severity": 8.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.8.2"}, "RULE-CVE-2024-6589-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/wp/v2/posts(?:/\\\\d+)?$~"}, {"name": "ARGS:content", "type": "regex", "value": "~wp:learnpress/[^>]*\\"template\\"\\\\s*:\\\\s*\\"[^\\"]*(?:\\\\.\\\\./|\\\\.\\\\.\\\\\\\\)[^\\"]*\\"~i"}], "cve": "CVE-2024-6589", "method": "PUT", "mode": "block", "severity": 8.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.8.2"}, "RULE-CVE-2024-6589-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/wp/v2/posts(?:/\\\\d+)?$~"}, {"name": "ARGS:content", "type": "regex", "value": "~wp:learnpress/[^>]*\\"template\\"\\\\s*:\\\\s*\\"[^\\"]*(?:\\\\.\\\\./|\\\\.\\\\.\\\\\\\\)[^\\"]*\\"~i"}], "cve": "CVE-2024-6589", "method": "PATCH", "mode": "block", "severity": 8.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.8.2"}, "RULE-CVE-2024-6624-01": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/register~i"}, {"name": "ARGS:custom_fields[wp_capabilities]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-01G": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/register~i"}, {"name": "ARGS:custom_fields[wp_capabilities]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-02": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/register~i"}, {"name": "ARGS:custom_fields[wp_user_level]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-02G": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/register~i"}, {"name": "ARGS:custom_fields[wp_user_level]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-03": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/update_user_meta~i"}, {"name": "ARGS:meta_key", "type": "regex", "value": "~^wp_(capabilities|user_level)$~i"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-03G": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/update_user_meta~i"}, {"name": "ARGS:meta_key", "type": "regex", "value": "~^wp_(capabilities|user_level)$~i"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-04": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/update_user_meta~i"}, {"name": "ARGS:wp_capabilities", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-04G": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/update_user_meta~i"}, {"name": "ARGS:wp_capabilities", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-05": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/update_user_meta~i"}, {"name": "ARGS:wp_user_level", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-05G": {"action": "init", "conditions": [{"name": "ARGS:json", "type": "regex", "value": "~user/update_user_meta~i"}, {"name": "ARGS:wp_user_level", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-06": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/register~i"}, {"name": "ARGS:custom_fields[wp_capabilities]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-06G": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/register~i"}, {"name": "ARGS:custom_fields[wp_capabilities]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-07": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/register~i"}, {"name": "ARGS:custom_fields[wp_user_level]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-07G": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/register~i"}, {"name": "ARGS:custom_fields[wp_user_level]", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-08": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/update_user_meta~i"}, {"name": "ARGS:meta_key", "type": "regex", "value": "~^wp_(capabilities|user_level)$~i"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-08G": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/update_user_meta~i"}, {"name": "ARGS:meta_key", "type": "regex", "value": "~^wp_(capabilities|user_level)$~i"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-09": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/update_user_meta~i"}, {"name": "ARGS:wp_capabilities", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-09G": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/update_user_meta~i"}, {"name": "ARGS:wp_capabilities", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-10": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/update_user_meta~i"}, {"name": "ARGS:wp_user_level", "type": "exists"}], "cve": "CVE-2024-6624", "method": "POST", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6624-10G": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/api/user/update_user_meta~i"}, {"name": "ARGS:wp_user_level", "type": "exists"}], "cve": "CVE-2024-6624", "method": "GET", "mode": "block", "severity": 9.8, "slug": "json-api-user", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2024-6660-01": {"ajax_action": "bookingpress_import_data_continue_process_func", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2024-6660", "description": "BookingPress <=1.1.5 missing authorization on bookingpress_import_data_continue_process_func allows subscriber+ arbitrary options update and file upload", "mode": "block", "severity": 8.8, "slug": "bookingpress-appointment-booking", "target": "plugin", "versions": "<=1.1.5"}, "RULE-CVE-2024-6691-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php$~"}, {"name": "ARGS:option_page", "type": "equals", "value": "edd_settings"}], "cve": "CVE-2024-6691", "method": "POST", "mode": "block", "severity": 4.0, "slug": "easy-digital-downloads", "target": "plugin", "versions": "<=3.3.2"}, "RULE-CVE-2024-6692-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "contains", "value": "/wp-admin/options.php"}, {"name": "ARGS:edd_settings[agree_text]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2024-6692", "method": "POST", "mode": "block", "severity": 3.1, "slug": "easy-digital-downloads", "target": "plugin", "versions": "<=3.3.2"}, "RULE-CVE-2024-6704-01": {"ajax_action": "wpdAddComment", "conditions": [{"name": "ARGS:comment", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouseover|mouseenter|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:)~i"}], "cve": "CVE-2024-6704", "description": "wpDiscuz <=7.6.21 unauthenticated stored XSS via comment parameter in wpdAddComment AJAX handler", "mode": "block", "severity": 6.1, "slug": "wpdiscuz", "target": "plugin", "versions": "<=7.6.21"}, "RULE-CVE-2024-6704-02": {"ajax_action": "wpdAddInlineComment", "conditions": [{"name": "ARGS:comment", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouseover|mouseenter|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:)~i"}], "cve": "CVE-2024-6704", "description": "wpDiscuz <=7.6.21 unauthenticated stored XSS via comment parameter in wpdAddInlineComment AJAX handler", "mode": "block", "severity": 6.1, "slug": "wpdiscuz", "target": "plugin", "versions": "<=7.6.21"}, "RULE-CVE-2024-6704-03": {"ajax_action": "wpdGuestAction", "conditions": [{"name": "ARGS:comment", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouseover|mouseenter|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:)~i"}], "cve": "CVE-2024-6704", "description": "wpDiscuz <=7.6.21 unauthenticated stored XSS via guest comment submission", "mode": "block", "severity": 6.1, "slug": "wpdiscuz", "target": "plugin", "versions": "<=7.6.21"}, "RULE-CVE-2024-6723-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mwai/v1/discussions/list(/|\\\\?|$)~"}, {"name": "ARGS:sort[accessor]", "type": "regex", "value": "~[^a-zA-Z0-9_]~"}], "cve": "CVE-2024-6723", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6723", "description": "AI Engine <2.4.8 SQL injection via sort.accessor in admin discussions REST endpoint", "method": "POST", "mode": "block", "severity": 4.7, "slug": "ai-engine", "tags": ["sql-injection", "rest-api"], "target": "plugin", "versions": "<2.4.8"}, "RULE-CVE-2024-6723-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mwai-ui/v1/discussions/list(/|\\\\?|$)~"}, {"name": "ARGS:sort[accessor]", "type": "regex", "value": "~[^a-zA-Z0-9_]~"}], "cve": "CVE-2024-6723", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6723", "description": "AI Engine <2.4.8 SQL injection via sort.accessor in public discussions REST endpoint", "method": "POST", "mode": "block", "severity": 4.7, "slug": "ai-engine", "tags": ["sql-injection", "rest-api"], "target": "plugin", "versions": "<2.4.8"}, "RULE-CVE-2024-6723-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mwai/v1/discussions/list(/|\\\\?|$)~"}, {"name": "ARGS:sort[by]", "type": "regex", "value": "~[^a-zA-Z0-9_]~"}], "cve": "CVE-2024-6723", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6723", "description": "AI Engine <2.4.8 SQL injection via sort.by in admin discussions REST endpoint", "method": "POST", "mode": "block", "severity": 4.7, "slug": "ai-engine", "tags": ["sql-injection", "rest-api"], "target": "plugin", "versions": "<2.4.8"}, "RULE-CVE-2024-6723-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mwai-ui/v1/discussions/list(/|\\\\?|$)~"}, {"name": "ARGS:sort[by]", "type": "regex", "value": "~[^a-zA-Z0-9_]~"}], "cve": "CVE-2024-6723", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6723", "description": "AI Engine <2.4.8 SQL injection via sort.by in public discussions REST endpoint", "method": "POST", "mode": "block", "severity": 4.7, "slug": "ai-engine", "tags": ["sql-injection", "rest-api"], "target": "plugin", "versions": "<2.4.8"}, "RULE-CVE-2024-6809-01": {"ajax_action": "qcsmd_upvote_action", "conditions": [{"name": "ARGS:id", "type": "detectSQLi"}], "cve": "CVE-2024-6809", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-6809", "description": "Simple Video Directory <=1.4.2 unauthenticated SQL injection via id parameter in qcsmd_upvote_action AJAX handler", "method": "POST", "mode": "block", "severity": 9.8, "slug": "simple-media-directory", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=1.4.2"}, "RULE-CVE-2024-6849-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/async-upload\\\\.php~"}, {"name": "FILES:async-upload:name", "type": "regex", "value": "~\\\\.svg$~i"}, {"name": "FILES:async-upload:content", "type": "regex", "value": "~(?:]|\\\\bon(?:load|error|mouseover|click|focus|mousedown)\\\\s*=|javascript\\\\s*:|])~i"}], "cve": "CVE-2024-6849", "description": "Preloader Plus <=2.2.1 stored XSS via unsanitized SVG file upload (async-upload.php)", "mode": "block", "severity": 6.4, "slug": "preloader-plus", "target": "plugin", "versions": "<=2.2.1"}, "RULE-CVE-2024-6849-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/media-new\\\\.php~"}, {"name": "FILES:async-upload:name", "type": "regex", "value": "~\\\\.svg$~i"}, {"name": "FILES:async-upload:content", "type": "regex", "value": "~(?:]|\\\\bon(?:load|error|mouseover|click|focus|mousedown)\\\\s*=|javascript\\\\s*:|])~i"}], "cve": "CVE-2024-6849", "description": "Preloader Plus <=2.2.1 stored XSS via unsanitized SVG file upload (media-new.php)", "mode": "block", "severity": 6.4, "slug": "preloader-plus", "target": "plugin", "versions": "<=2.2.1"}, "RULE-CVE-2024-6849-03": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/media(?:/|\\\\?|$)~"}, {"name": "FILES:file:name", "type": "regex", "value": "~\\\\.svg$~i"}, {"name": "FILES:file:content", "type": "regex", "value": "~(?:]|\\\\bon(?:load|error|mouseover|click|focus|mousedown)\\\\s*=|javascript\\\\s*:|])~i"}], "cve": "CVE-2024-6849", "description": "Preloader Plus <=2.2.1 stored XSS via unsanitized SVG file upload (REST /wp/v2/media)", "mode": "block", "severity": 6.4, "slug": "preloader-plus", "target": "plugin", "versions": "<=2.2.1"}, "RULE-CVE-2024-7031-01": {"ajax_action": "njt_fs_save_setting_restrictions", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2024-7031", "method": "POST", "mode": "block", "severity": 8.8, "slug": "filester", "target": "plugin", "versions": "<=1.8.2"}, "RULE-CVE-2024-7031-02": {"ajax_action": "njt_fs_save_setting", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2024-7031", "method": "POST", "mode": "block", "severity": 8.8, "slug": "filester", "target": "plugin", "versions": "<=1.8.2"}, "RULE-CVE-2024-7094-01": {"action": "init", "conditions": [{"name": "ARGS:form_request", "type": "equals", "value": "jssupportticket"}, {"name": "ARGS:jstmod", "type": "equals", "value": "themes"}, {"name": "ARGS:task", "type": "equals", "value": "savetheme"}, {"name": "ARGS:/color[1-7]/", "type": "regex", "value": "~[\\"\'`;]|<\\\\?(?:php|=)|[$][a-zA-Z_]~"}], "cve": "CVE-2024-7094", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7094", "description": "JS Help Desk <=2.8.6 unauthorized frontend savetheme dispatch via formhandler", "method": "POST", "mode": "block", "severity": 9.8, "slug": "js-support-ticket", "tags": ["missing-authorization", "code-injection", "frontend-form"], "target": "plugin", "versions": "<=2.8.6"}, "RULE-CVE-2024-7112-01": {"ajax_action": "dopbsp_calendar_schedule_set", "conditions": [{"name": "ARGS:schedule", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bEXTRACTVALUE\\\\s*\\\\(|\\\\bUPDATEXML\\\\s*\\\\(|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2024-7112", "description": "Pinpoint Booking System <=2.9.9.5.0 authenticated SQL injection via schedule parameter in dopbsp_calendar_schedule_set AJAX handler", "mode": "block", "severity": 8.8, "slug": "booking-system", "target": "plugin", "versions": "<=2.9.9.5.0"}, "RULE-CVE-2024-7112-02": {"ajax_action": "dopbsp_calendar_schedule_get", "conditions": [{"name": "ARGS:schedule", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bEXTRACTVALUE\\\\s*\\\\(|\\\\bUPDATEXML\\\\s*\\\\(|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2024-7112", "description": "Pinpoint Booking System <=2.9.9.5.0 authenticated SQL injection via schedule parameter in dopbsp_calendar_schedule_get AJAX handler", "mode": "block", "severity": 8.8, "slug": "booking-system", "target": "plugin", "versions": "<=2.9.9.5.0"}, "RULE-CVE-2024-7112-03": {"ajax_action": "dopbsp_calendar_schedule_set", "conditions": [{"name": "ARGS:calendar_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bEXTRACTVALUE\\\\s*\\\\(|\\\\bUPDATEXML\\\\s*\\\\(|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2024-7112", "description": "Pinpoint Booking System <=2.9.9.5.0 authenticated SQL injection via calendar_id parameter in dopbsp_calendar_schedule_set AJAX handler", "mode": "block", "severity": 8.8, "slug": "booking-system", "target": "plugin", "versions": "<=2.9.9.5.0"}, "RULE-CVE-2024-7112-04": {"ajax_action": "dopbsp_calendar_schedule_get", "conditions": [{"name": "ARGS:calendar_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bEXTRACTVALUE\\\\s*\\\\(|\\\\bUPDATEXML\\\\s*\\\\(|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2024-7112", "description": "Pinpoint Booking System <=2.9.9.5.0 authenticated SQL injection via calendar_id parameter in dopbsp_calendar_schedule_get AJAX handler", "mode": "block", "severity": 8.8, "slug": "booking-system", "target": "plugin", "versions": "<=2.9.9.5.0"}, "RULE-CVE-2024-7122-01": {"ajax_action": "elementor_ajax", "conditions": [{"name": "ARGS:actions", "type": "regex", "value": "~(?:separator_title|button_text(?:_2)?|image_[12]_label|alt_text)[^}]*(?:]|on(?:error|load|mouseover|click|focus)\\\\s*=|javascript\\\\s*:)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2024-7122", "description": "Addon Elements for Elementor <=1.13.6 contributor+ stored XSS via unescaped widget attributes in Elementor AJAX save", "mode": "block", "severity": 6.4, "slug": "addon-elements-for-elementor-page-builder", "target": "plugin", "versions": "<=1.13.6"}, "RULE-CVE-2024-7122-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/elementor/v1/document/save(?:/|\\\\?|$)~"}, {"name": "ARGS:elements", "type": "regex", "value": "~(?:separator_title|button_text(?:_2)?|image_[12]_label|alt_text)[^}]*(?:]|on(?:error|load|mouseover|click|focus)\\\\s*=|javascript\\\\s*:)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2024-7122", "description": "Addon Elements for Elementor <=1.13.6 contributor+ stored XSS via unescaped widget attributes in Elementor REST save", "mode": "block", "severity": 6.4, "slug": "addon-elements-for-elementor-page-builder", "target": "plugin", "versions": "<=1.13.6"}, "RULE-CVE-2024-7257-01": {"ajax_action": "yaye_handle_upload_file", "conditions": [{"name": "FILES:option_field_data", "type": "exists"}], "cve": "CVE-2024-7257", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7257", "description": "YayExtra \\u2013 WooCommerce Extra Product Options <=1.3.7 unauthenticated arbitrary file upload via yaye_handle_upload_file AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "yayextra", "tags": ["arbitrary-file-upload", "unauthenticated", "remote-code-execution"], "target": "plugin", "versions": "<=1.3.7"}, "RULE-CVE-2024-7258-01": {"ajax_action": "myajax-delete-feed-file", "conditions": [{"type": "missing_capability", "value": "manage_options"}, {"name": "ARGS:feed_id", "type": "exists"}], "cve": "CVE-2024-7258", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7258", "description": "WP Product Feed Manager <=2.8.0 unauthenticated feed file deletion via missing authorization", "method": "POST", "mode": "block", "severity": 8.8, "slug": "wp-product-feed-manager", "tags": ["missing-authorization", "idor"], "target": "plugin", "versions": "<=2.8.0"}, "RULE-CVE-2024-7258-02": {"ajax_action": "myajax-delete-feed", "conditions": [{"type": "missing_capability", "value": "manage_options"}, {"name": "ARGS:feed_id", "type": "exists"}], "cve": "CVE-2024-7258", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7258", "description": "WP Product Feed Manager <=2.8.0 unauthenticated feed deletion via missing authorization", "method": "POST", "mode": "block", "severity": 8.8, "slug": "wp-product-feed-manager", "tags": ["missing-authorization", "idor"], "target": "plugin", "versions": "<=2.8.0"}, "RULE-CVE-2024-7302-01": {"ajax_action": "b2s_upload_video", "conditions": [{"name": "ARGS:post_title", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouse(?:down|up|over|out|move)|key(?:down|up|press)|focus|blur|change|submit|reset|select|abort|dragstart|drag|dragend|drop)\\\\s*=|javascript\\\\s*:|data\\\\s*:)~i"}], "cve": "CVE-2024-7302", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7302", "description": "Blog2Social <=7.5.4 stored XSS via post_title in video upload", "method": "POST", "mode": "block", "severity": 5.4, "slug": "blog2social", "tags": ["xss", "stored", "authenticated"], "target": "plugin", "versions": "<=7.5.4"}, "RULE-CVE-2024-7315-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~wp-content/wpvividbackups/[^/]+\\\\.(?:zip|sql|gz|tar|json|txt|log)(?:\\\\?|$)~i"}], "cve": "CVE-2024-7315", "method": "GET", "mode": "block", "severity": 7.5, "slug": "wpvivid-backuprestore", "target": "plugin", "versions": "<0.9.106"}, "RULE-CVE-2024-7315-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~wp-content/wpvividbackups/wpvivid_log/~i"}], "cve": "CVE-2024-7315", "method": "GET", "mode": "block", "severity": 7.5, "slug": "wpvivid-backuprestore", "target": "plugin", "versions": "<0.9.106"}, "RULE-CVE-2024-7385-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "wshs_saved"}, {"name": "ARGS:action", "type": "equals", "value": "delete"}, {"name": "ARGS:id", "type": "detectSQLi"}], "cve": "CVE-2024-7385", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7385", "description": "WordPress Simple HTML Sitemap <=3.1 authenticated (Admin+) SQL injection via id parameter in wshs_saved delete action", "mode": "block", "severity": 7.2, "slug": "wp-simple-html-sitemap", "tags": ["sql-injection", "authenticated", "admin-page"], "target": "plugin", "versions": "<=3.1"}, "RULE-CVE-2024-7385-02": {"ajax_action": "wshs_save_shortcode", "conditions": [{"name": "ARGS:id", "type": "detectSQLi"}], "cve": "CVE-2024-7385", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7385", "description": "WordPress Simple HTML Sitemap <=3.1 SQL injection via id parameter in wshs_save_shortcode AJAX handler", "method": "POST", "mode": "block", "severity": 7.2, "slug": "wp-simple-html-sitemap", "tags": ["sql-injection", "authenticated", "ajax"], "target": "plugin", "versions": "<=3.1"}, "RULE-CVE-2024-7493-01": {"ajax_action": "wpcom_register", "conditions": [{"name": "ARGS:role", "type": "exists"}], "cve": "CVE-2024-7493", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7493", "description": "WPCOM Member <=1.5.2.1 unauthenticated privilege escalation via role parameter in registration", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wpcom-member", "tags": ["privilege-escalation", "unauthenticated", "mass-assignment"], "target": "plugin", "versions": "<=1.5.2.1"}, "RULE-CVE-2024-7493-02": {"ajax_action": "wpcom_register", "conditions": [{"name": "ARGS:meta_input[wp_capabilities]", "type": "exists"}], "cve": "CVE-2024-7493", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7493", "description": "WPCOM Member <=1.5.2.1 unauthenticated privilege escalation via meta_input wp_capabilities", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wpcom-member", "tags": ["privilege-escalation", "unauthenticated", "mass-assignment"], "target": "plugin", "versions": "<=1.5.2.1"}, "RULE-CVE-2024-7493-03": {"ajax_action": "wpcom_register", "conditions": [{"name": "ARGS:meta_input[wp_user_level]", "type": "exists"}], "cve": "CVE-2024-7493", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7493", "description": "WPCOM Member <=1.5.2.1 unauthenticated privilege escalation via meta_input wp_user_level", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wpcom-member", "tags": ["privilege-escalation", "unauthenticated", "mass-assignment"], "target": "plugin", "versions": "<=1.5.2.1"}, "RULE-CVE-2024-7514-01": {"ajax_action": "product_comments_csv_import_request", "conditions": [{"name": "ARGS:file", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:%2[Ee]){2}%2[Ff]|(?:%252[Ee]){2}%25(?:2[Ff]|5[Cc])|[\\\\\\\\/]etc[\\\\\\\\/]|wp-config\\\\.php|\\\\.htaccess|\\\\.env)~i"}, {"type": "missing_capability", "value": "import"}], "cve": "CVE-2024-7514", "description": "Comments Import & Export <=2.3.7 authenticated arbitrary file read via path traversal in file parameter", "mode": "block", "severity": 6.5, "slug": "comments-import-export-woocommerce", "target": "plugin", "versions": "<=2.3.7"}, "RULE-CVE-2024-7548-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[learn_press_featured_courses[^\\\\]]*order\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:select|sleep|benchmark|union|concat|if\\\\s*\\\\(|0x|/\\\\*|;|\\\\()[^\\"\']*[\\"\']~i"}], "cve": "CVE-2024-7548", "method": "POST", "mode": "block", "severity": 6.5, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.9.3"}, "RULE-CVE-2024-7548-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/wp/v2/posts(/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[learn_press_featured_courses[^\\\\]]*order\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:select|sleep|benchmark|union|concat|if\\\\s*\\\\(|0x|/\\\\*|;|\\\\()[^\\"\']*[\\"\']~i"}], "cve": "CVE-2024-7548", "method": "POST", "mode": "block", "severity": 6.5, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.9.3"}, "RULE-CVE-2024-7548-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/wp/v2/posts(/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[learn_press_featured_courses[^\\\\]]*order\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:select|sleep|benchmark|union|concat|if\\\\s*\\\\(|0x|/\\\\*|;|\\\\()[^\\"\']*[\\"\']~i"}], "cve": "CVE-2024-7548", "method": "PATCH", "mode": "block", "severity": 6.5, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.9.3"}, "RULE-CVE-2024-7548-05": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[learn_press_featured_courses[^\\\\]]*order\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:select|sleep|benchmark|union|concat|if\\\\s*\\\\(|0x|/\\\\*|;|\\\\()[^\\"\']*[\\"\']~i"}], "cve": "CVE-2024-7548", "method": "POST", "mode": "block", "severity": 6.5, "slug": "learnpress", "target": "plugin", "versions": "<=4.2.6.9.3"}, "RULE-CVE-2024-7590-01": {"ajax_action": "uag_load_image_gallery_masonry", "conditions": [{"name": "ARGS:attr", "type": "regex", "value": "~(?:<[^>]*\\\\son\\\\w+\\\\s*=|<\\\\s*(?:script|iframe|object|embed|applet|base|link|meta|style|svg|math|body|video|audio|details|form|input|select|textarea|button|marquee)\\\\b|javascript\\\\s*:|vbscript\\\\s*:|data\\\\s*:[^,]*;base64)~i"}], "cve": "CVE-2024-7590", "method": "POST", "mode": "block", "severity": 5.4, "slug": "ultimate-addons-for-gutenberg", "target": "plugin", "versions": "<=2.15.0"}, "RULE-CVE-2024-7590-02": {"ajax_action": "uag_load_image_gallery_grid_pagination", "conditions": [{"name": "ARGS:attr", "type": "regex", "value": "~(?:<[^>]*\\\\son\\\\w+\\\\s*=|<\\\\s*(?:script|iframe|object|embed|applet|base|link|meta|style|svg|math|body|video|audio|details|form|input|select|textarea|button|marquee)\\\\b|javascript\\\\s*:|vbscript\\\\s*:|data\\\\s*:[^,]*;base64)~i"}], "cve": "CVE-2024-7590", "method": "POST", "mode": "block", "severity": 5.4, "slug": "ultimate-addons-for-gutenberg", "target": "plugin", "versions": "<=2.15.0"}, "RULE-CVE-2024-7607-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "feup-users"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2024-7607", "description": "Front End Only Users <=3.2.28 authenticated SQL injection via order parameter on feup-users admin page", "mode": "block", "severity": 8.8, "slug": "front-end-only-users", "target": "plugin", "versions": "<=3.2.28"}, "RULE-CVE-2024-7656-01": {"action": "init", "conditions": [{"name": "ARGS:content", "type": "regex", "value": "~devvn_ihotspot[\\\\s\\\\S]{0,2000}?[OC]:[0-9]+:(?:\\\\\\\\?\\"|"|%22)~i"}], "cve": "CVE-2024-7656", "description": "Image Hotspot by DevVN <=1.2.5 authenticated (Author+) PHP Object Injection via devvn_ihotspot shortcode unserialize sink \\u2014 write-time block on content param", "mode": "block", "severity": 8.8, "slug": "devvn-image-hotspot", "target": "plugin", "versions": "<=1.2.5"}, "RULE-CVE-2024-7656-02": {"action": "init", "conditions": [{"name": "ARGS:post_content", "type": "regex", "value": "~devvn_ihotspot[\\\\s\\\\S]{0,2000}?[OC]:[0-9]+:(?:\\\\\\\\?\\"|"|%22)~i"}], "cve": "CVE-2024-7656", "description": "Image Hotspot by DevVN <=1.2.5 authenticated (Author+) PHP Object Injection via post_content carrying devvn_ihotspot serialized object", "mode": "block", "severity": 8.8, "slug": "devvn-image-hotspot", "target": "plugin", "versions": "<=1.2.5"}, "RULE-CVE-2024-7703-01": {"ajax_action": "arm_upload_front", "conditions": [{"name": "FILES:file:type", "type": "regex", "value": "~^image/svg~i"}, {"name": "FILES:file:content", "type": "regex", "value": "~(]|on(?:load|error|click|mouseover)\\\\s*=)~i"}], "cve": "CVE-2024-7703", "description": "ARMember <=4.0.37 stored XSS via SVG file upload in arm_upload_front", "mode": "block", "severity": 6.4, "slug": "armember-membership", "target": "plugin", "versions": "<=4.0.37"}, "RULE-CVE-2024-7703-02": {"ajax_action": "arm_upload_cover", "conditions": [{"name": "FILES:file:type", "type": "regex", "value": "~^image/svg~i"}, {"name": "FILES:file:content", "type": "regex", "value": "~(]|on(?:load|error|click|mouseover)\\\\s*=)~i"}], "cve": "CVE-2024-7703", "description": "ARMember <=4.0.37 stored XSS via SVG file upload in arm_upload_cover", "mode": "block", "severity": 6.4, "slug": "armember-membership", "target": "plugin", "versions": "<=4.0.37"}, "RULE-CVE-2024-7703-03": {"ajax_action": "arm_upload_profile", "conditions": [{"name": "FILES:file:type", "type": "regex", "value": "~^image/svg~i"}, {"name": "FILES:file:content", "type": "regex", "value": "~(]|on(?:load|error|click|mouseover)\\\\s*=)~i"}], "cve": "CVE-2024-7703", "description": "ARMember <=4.0.37 stored XSS via SVG file upload in arm_upload_profile", "mode": "block", "severity": 6.4, "slug": "armember-membership", "target": "plugin", "versions": "<=4.0.37"}, "RULE-CVE-2024-7703-04": {"ajax_action": "arm_import_user", "conditions": [{"name": "FILES:file:type", "type": "regex", "value": "~^image/svg~i"}, {"name": "FILES:file:content", "type": "regex", "value": "~(]|on(?:load|error|click|mouseover)\\\\s*=)~i"}], "cve": "CVE-2024-7703", "description": "ARMember <=4.0.37 stored XSS via SVG file import in arm_import_user", "mode": "block", "severity": 6.4, "slug": "armember-membership", "target": "plugin", "versions": "<=4.0.37"}, "RULE-CVE-2024-7717-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "contains", "value": "/wp-admin/edit.php"}, {"name": "ARGS:post_type", "type": "equals", "value": "tp_event"}, {"name": "ARGS:orderby", "type": "exists"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|IF\\\\s*\\\\(|CASE\\\\s+WHEN|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|\\\\bOR\\\\b\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|\\\\bAND\\\\b\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|\\\\(\\\\s*SELECT\\\\s)~i"}], "cve": "CVE-2024-7717", "description": "WP Events Manager <=2.1.11 authenticated SQL injection via order parameter in admin event list sorting", "mode": "block", "severity": 8.8, "slug": "wp-events-manager", "target": "plugin", "versions": "<=2.1.11"}, "RULE-CVE-2024-7770-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~file-manager/libs/elFinder/php/connector~i"}, {"name": "FILES:upload:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$~i"}], "cve": "CVE-2024-7770", "description": "Bit File Manager <=6.5.5 block direct access to elFinder connector with dangerous file upload", "mode": "block", "severity": 8.8, "slug": "file-manager", "target": "plugin", "versions": "<=6.5.5"}, "RULE-CVE-2024-7856-01": {"ajax_action": "removeTempFiles", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2024-7856", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7856", "description": "MP3 Music Player by Sonaar <=5.7.0.1 missing authorization (subscriber+) arbitrary file deletion via removeTempFiles AJAX handler", "method": "POST", "mode": "block", "severity": 8.1, "slug": "mp3-music-player-by-sonaar", "tags": ["missing-authorization", "arbitrary-file-deletion", "path-traversal"], "target": "plugin", "versions": "<=5.7.0.1"}, "RULE-CVE-2024-7857-01": {"ajax_action": "mlf_change_sort_type", "conditions": [{"name": "ARGS:sort_type", "type": "detectSQLi"}], "cve": "CVE-2024-7857", "method": "POST", "mode": "block", "severity": 6.5, "slug": "media-library-plus", "target": "plugin", "versions": "<=8.2.2"}, "RULE-CVE-2024-7982-01": {"ajax_action": "rtec_process_form_submission", "conditions": [{"name": "ARGS:first_name", "type": "detectXSS"}], "cve": "CVE-2024-7982", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7982", "description": "Registrations for the Events Calendar <=2.12.3 unauthenticated stored XSS via first_name in registration form submission", "method": "POST", "mode": "block", "severity": 9.6, "slug": "registrations-for-the-events-calendar", "tags": ["xss", "stored-xss", "unauthenticated"], "target": "plugin", "versions": "<=2.12.3"}, "RULE-CVE-2024-7982-02": {"ajax_action": "rtec_process_form_submission", "conditions": [{"name": "ARGS:last_name", "type": "detectXSS"}], "cve": "CVE-2024-7982", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7982", "description": "Registrations for the Events Calendar <=2.12.3 unauthenticated stored XSS via last_name in registration form submission", "method": "POST", "mode": "block", "severity": 9.6, "slug": "registrations-for-the-events-calendar", "tags": ["xss", "stored-xss", "unauthenticated"], "target": "plugin", "versions": "<=2.12.3"}, "RULE-CVE-2024-7985-01": {"ajax_action": "fileorganizer_file_folder_manager", "conditions": [{"name": "ARGS:cmd", "type": "equals", "value": "upload"}, {"name": "ARGS:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|phtml|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini|htaccess)$~i"}], "cve": "CVE-2024-7985", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-7985", "description": "File Organizer <=1.0.9 authenticated arbitrary file upload via filename extension bypass", "mode": "block", "severity": 8.8, "slug": "fileorganizer", "tags": ["arbitrary-file-upload", "authenticated", "file-upload"], "target": "plugin", "versions": "<=1.0.9"}, "RULE-CVE-2024-8252-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[clean-login-register[^\\\\]]*template\\\\s*=\\\\s*[\\"\']?[^\\"\'\\\\]]*\\\\.\\\\.[/\\\\\\\\]~i"}], "cve": "CVE-2024-8252", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-8252", "description": "Clean Login <=1.14.5 authenticated (Contributor+) local file inclusion via clean-login-register shortcode template attribute in post content (post.php)", "mode": "block", "severity": 8.8, "slug": "clean-login", "tags": ["local-file-inclusion", "path-traversal", "shortcode", "authenticated"], "target": "plugin", "versions": "<=1.14.5"}, "RULE-CVE-2024-8252-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[clean-login-register[^\\\\]]*template\\\\s*=\\\\s*[\\"\']?[^\\"\'\\\\]]*\\\\.\\\\.[/\\\\\\\\]~i"}], "cve": "CVE-2024-8252", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-8252", "description": "Clean Login <=1.14.5 authenticated (Contributor+) local file inclusion via clean-login-register shortcode template attribute in REST API post creation", "mode": "block", "severity": 8.8, "slug": "clean-login", "tags": ["local-file-inclusion", "path-traversal", "shortcode", "authenticated", "rest-api"], "target": "plugin", "versions": "<=1.14.5"}, "RULE-CVE-2024-8271-01": {"ajax_action": "woocs_get_custom_price_html", "conditions": [{"name": "ARGS:custom_prices", "type": "regex", "value": "~(?:\\\\[[a-zA-Z][a-zA-Z0-9_\\\\-]*(?:\\\\s|\\\\]|/)|%5[Bb][a-zA-Z][a-zA-Z0-9_\\\\-]*(?:\\\\s|%5[Dd]|/)|%25[57]5[Bb][a-zA-Z])~"}], "cve": "CVE-2024-8271", "description": "WooCommerce Currency Switcher <=1.4.2.1 unauthenticated arbitrary shortcode execution via woocs_get_custom_price_html AJAX action (custom_prices parameter flows to do_shortcode at classes/woocs.php:4600)", "mode": "block", "severity": 7.3, "slug": "woocommerce-currency-switcher", "target": "plugin", "versions": "<=1.4.2.1"}, "RULE-CVE-2024-8271-02": {"ajax_action": "nopriv_woocs_get_custom_price_html", "conditions": [{"name": "ARGS:custom_prices", "type": "regex", "value": "~(?:\\\\[[a-zA-Z][a-zA-Z0-9_\\\\-]*(?:\\\\s|\\\\]|/)|%5[Bb][a-zA-Z][a-zA-Z0-9_\\\\-]*(?:\\\\s|%5[Dd]|/)|%25[57]5[Bb][a-zA-Z])~"}], "cve": "CVE-2024-8271", "description": "WooCommerce Currency Switcher <=1.4.2.1 unauthenticated arbitrary shortcode execution via woocs_get_custom_price_html AJAX action (nopriv hook)", "mode": "block", "severity": 7.3, "slug": "woocommerce-currency-switcher", "target": "plugin", "versions": "<=1.4.2.1"}, "RULE-CVE-2024-8275-01": {"action": "init", "conditions": [{"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[0-9]+\\\\s*=\\\\s*[0-9]+|EXTRACTVALUE\\\\s*\\\\(|CONCAT\\\\s*\\\\(|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2024-8275", "description": "The Events Calendar <=6.6.4 unauthenticated SQL injection via order parameter in tribe_has_next_event template tag", "method": "GET", "mode": "block", "severity": 9.8, "slug": "the-events-calendar", "target": "plugin", "versions": "<=6.6.4"}, "RULE-CVE-2024-8289-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mvx/v1/vendors/?(?:\\\\?|$)~"}, {"type": "missing_capability", "value": "create_users"}], "cve": "CVE-2024-8289", "method": "POST", "mode": "block", "severity": 9.8, "slug": "dc-woocommerce-multi-vendor", "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2024-8289-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mvx/v1/vendors/\\\\d+(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2024-8289", "method": "POST", "mode": "block", "severity": 9.8, "slug": "dc-woocommerce-multi-vendor", "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2024-8289-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mvx/v1/vendors/\\\\d+(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2024-8289", "method": "PUT", "mode": "block", "severity": 9.8, "slug": "dc-woocommerce-multi-vendor", "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2024-8289-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mvx/v1/vendors/\\\\d+(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2024-8289", "method": "PATCH", "mode": "block", "severity": 9.8, "slug": "dc-woocommerce-multi-vendor", "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2024-8289-05": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mvx/v1/vendors/\\\\d+(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "delete_users"}], "cve": "CVE-2024-8289", "method": "DELETE", "mode": "block", "severity": 9.8, "slug": "dc-woocommerce-multi-vendor", "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2024-8289-06": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mvx/v1/vendors/batch(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2024-8289", "method": "POST", "mode": "block", "severity": 9.8, "slug": "dc-woocommerce-multi-vendor", "target": "plugin", "versions": "<=4.2.0"}, "RULE-CVE-2024-8353-02": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_address", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-03": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_address_2", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-04": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_city", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-05": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_state", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-06": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_zip", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-07": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_name", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-08": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_number", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-09": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_cvc", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-10": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_exp_month", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-11": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:card_exp_year", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-12": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:billing_country", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-13": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:give_first", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-14": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:give_last", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8353-15": {"ajax_action": "give_process_donation", "conditions": [{"name": "ARGS:give-form-title", "type": "regex", "value": "~[oOcCaA]:\\\\d+:[\\"\\\\{]~"}], "cve": "CVE-2024-8353", "method": "POST", "mode": "block", "severity": 9.8, "slug": "give", "target": "plugin", "versions": "<3.16.2"}, "RULE-CVE-2024-8485-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/watch-life-net/v1/weixin/updateuserinfo(?:/|\\\\?|&|$)~i"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2024-8485", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-8485", "description": "REST API TO MiniProgram <=4.7.1 unauthenticated arbitrary user email update and privilege escalation via updateuserinfo REST endpoint IDOR", "method": "POST", "mode": "block", "severity": 9.8, "slug": "rest-api-to-miniprogram", "tags": ["authorization-bypass", "idor", "privilege-escalation", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<4.7.6"}, "RULE-CVE-2024-8500-01": {"ajax_action": "su_generator_preview", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|on(?:error|load|click|mouseover|focus|blur|toggle|animationstart)\\\\s*=|javascript\\\\s*:|<\\\\s*svg[^>]*on|<\\\\s*img[^>]+onerror|data\\\\s*:\\\\s*text/html)~i"}], "cve": "CVE-2024-8500", "description": "Shortcodes Ultimate <=7.2.2 Contributor+ XSS via su_generator_preview shortcode/atts/content parameters reaching echo sink in Su_Generator::preview", "mode": "block", "severity": 5.4, "slug": "shortcodes-ultimate", "target": "plugin", "versions": "<=7.2.2"}, "RULE-CVE-2024-8500-02": {"ajax_action": "su_generator_settings", "conditions": [{"name": "ARGS:shortcode", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*svg[^>]*on|<\\\\s*img[^>]+onerror)~i"}], "cve": "CVE-2024-8500", "description": "Shortcodes Ultimate <=7.2.2 Contributor+ XSS/code-flow via su_generator_settings shortcode parameter reaching echo/call_user_func sinks", "mode": "block", "severity": 5.4, "slug": "shortcodes-ultimate", "target": "plugin", "versions": "<=7.2.2"}, "RULE-CVE-2024-8519-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "contains", "value": "um_loggedin"}, {"name": "ARGS:post_content", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|\\\\bon(?:error|load|mouseover|click|focus|blur|toggle|begin|end)\\\\s*=|javascript\\\\s*:|<\\\\s*iframe[\\\\s>]|<\\\\s*svg[\\\\s/>])~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2024-8519", "description": "Ultimate Member <=2.8.6 stored XSS via um_loggedin shortcode lock_text attribute or inner content", "mode": "block", "severity": 6.4, "slug": "ultimate-member", "target": "plugin", "versions": "<=2.8.6"}, "RULE-CVE-2024-8522-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/learnpress/v1/courses~"}, {"name": "ARGS:c_only_fields", "type": "regex", "value": "~(?i)(SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|IF\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|\\\\(SELECT\\\\b|UNION\\\\s+SELECT\\\\b)~"}], "cve": "CVE-2024-8522", "description": "LearnPress <=4.2.7 unauthenticated SQL injection via c_only_fields parameter in REST courses endpoint.", "method": "GET", "mode": "block", "severity": 7.5, "slug": "learnpress", "target": "plugin", "versions": "<4.2.7.1"}, "RULE-CVE-2024-8529-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/lp/v1/courses/archive-course(?:/|\\\\?|&|$)~i"}, {"name": "ARGS:c_fields", "type": "detectSQLi"}], "cve": "CVE-2024-8529", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-8529", "description": "LearnPress <= 4.2.7 unauthenticated SQL injection via c_fields parameter on the REST endpoint /wp-json/lp/v1/courses/archive-course. The REQUEST_URI regex is intentionally used alongside action: rest_api_init to tightly scope detection to only the known vulnerable REST route, avoiding false positives on other LearnPress REST endpoints that do not consume c_fields/c_only_fields.", "mode": "block", "severity": 9.8, "slug": "learnpress-wordpress-lms-plugin", "tags": ["sqli", "unauthenticated", "rest-api", "learnpress"], "target": "plugin", "versions": "<=4.2.7"}, "RULE-CVE-2024-8529-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/lp/v1/courses/archive-course(?:/|\\\\?|&|$)~i"}, {"name": "ARGS:c_only_fields", "type": "detectSQLi"}], "cve": "CVE-2024-8529", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2024-8529", "description": "LearnPress <= 4.2.7 unauthenticated SQL injection via c_only_fields parameter on the REST endpoint /wp-json/lp/v1/courses/archive-course. The REQUEST_URI regex is intentionally used alongside action: rest_api_init to tightly scope detection to only the known vulnerable REST route, avoiding false positives on other LearnPress REST endpoints that do not consume c_fields/c_only_fields.", "mode": "block", "severity": 9.8, "slug": "learnpress-wordpress-lms-plugin", "tags": ["sqli", "unauthenticated", "rest-api", "learnpress"], "target": "plugin", "versions": "<=4.2.7"}, "RULE-CVE-2024-8549-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/(?:edit\\\\.php|post\\\\.php|post-new\\\\.php|admin\\\\.php|options-general\\\\.php).*[?&].*(?:post_type=calendar|page=simple-calendar)~"}, {"name": "REQUEST_URI", "type": "regex", "value": "~(?:%3[Cc]|<)(?:[a-zA-Z/!]|%2[Ff])|(?:%22|%27|\\"|\')\\\\s*(?:%3[Ee]|>)|javascript(?:%3[Aa]|:)|on(?:load|error|click|focus|mouseover|mouseenter|toggle|animationstart|animationend|pointerdown|pointerover|wheel|keydown|keyup|blur|change|submit|input)\\\\s*(?:%3[Dd]|=)|(?:%3[Cc]|<)(?:script|svg|img|iframe|body|input|object|embed|link|style|meta|video|audio|details|marquee)~i"}], "cve": "CVE-2024-8549", "description": "Simple Calendar (google-calendar-events) <=3.4.2 reflected XSS via admin_notices add_query_arg URL reflected from REQUEST_URI without esc_url", "mode": "block", "severity": 6.1, "slug": "google-calendar-events", "target": "plugin", "versions": "<=3.4.2"}, "RULE-CVE-2024-8672-01": {"ajax_action": "widgetopts_migrator", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2024-8672", "description": "Widget Options <=4.0.7 widgetopts_migrator AJAX handler lacks nonce and capability checks, allowing authenticated users to trigger file delete/upload/include operations via the import-export migrator flow", "mode": "block", "severity": 9.9, "slug": "widget-options", "target": "plugin", "versions": "<=4.0.7"}, "RULE-CVE-2024-8800-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php(\\\\?|$)~"}, {"name": "ARGS:page", "type": "equals", "value": "rabbit-loader"}, {"name": "ARGS", "type": "regex", "value": "~(?i)(%3Cscript|]*>|\\\\bon(?:error|load|click|mouseover|focus|blur|toggle|animationend|change|input|submit|pointerover|mouseenter|dblclick|keydown|keyup|keypress)\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*;base64)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-11876", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11876", "description": "Mailgun Subscriptions <=1.3.1 Stored XSS via mailgun_subscription_form shortcode attributes in post content", "method": "POST", "mode": "block", "severity": 6.4, "slug": "mailgun-subscriptions", "tags": ["xss", "stored-xss", "shortcode"], "target": "plugin", "versions": "<=1.3.2"}, "RULE-CVE-2025-11881-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/appp/v1/myappp-verify(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11881", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11881", "description": "AppPresser <=4.5.0 unauthenticated information disclosure via myappp-verify REST endpoint", "method": "GET", "mode": "block", "severity": 5.3, "slug": "apppresser", "tags": ["missing-authorization", "information-disclosure", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=4.5.0"}, "RULE-CVE-2025-11881-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/appp/v1/system-info(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11881", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11881", "description": "AppPresser <=4.5.0 unauthenticated information disclosure via system-info REST endpoint", "method": "GET", "mode": "block", "severity": 5.3, "slug": "apppresser", "tags": ["missing-authorization", "information-disclosure", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=4.5.0"}, "RULE-CVE-2025-11917-01": {"ajax_action": "wpematico_test_feed", "conditions": [{"name": "ARGS:url", "type": "regex", "value": "~(?:^(?:gopher|dict|file|ftp|ldap|tftp)://|://(?:localhost|\\\\[?::1\\\\]?|0x[0-9a-f]|0[0-7]{2,}|127\\\\.|10\\\\.|172\\\\.(?:1[6-9]|2[0-9]|3[01])\\\\.|192\\\\.168\\\\.|169\\\\.254\\\\.)|://[^/?#]*@)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11917", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11917", "description": "WPeMatico RSS Feed Fetcher <=2.8.11 authenticated (Subscriber+) SSRF via wpematico_test_feed AJAX action", "method": "POST", "mode": "block", "severity": 6.4, "slug": "wpematico", "tags": ["ssrf", "missing-authorization", "authenticated"], "target": "plugin", "versions": "<=2.8.11"}, "RULE-CVE-2025-11923-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/llms/v1/students/\\\\d+(/|\\\\?|&|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11923", "mode": "block", "severity": 8.8, "slug": "lifterlms", "target": "plugin", "versions": ">=3.5.3 <=9.1.0"}, "RULE-CVE-2025-11923-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/llms/v1/instructors/\\\\d+(/|\\\\?|&|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11923", "mode": "block", "severity": 8.8, "slug": "lifterlms", "target": "plugin", "versions": ">=3.5.3 <=9.1.0"}, "RULE-CVE-2025-11924-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/ninja-forms-views/(?:v1/)?forms/\\\\d+/submissions(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11924", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11924", "description": "Ninja Forms <=3.13.2 unauthenticated IDOR on ninja-forms-views REST submissions endpoint", "method": "GET", "mode": "block", "severity": 7.5, "slug": "ninja-forms", "tags": ["idor", "missing-authorization", "unauthenticated", "rest-api", "sensitive-data-exposure"], "target": "plugin", "versions": "<=3.13.2"}, "RULE-CVE-2025-11924-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/ninja-forms-views/(?:v1/)?token/refresh(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11924", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11924", "description": "Ninja Forms <=3.13.2 unauthenticated bearer token minting via ninja-forms-views REST token/refresh endpoint", "method": "POST", "mode": "block", "severity": 7.5, "slug": "ninja-forms", "tags": ["authentication-bypass", "missing-authorization", "unauthenticated", "rest-api", "token-minting"], "target": "plugin", "versions": "<=3.13.2"}, "RULE-CVE-2025-11928-01": {"ajax_action": "cjtoolbox_set_property", "conditions": [{"type": "missing_capability", "value": "unfiltered_html"}, {"name": "ARGS", "type": "regex", "value": "~<(?:script|iframe|embed|object|form|meta|base|link)\\\\b|\\\\bon(?:error|load|click|mouseover|focus|blur|change|submit|keydown|keyup|mouseout|mouseenter|mouseleave|dblclick|contextmenu|input|invalid|reset|search|select|drag|drop|copy|cut|paste|abort|canplay|ended|pause|play|progress|ratechange|seeked|seeking|stalled|suspend|waiting|toggle|popstate|hashchange|beforeunload|unload|message|storage|animationstart|animationend|animationiteration|transitionend)\\\\s*=|javascript\\\\s*:/~i"}], "cve": "CVE-2025-11928", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11928", "description": "CSS & JavaScript Toolbox <=12.0.5 Stored XSS via cjtoolbox_set_property AJAX handler", "method": "POST", "mode": "block", "severity": 4.4, "slug": "css-javascript-toolbox", "tags": ["xss", "stored-xss", "authenticated"], "target": "plugin", "versions": "<=12.0.5"}, "RULE-CVE-2025-11928-02": {"ajax_action": "cjtoolbox_create", "conditions": [{"type": "missing_capability", "value": "unfiltered_html"}, {"name": "ARGS", "type": "regex", "value": "~<(?:script|iframe|embed|object|form|meta|base|link)\\\\b|\\\\bon(?:error|load|click|mouseover|focus|blur|change|submit|keydown|keyup|mouseout|mouseenter|mouseleave|dblclick|contextmenu|input|invalid|reset|search|select|drag|drop|copy|cut|paste|abort|canplay|ended|pause|play|progress|ratechange|seeked|seeking|stalled|suspend|waiting|toggle|popstate|hashchange|beforeunload|unload|message|storage|animationstart|animationend|animationiteration|transitionend)\\\\s*=|javascript\\\\s*:/~i"}], "cve": "CVE-2025-11928", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11928", "description": "CSS & JavaScript Toolbox <=12.0.5 Stored XSS via cjtoolbox_create AJAX handler", "method": "POST", "mode": "block", "severity": 4.4, "slug": "css-javascript-toolbox", "tags": ["xss", "stored-xss", "authenticated"], "target": "plugin", "versions": "<=12.0.5"}, "RULE-CVE-2025-11976-01": {"action": "admin_init", "conditions": [{"name": "ARGS:fusewp_save_sync_rule", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11976", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11976", "description": "FuseWP <=1.1.23.0 CSRF to sync rule creation/edit via missing nonce and capability check on save_changes()", "method": "POST", "mode": "block", "severity": 4.3, "slug": "fusewp", "tags": ["csrf", "missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=1.1.23.0"}, "RULE-CVE-2025-11986-01": {"ajax_action": "crypto_connect_ajax_process", "conditions": [{"type": "missing_capability", "value": "read"}], "cve": "CVE-2025-11986", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11986", "description": "Crypto plugin <=2.22 unauthenticated auth bypass and data injection via crypto_connect_ajax_process AJAX action", "method": "POST", "mode": "block", "severity": 5.3, "slug": "crypto", "tags": ["missing-authentication", "authentication-bypass", "unauthenticated", "information-exposure"], "target": "plugin", "versions": "<=2.22"}, "RULE-CVE-2025-11987-01": {"action": "init", "conditions": [{"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[visual-link-preview\\\\b[^\\\\]]*(?:<[a-z/!]|(?:\\\\s|\\"|\')on[a-z]+\\\\s*=|javascript\\\\s*:)[^\\\\]]*\\\\]~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-11987", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11987", "description": "Visual Link Preview <=2.2.7 Stored XSS via visual-link-preview shortcode attributes in post content (post.php)", "method": "POST", "mode": "block", "severity": 6.4, "slug": "visual-link-preview", "tags": ["xss", "stored-xss", "shortcode"], "target": "plugin", "versions": "<=2.2.7"}, "RULE-CVE-2025-11987-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/\\\\d+)?(?:/)?(?:\\\\?|&|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[visual-link-preview\\\\b[^\\\\]]*(?:<[a-z/!]|(?:\\\\s|\\"|\')on[a-z]+\\\\s*=|javascript\\\\s*:)[^\\\\]]*\\\\]~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-11987", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11987", "description": "Visual Link Preview <=2.2.7 Stored XSS via visual-link-preview shortcode attributes in REST API post content", "method": "POST", "mode": "block", "severity": 6.4, "slug": "visual-link-preview", "tags": ["xss", "stored-xss", "shortcode", "rest-api"], "target": "plugin", "versions": "<=2.2.7"}, "RULE-CVE-2025-11994-01": {"action": "init", "conditions": [{"name": "ARGS:name", "type": "regex", "value": "~<[a-zA-Z/!]~"}], "cve": "CVE-2025-11994", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11994", "description": "Easy Email Subscription <=1.3 unauthenticated stored XSS via subscription form name parameter", "method": "POST", "mode": "block", "severity": 7.2, "slug": "email-subscription-with-secure-captcha", "tags": ["xss", "stored-xss", "unauthenticated"], "target": "plugin", "versions": "<=1.3"}, "RULE-CVE-2025-11995-01": {"action": "init", "conditions": [{"name": "ARGS:eventdesc", "type": "detectXSS"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated stored XSS via event description field in front-end submission form", "method": "POST", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "stored-xss", "unauthenticated", "shortcode"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11995-02": {"action": "init", "conditions": [{"name": "ARGS:eventname", "type": "detectXSS"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated stored XSS via event name field in front-end submission form", "method": "POST", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "stored-xss", "unauthenticated", "shortcode"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11995-03": {"action": "init", "conditions": [{"name": "ARGS:eventaddress", "type": "detectXSS"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated stored XSS via event address field in front-end submission form", "method": "POST", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "stored-xss", "unauthenticated", "shortcode"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11995-04": {"action": "init", "conditions": [{"name": "ARGS:eventticket", "type": "detectXSS"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated stored XSS via event ticket address field in front-end submission form", "method": "POST", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "stored-xss", "unauthenticated", "shortcode"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11995-05": {"ajax_action": "community_events_frontend_list", "conditions": [{"name": "ARGS:year", "type": "regex", "value": "~[^0-9]~"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated reflected XSS via year parameter in community_events_frontend_list AJAX handler", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "reflected-xss", "unauthenticated"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11995-06": {"ajax_action": "community_events_admin_list", "conditions": [{"name": "ARGS:currentyear", "type": "regex", "value": "~[^0-9]~"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated reflected XSS via currentyear parameter in community_events_admin_list AJAX handler", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "reflected-xss", "unauthenticated"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11995-07": {"ajax_action": "community_events_click_tracker", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~[^0-9]~"}], "cve": "CVE-2025-11995", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11995", "description": "Community Events <=1.5.2 unauthenticated reflected XSS via id parameter in community_events_click_tracker AJAX handler", "mode": "block", "severity": 7.2, "slug": "community-events", "tags": ["xss", "reflected-xss", "unauthenticated"], "target": "plugin", "versions": "<=1.5.2"}, "RULE-CVE-2025-11999-01": {"ajax_action": "addmultiplemarker_reset_map", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11999", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11999", "description": "Add Multiple Marker <=1.2 unauthenticated map reset via addmultiplemarker_reset_map AJAX handler", "method": "POST", "mode": "block", "severity": 5.3, "slug": "add-multiple-marker", "tags": ["missing-authorization", "unauthenticated", "data-deletion"], "target": "plugin", "versions": "<=1.2"}, "RULE-CVE-2025-11999-02": {"ajax_action": "amm_save_map_api", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-11999", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-11999", "description": "Add Multiple Marker <=1.2 unauthenticated API key overwrite via amm_save_map_api AJAX handler", "method": "POST", "mode": "block", "severity": 5.3, "slug": "add-multiple-marker", "tags": ["missing-authorization", "unauthenticated", "settings-manipulation"], "target": "plugin", "versions": "<=1.2"}, "RULE-CVE-2025-12000-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wpfunnels/v1/settings(/|\\\\?|&|$)~"}, {"name": "ARGS:logKey", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:%2e%2e|%252e%252e)[%/\\\\\\\\]|[\\\\\\\\/]etc[\\\\\\\\/]|(?:wp-config\\\\.php|\\\\.htaccess|\\\\.env|(?:^|[\\\\\\\\/])(?:debug\\\\.log|error_log)(?:$|[\\\\\\\\/])))~i"}], "cve": "CVE-2025-12000", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12000", "description": "WPFunnels <=3.6.2 authenticated arbitrary file deletion via path traversal in logKey parameter on REST settings endpoint", "method": "POST", "mode": "block", "severity": 6.5, "slug": "wpfunnels", "tags": ["path-traversal", "arbitrary-file-deletion", "rest-api"], "target": "plugin", "versions": "<=3.6.2"}, "RULE-CVE-2025-12010-01": {"action": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\{al:\\\\s*(?:user_pass|user_activation_key|user_email|user_login|user_registered|user_status)\\\\}~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-12010", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12010", "description": "Authors List <=2.0.6.1 authenticated (Contributor+) sensitive information exposure via {al:*} shortcode placeholders in post content", "method": "POST", "mode": "block", "severity": 6.5, "slug": "authors-list", "tags": ["sensitive-information-exposure", "shortcode", "authenticated"], "target": "plugin", "versions": "<=2.0.6.1"}, "RULE-CVE-2025-12010-02": {"ajax_action": "update_authors_list_ajax", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\{al:\\\\s*(?:user_pass|user_activation_key|user_email|user_login|user_registered|user_status)\\\\}~i"}], "cve": "CVE-2025-12010", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12010", "description": "Authors List <=2.0.6.1 unauthenticated sensitive information exposure via update_authors_list_ajax AJAX handler", "method": "POST", "mode": "block", "severity": 6.5, "slug": "authors-list", "tags": ["sensitive-information-exposure", "shortcode", "unauthenticated"], "target": "plugin", "versions": "<=2.0.6.1"}, "RULE-CVE-2025-12010-03": {"ajax_action": "authors_list_display_edit_item_preview_ajax", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\{al:\\\\s*(?:user_pass|user_activation_key|user_email|user_login|user_registered|user_status)\\\\}~i"}], "cve": "CVE-2025-12010", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12010", "description": "Authors List <=2.0.6.1 authenticated sensitive information exposure via authors_list_display_edit_item_preview_ajax AJAX handler", "method": "POST", "mode": "block", "severity": 6.5, "slug": "authors-list", "tags": ["sensitive-information-exposure", "shortcode", "authenticated"], "target": "plugin", "versions": "<=2.0.6.1"}, "RULE-CVE-2025-12018-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[fnd]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[fnd] admin setting (attribute context)", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-02": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[rsp]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[rsp] admin setting (attribute context)", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-03": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[mol]", "type": "regex", "value": "~<\\\\s*(?:script|iframe|object|embed|form)|\\\\bon\\\\w+\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*;base64~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[mol] member login message", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-04": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[moe]", "type": "regex", "value": "~<\\\\s*(?:script|iframe|object|embed|form)|\\\\bon\\\\w+\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*;base64~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[moe] membership expired message", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-05": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[mon]", "type": "regex", "value": "~<\\\\s*(?:script|iframe|object|embed|form)|\\\\bon\\\\w+\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*;base64~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[mon] no-access message", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-06": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[moi]", "type": "regex", "value": "~<\\\\s*(?:script|iframe|object|embed|form)|\\\\bon\\\\w+\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*;base64~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[moi] session expired message", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-07": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[org]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[org] data attribute injection", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-08": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[out]", "type": "regex", "value": "~(?:javascript\\\\s*:|\\"\\\\s*(?:on\\\\w+\\\\s*=|>)|<\\\\s*(?:script|img|svg|iframe))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[out] logout redirect URL", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-09": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[top]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[top] data attribute injection", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-10": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[fbk]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[fbk] Facebook App ID attribute injection", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12018-11": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "sf_admin_group"}, {"name": "ARGS:sf_set[map]", "type": "detectXSS"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12018", "description": "MembershipWorks <=6.14 stored XSS via sf_set[map] Google Maps API key attribute injection", "method": "POST", "mode": "block", "severity": 4.4, "slug": "memberfindme", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=6.14"}, "RULE-CVE-2025-12021-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~wp-login\\\\.php~"}, {"name": "ARGS:error_description", "type": "detectXSS"}], "cve": "CVE-2025-12021", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12021", "description": "WP-OAuth <=0.4.1 Reflected XSS via error_description parameter on wp-login.php", "method": "GET", "mode": "block", "severity": 6.1, "slug": "wp-oauth", "tags": ["xss", "reflected-xss", "unauthenticated"], "target": "plugin", "versions": "<=0.4.1"}, "RULE-CVE-2025-12021-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~login-google\\\\.php~"}, {"name": "ARGS:error_description", "type": "detectXSS"}], "cve": "CVE-2025-12021", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12021", "description": "WP-OAuth <=0.4.1 Reflected XSS via error_description parameter on login-google.php", "method": "GET", "mode": "block", "severity": 6.1, "slug": "wp-oauth", "tags": ["xss", "reflected-xss", "unauthenticated"], "target": "plugin", "versions": "<=0.4.1"}, "RULE-CVE-2025-12025-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:sm_ytcs_option[sm_ytcs_title]", "type": "regex", "value": "~(?:]|on(?:load|error|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]|]|]|])~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12025", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12025", "description": "YouTube Subscribe <=3.0.0 Authenticated (Admin+) Stored XSS via title setting", "method": "POST", "mode": "block", "severity": 4.4, "slug": "easy-youtube-subscribe", "tags": ["xss", "stored-xss", "settings-api"], "target": "plugin", "versions": "<=3.0.0"}, "RULE-CVE-2025-12025-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:sm_ytcs_option[sm_youtube_channel_id]", "type": "regex", "value": "~(?:]|on(?:load|error|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]|]|]|]|\\"|\')~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-12025", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12025", "description": "YouTube Subscribe <=3.0.0 Authenticated (Admin+) Stored XSS via channel ID setting", "method": "POST", "mode": "block", "severity": 4.4, "slug": "easy-youtube-subscribe", "tags": ["xss", "stored-xss", "settings-api"], "target": "plugin", "versions": "<=3.0.0"}, "RULE-CVE-2025-12028-01": {"action": "login_form_indieauth", "conditions": [{"name": "ARGS:client_id", "type": "regex", "value": "~^https?://~i"}, {"name": "ARGS:redirect_uri", "type": "regex", "value": "~^https?://~i"}], "cve": "CVE-2025-12028", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12028", "description": "IndieAuth <=4.5.4 CSRF on OAuth authorization POST confirmation via wp-login.php?action=indieauth", "method": "POST", "mode": "block", "severity": 8.8, "slug": "indieauth", "tags": ["csrf", "account-takeover", "oauth", "unauthenticated"], "target": "plugin", "versions": "<=4.5.4"}, "RULE-CVE-2025-12028-02": {"action": "login_form_indieauth", "conditions": [{"name": "ARGS:client_id", "type": "regex", "value": "~^https?://~i"}, {"name": "ARGS:redirect_uri", "type": "regex", "value": "~^https?://~i"}], "cve": "CVE-2025-12028", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12028", "description": "IndieAuth <=4.5.4 CSRF on OAuth authorization GET initiation via wp-login.php?action=indieauth", "method": "GET", "mode": "block", "severity": 8.8, "slug": "indieauth", "tags": ["csrf", "account-takeover", "oauth", "unauthenticated"], "target": "plugin", "versions": "<=4.5.4"}, "RULE-CVE-2025-12028-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-json/indieauth/1\\\\.0/auth(?:/|\\\\?|$)~"}, {"name": "ARGS:client_id", "type": "regex", "value": "~^https?://~i"}, {"name": "ARGS:redirect_uri", "type": "regex", "value": "~^https?://~i"}], "cve": "CVE-2025-12028", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12028", "description": "IndieAuth <=4.5.4 CSRF via REST auth endpoint missing PKCE requirements (/indieauth/1.0/auth)", "method": "GET", "mode": "block", "severity": 8.8, "slug": "indieauth", "tags": ["csrf", "account-takeover", "oauth", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=4.5.4"}, "RULE-CVE-2025-12028-04": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/indieauth/1\\\\.0/auth(?:/|$)~"}, {"name": "ARGS:client_id", "type": "regex", "value": "~^https?://~i"}, {"name": "ARGS:redirect_uri", "type": "regex", "value": "~^https?://~i"}], "cve": "CVE-2025-12028", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12028", "description": "IndieAuth <=4.5.4 CSRF via REST auth endpoint missing PKCE requirements (rest_route=/indieauth/1.0/auth)", "method": "GET", "mode": "block", "severity": 8.8, "slug": "indieauth", "tags": ["csrf", "account-takeover", "oauth", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=4.5.4"}, "RULE-CVE-2025-12032-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:vithanhlam_zsocial_save_messager", "type": "detectXSS"}], "cve": "CVE-2025-12032", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12032", "description": "Zweb Social Mobile <=1.0.0 stored XSS via unsanitized messager setting", "method": "POST", "mode": "block", "severity": 4.4, "slug": "zweb-social-mobile", "tags": ["xss", "stored-xss", "settings-api"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2025-12032-02": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:vithanhlam_zsocial_save_zalo", "type": "detectXSS"}], "cve": "CVE-2025-12032", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12032", "description": "Zweb Social Mobile <=1.0.0 stored XSS via unsanitized zalo setting", "method": "POST", "mode": "block", "severity": 4.4, "slug": "zweb-social-mobile", "tags": ["xss", "stored-xss", "settings-api"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2025-12032-03": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:vithanhlam_zsocial_save_hotline", "type": "detectXSS"}], "cve": "CVE-2025-12032", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12032", "description": "Zweb Social Mobile <=1.0.0 stored XSS via unsanitized hotline setting", "method": "POST", "mode": "block", "severity": 4.4, "slug": "zweb-social-mobile", "tags": ["xss", "stored-xss", "settings-api"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2025-12032-04": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php~"}, {"name": "ARGS:vithanhlam_zsocial_save_contact", "type": "detectXSS"}], "cve": "CVE-2025-12032", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12032", "description": "Zweb Social Mobile <=1.0.0 stored XSS via unsanitized contact setting", "method": "POST", "mode": "block", "severity": 4.4, "slug": "zweb-social-mobile", "tags": ["xss", "stored-xss", "settings-api"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2025-12034-01": {"action": "admin_init", "conditions": [{"name": "ARGS:fvm_settings[cdn][domain]", "type": "regex", "value": "~[\\"\'<>]~"}], "cve": "CVE-2025-12034", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12034", "description": "Fast Velocity Minify <=3.5.1 Stored XSS via CDN domain settings field (domain key)", "method": "POST", "mode": "block", "severity": 4.4, "slug": "fast-velocity-minify", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=3.5.1"}, "RULE-CVE-2025-12034-02": {"action": "admin_init", "conditions": [{"name": "ARGS:fvm_settings[cdn][url]", "type": "regex", "value": "~[\\"\'<>]~"}], "cve": "CVE-2025-12034", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12034", "description": "Fast Velocity Minify <=3.5.1 Stored XSS via CDN url settings field (legacy url key)", "method": "POST", "mode": "block", "severity": 4.4, "slug": "fast-velocity-minify", "tags": ["xss", "stored-xss", "admin-settings"], "target": "plugin", "versions": "<=3.5.1"}, "RULE-CVE-2025-12042-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[/\\\\\\\\]course-booking-system[/\\\\\\\\](includes[/\\\\\\\\])?csv-export\\\\.php([?#]|$)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-12042", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12042", "description": "Course Booking System <=6.1.5 unauthenticated booking data export via direct access to csv-export.php", "method": "GET", "mode": "block", "severity": 5.3, "slug": "course-booking-system", "tags": ["missing-authorization", "information-disclosure", "unauthenticated"], "target": "plugin", "versions": "<=6.1.5"}, "RULE-CVE-2025-12045-01": {"ajax_action": "add-tag", "conditions": [{"name": "ARGS:tag-name", "type": "detectXSS"}], "cve": "CVE-2025-12045", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12045", "description": "Orbit Fox Companion <=3.0.2 Stored XSS via taxonomy term name in add-tag AJAX handler", "method": "POST", "mode": "block", "severity": 6.4, "slug": "themeisle-companion", "tags": ["xss", "stored-xss", "taxonomy"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2025-12045-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/tags(/|\\\\?|&|$)~"}, {"name": "ARGS:name", "type": "detectXSS"}], "cve": "CVE-2025-12045", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12045", "description": "Orbit Fox Companion <=3.0.2 Stored XSS via tag name through REST /wp/v2/tags endpoint", "method": "POST", "mode": "block", "severity": 6.4, "slug": "themeisle-companion", "tags": ["xss", "stored-xss", "rest-api", "taxonomy"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2025-12045-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/categories(/|\\\\?|&|$)~"}, {"name": "ARGS:name", "type": "detectXSS"}], "cve": "CVE-2025-12045", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12045", "description": "Orbit Fox Companion <=3.0.2 Stored XSS via category name through REST /wp/v2/categories endpoint", "method": "POST", "mode": "block", "severity": 6.4, "slug": "themeisle-companion", "tags": ["xss", "stored-xss", "rest-api", "taxonomy"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2025-12062-01": {"ajax_action": "core_templates", "conditions": [{"name": "ARGS:template_name", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}~"}], "cve": "CVE-2025-12062", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12062", "description": "WP Maps plugin <=4.8.6 Local File Inclusion via template_name parameter in core_templates AJAX handler", "method": "POST", "mode": "block", "severity": 8.8, "slug": "wp-google-map-plugin", "tags": ["local-file-inclusion", "path-traversal", "authenticated"], "target": "plugin", "versions": "<=4.8.6"}, "RULE-CVE-2025-12062-02": {"ajax_action": "core_templates", "conditions": [{"name": "ARGS:template_type", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}~"}], "cve": "CVE-2025-12062", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12062", "description": "WP Maps plugin <=4.8.6 Local File Inclusion via template_type parameter in core_templates AJAX handler", "method": "POST", "mode": "block", "severity": 8.8, "slug": "wp-google-map-plugin", "tags": ["local-file-inclusion", "path-traversal", "authenticated"], "target": "plugin", "versions": "<=4.8.6"}, "RULE-CVE-2025-12064-01": {"ajax_action": "xyz_fbap_del_entries", "conditions": [{"name": "ARGS:xyzscripts_user_hash", "type": "detectXSS"}], "cve": "CVE-2025-12064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12064", "description": "WP2Social Auto Publish <=2.4.7 Reflected XSS via xyzscripts_user_hash in xyz_fbap_del_entries AJAX handler", "method": "POST", "mode": "block", "severity": 6.1, "slug": "facebook-auto-publish", "tags": ["xss", "reflected-xss", "authenticated"], "target": "plugin", "versions": "<=2.4.7"}, "RULE-CVE-2025-12064-02": {"ajax_action": "xyz_fbap_del_fb_entries", "conditions": [{"name": "ARGS:xyzscripts_user_hash", "type": "detectXSS"}], "cve": "CVE-2025-12064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12064", "description": "WP2Social Auto Publish <=2.4.7 Reflected XSS via xyzscripts_user_hash in xyz_fbap_del_fb_entries AJAX handler", "method": "POST", "mode": "block", "severity": 6.1, "slug": "facebook-auto-publish", "tags": ["xss", "reflected-xss", "authenticated"], "target": "plugin", "versions": "<=2.4.7"}, "RULE-CVE-2025-12066-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_type", "type": "equals", "value": "wpedpcampaign"}, {"name": "ARGS", "type": "regex", "value": "~<[^>]*(?:on\\\\w+\\\\s*=|(?:src|href|action)\\\\s*=\\\\s*[\\"\']?javascript:|xmlns)|<\\\\s*(?:script|iframe|object|embed|svg|math)~i"}], "cve": "CVE-2025-12066", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12066", "description": "WP Delete Post Copies <=6.0.2 stored XSS via campaign meta box fields on save_post", "method": "POST", "mode": "block", "severity": 4.4, "slug": "etruel-del-post-copies", "tags": ["xss", "stored-xss", "admin-plus"], "target": "plugin", "versions": "<=6.0.2"}, "RULE-CVE-2025-12067-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS", "type": "regex", "value": "~\\"c\\"\\\\s*:\\\\s*\\".*(?:]*>|on[a-zA-Z]{3,} *=~i"}], "cve": "CVE-2025-12371", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12371", "description": "Nari Accountant <=1.0.12 Authenticated (Editor+) Stored XSS via account save action", "method": "POST", "mode": "block", "severity": 4.4, "slug": "nari-accountant", "tags": ["xss", "stored-xss", "authenticated"], "target": "plugin", "versions": "<=1.0.12"}, "RULE-CVE-2025-12371-02": {"ajax_action": "nari100", "conditions": [{"name": "ARGS:by", "type": "detectXSS"}], "cve": "CVE-2025-12371", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12371", "description": "Nari Accountant <=1.0.12 Authenticated (Editor+) Reflected XSS via by parameter", "mode": "block", "severity": 4.4, "slug": "nari-accountant", "tags": ["xss", "reflected-xss", "authenticated"], "target": "plugin", "versions": "<=1.0.12"}, "RULE-CVE-2025-12375-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/printful/v2/advanced-size-chart(/|\\\\?|$)~"}, {"name": "ARGS:url", "type": "regex", "value": "~://(?:localhost|127\\\\.|10\\\\.|0\\\\.|169\\\\.254|172\\\\.(?:1[6-9]|2\\\\d|3[01])|192\\\\.168|\\\\[::1\\\\]|\\\\[0:|0\\\\.0\\\\.0\\\\.0)~i"}], "cve": "CVE-2025-12375", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12375", "description": "Printful Integration for WooCommerce <=2.2.11 authenticated SSRF via advanced size chart REST API endpoint", "method": "GET", "mode": "block", "severity": 6.4, "slug": "printful-shipping-for-woocommerce", "tags": ["ssrf", "rest-api", "authenticated"], "target": "plugin", "versions": "<=2.2.11"}, "RULE-CVE-2025-12376-01": {"ajax_action": "fs_api_request", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "fs_api_request"}, {"name": "ARGS:url", "type": "regex", "value": "~^(?:https?:)?//~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-12376", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12376", "description": "Icon List Block <=1.2.1 authenticated (Subscriber+) SSRF via fs_api_request AJAX handler", "method": "POST", "mode": "block", "severity": 6.4, "slug": "icon-list-block", "tags": ["ssrf", "missing-authorization", "authenticated"], "target": "plugin", "versions": "<=1.2.1"}, "RULE-CVE-2025-12379-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "elementor_ajax"}, {"name": "ARGS:actions", "type": "regex", "value": "~(?:title_tag|title_tag_secondary)(?:\\\\\\\\?[\\"\']\\\\s*:\\\\s*\\\\\\\\?[\\"\'])(?!(?:h[1-6]|div|span|p)\\\\\\\\?[\\"\'])~i"}], "cve": "CVE-2025-12379", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12379", "description": "Auxin Elements <=2.17.13 Stored XSS via Modern Heading widget title_tag/title_tag_secondary in Elementor AJAX save", "method": "POST", "mode": "block", "severity": 6.4, "slug": "auxin-elements", "tags": ["xss", "stored-xss", "elementor-widget"], "target": "plugin", "versions": "<=2.17.13"}, "RULE-CVE-2025-12379-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages)(?:/\\\\d+)?(/|\\\\?|$)~"}, {"name": "ARGS", "type": "regex", "value": "~(?:title_tag|title_tag_secondary)(?:\\\\\\\\?[\\"\']\\\\s*:\\\\s*\\\\\\\\?[\\"\'])(?!(?:h[1-6]|div|span|p)\\\\\\\\?[\\"\'])~i"}], "cve": "CVE-2025-12379", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12379", "description": "Auxin Elements <=2.17.13 Stored XSS via Modern Heading widget title_tag/title_tag_secondary in REST API post save", "method": "POST", "mode": "block", "severity": 6.4, "slug": "auxin-elements", "tags": ["xss", "stored-xss", "elementor-widget", "rest-api"], "target": "plugin", "versions": "<=2.17.13"}, "RULE-CVE-2025-12384-01": {"ajax_action": "bplde_save_document_library", "conditions": [{"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2025-12384", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12384", "description": "Document Embedder <=2.0.0 unauthenticated document creation/update via bplde_save_document_library AJAX action", "method": "POST", "mode": "block", "severity": 8.6, "slug": "document-emberdder", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<=2.0.0"}, "RULE-CVE-2025-12384-02": {"ajax_action": "bplde_get_all", "conditions": [{"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2025-12384", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12384", "description": "Document Embedder <=2.0.0 unauthenticated document listing via bplde_get_all AJAX action", "method": "POST", "mode": "block", "severity": 8.6, "slug": "document-emberdder", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<=2.0.0"}, "RULE-CVE-2025-12384-03": {"ajax_action": "bplde_get_single", "conditions": [{"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2025-12384", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12384", "description": "Document Embedder <=2.0.0 unauthenticated document read via bplde_get_single AJAX action", "method": "POST", "mode": "block", "severity": 8.6, "slug": "document-emberdder", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<=2.0.0"}, "RULE-CVE-2025-12384-04": {"ajax_action": "bplde_delete_document_library", "conditions": [{"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2025-12384", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12384", "description": "Document Embedder <=2.0.0 unauthenticated document deletion via bplde_delete_document_library AJAX action", "method": "POST", "mode": "block", "severity": 8.6, "slug": "document-emberdder", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<=2.0.0"}, "RULE-CVE-2025-12388-01": {"ajax_action": "bicbPipeChecker", "conditions": [{"name": "ARGS:url", "type": "regex", "value": "~(?:^https?://(?:127\\\\.|10\\\\.|172\\\\.(?:1[6-9]|2\\\\d|3[01])\\\\.|192\\\\.168\\\\.|0\\\\.|localhost|0x7f000001|2130706433|\\\\[::1\\\\]|\\\\[::ffff:|169\\\\.254\\\\.)|\\\\.internal[/:\\\\s]|^(?!https?://).+://)~i"}], "cve": "CVE-2025-12388", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12388", "description": "B Carousel Block <=1.1.5 authenticated (Subscriber+) SSRF via bicbPipeChecker AJAX handler", "method": "POST", "mode": "block", "severity": 6.4, "slug": "b-carousel-block", "tags": ["ssrf", "missing-authorization", "server-side-request-forgery"], "target": "plugin", "versions": "<=1.1.5"}, "RULE-CVE-2025-12392-01": {"action": "admin_post_nopriv_handle_optin_optout", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "handle_optin_optout"}], "cve": "CVE-2025-12392", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12392", "description": "TripleA Cryptocurrency Payment Gateway for WooCommerce <=2.0.25 missing authorization on handle_optin_optout allows unauthenticated tracking status update", "mode": "block", "severity": 5.3, "slug": "triplea-cryptocurrency-payment-gateway-for-woocommerce", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=2.0.25"}, "RULE-CVE-2025-12392-02": {"action": "admin_post_handle_optin_optout", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "handle_optin_optout"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-12392", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12392", "description": "TripleA Cryptocurrency Payment Gateway for WooCommerce <=2.0.25 missing authorization on handle_optin_optout allows low-privilege tracking status update", "mode": "block", "severity": 5.3, "slug": "triplea-cryptocurrency-payment-gateway-for-woocommerce", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=2.0.25"}, "RULE-CVE-2025-12402-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "linkedinresume.php"}, {"name": "ARGS:update_linkedinresumeSettings", "type": "exists"}, {"name": "ARGS:linkedinId", "type": "detectXSS"}], "cve": "CVE-2025-12402", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-12402", "description": "LinkedIn Resume <=2.00 CSRF to Stored XSS via unsanitized linkedinId parameter in admin settings", "method": "POST", "mode": "block", "severity": 6.1, "slug": "linkedin-resume", "tags": ["csrf", "xss", "stored-xss"], "target": "plugin", "versions": "<=2.00"}, "RULE-CVE-2025-12402-02": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "linkedinresume.php"}, {"name": "REQUEST_URI", "type": "regex", "value": "~])~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2025-5929", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5929", "description": "The Countdown <=2.0.1 Stored XSS via clientId block attribute in classic editor post save", "method": "POST", "mode": "block", "severity": 5.4, "slug": "the-countdown", "tags": ["xss", "stored-xss", "gutenberg-block"], "target": "plugin", "versions": "<=2.0.0"}, "RULE-CVE-2025-5950-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~indieblocks/facepile-content\\\\s[^>]*\\"type\\"\\\\s*:\\\\s*\\\\[\\\\s*\\"(?!(?:bookmark|like|repost)\\"\\\\s*[\\\\],])~i"}], "cve": "CVE-2025-5950", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5950", "description": "IndieBlocks <=0.13.2 Stored XSS via Facepile Content block kind parameter on REST API post creation", "method": "POST", "mode": "block", "severity": 5.4, "slug": "indieblocks", "tags": ["xss", "stored-xss", "gutenberg-block"], "target": "plugin", "versions": "<=0.13.2"}, "RULE-CVE-2025-5950-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts/\\\\d+(?:/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~indieblocks/facepile-content\\\\s[^>]*\\"type\\"\\\\s*:\\\\s*\\\\[\\\\s*\\"(?!(?:bookmark|like|repost)\\"\\\\s*[\\\\],])~i"}], "cve": "CVE-2025-5950", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5950", "description": "IndieBlocks <=0.13.2 Stored XSS via Facepile Content block kind parameter on REST API post update", "method": "PUT", "mode": "block", "severity": 5.4, "slug": "indieblocks", "tags": ["xss", "stored-xss", "gutenberg-block"], "target": "plugin", "versions": "<=0.13.2"}, "RULE-CVE-2025-5950-03": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:content", "type": "regex", "value": "~indieblocks/facepile-content\\\\s[^>]*\\"type\\"\\\\s*:\\\\s*\\\\[\\\\s*\\"(?!(?:bookmark|like|repost)\\"\\\\s*[\\\\],])~i"}], "cve": "CVE-2025-5950", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5950", "description": "IndieBlocks <=0.13.2 Stored XSS via Facepile Content block kind parameter on classic editor post save", "method": "POST", "mode": "block", "severity": 5.4, "slug": "indieblocks", "tags": ["xss", "stored-xss", "gutenberg-block"], "target": "plugin", "versions": "<=0.13.2"}, "RULE-CVE-2025-5953-01": {"ajax_action": "hrm_insert_employee", "conditions": [{"name": "ARGS:role", "type": "regex", "value": "~^(administrator|editor|author|contributor)$~i"}, {"type": "missing_capability", "value": "promote_users"}], "cve": "CVE-2025-5953", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5953", "description": "WP Human Resource Management <=2.2.17 missing authorization on hrm_insert_employee allows authenticated privilege escalation via role parameter", "method": "POST", "mode": "block", "severity": 8.8, "slug": "hrm", "tags": ["missing-authorization", "privilege-escalation"], "target": "plugin", "versions": "<=2.2.17"}, "RULE-CVE-2025-5957-01": {"ajax_action": "guest_support_handler", "conditions": [{"name": "ARGS:request", "type": "equals", "value": "delete_tickets"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-5957", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5957", "description": "Guest Support <=1.2.2 missing authorization on mass ticket deletion via guest_support_handler AJAX endpoint", "method": "POST", "mode": "block", "severity": 5.3, "slug": "guest-support", "tags": ["missing-authorization", "unauthenticated", "data-loss"], "target": "plugin", "versions": "<=1.2.2"}, "RULE-CVE-2025-5961-01": {"ajax_action": "wpvivid_upload_import_files", "conditions": [{"name": "ARGS:name", "type": "regex", "value": "~\\\\.(?:php\\\\d*|phtml|phar|shtml|cgi|asp|aspx|jsp|jspx)(?:\\\\x00|%00|$)~i"}], "cve": "CVE-2025-5961", "method": "POST", "mode": "block", "severity": 7.2, "slug": "wpvivid-backuprestore", "target": "plugin", "versions": "<=0.9.116"}, "RULE-CVE-2025-5983-01": {"action": "admin_init", "conditions": [{"name": "ARGS:mtm_meta[type]", "type": "equals", "value": "http-equiv"}, {"name": "ARGS:mtm_meta[value]", "type": "equals", "value": "refresh"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-5983", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-5983", "description": "Meta Tag Manager <3.3 Contributor+ open redirect via http-equiv refresh meta tag injection on post save", "method": "POST", "mode": "block", "severity": 6.5, "slug": "meta-tag-manager", "tags": ["open-redirect", "missing-authorization", "meta-refresh"], "target": "plugin", "versions": "<3.3"}, "RULE-CVE-2025-60041-01": {"ajax_action": "secas_navigate_to_page", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2025-60041", "mode": "block", "severity": 8.8, "slug": "emails-catch-all", "target": "plugin", "versions": "<=3.5.3"}, "RULE-CVE-2025-60042-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60042", "description": "chinchilla theme <= 1.16 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "chinchilla", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.16"}, "RULE-CVE-2025-60042-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60042", "description": "chinchilla theme <= 1.16 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "chinchilla", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.16"}, "RULE-CVE-2025-60043-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60043", "description": "wanderic theme <= 1.0.10 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "wanderic", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.10"}, "RULE-CVE-2025-60043-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60043", "description": "wanderic theme <= 1.0.10 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "wanderic", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.10"}, "RULE-CVE-2025-60044-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60044", "description": "fribbo theme <= 1.1.0 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "fribbo", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.1.0"}, "RULE-CVE-2025-60044-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60044", "description": "fribbo theme <= 1.1.0 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "fribbo", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.1.0"}, "RULE-CVE-2025-60046-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60046", "description": "heartstar theme <= 1.0.14 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "heartstar", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.14"}, "RULE-CVE-2025-60046-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60046", "description": "heartstar theme <= 1.0.14 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "heartstar", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.14"}, "RULE-CVE-2025-60047-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60047", "description": "ipharm theme <= 1.2.3 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "ipharm", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.2.3"}, "RULE-CVE-2025-60047-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60047", "description": "ipharm theme <= 1.2.3 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "ipharm", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.2.3"}, "RULE-CVE-2025-60048-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60048", "description": "tripster theme <= 1.0.10 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "tripster", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.10"}, "RULE-CVE-2025-60048-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60048", "description": "tripster theme <= 1.0.10 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "tripster", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.10"}, "RULE-CVE-2025-60049-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60049", "description": "soleil theme <= 1.17 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "soleil", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.17"}, "RULE-CVE-2025-60049-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60049", "description": "soleil theme <= 1.17 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "soleil", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.17"}, "RULE-CVE-2025-60050-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60050", "description": "panda theme <= 1.21 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "panda", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.21"}, "RULE-CVE-2025-60050-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60050", "description": "panda theme <= 1.21 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "panda", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.21"}, "RULE-CVE-2025-60051-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60051", "description": "rareradio theme <= 1.0.15.1 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "rareradio", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.15.1"}, "RULE-CVE-2025-60051-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60051", "description": "rareradio theme <= 1.0.15.1 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "rareradio", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.15.1"}, "RULE-CVE-2025-60052-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60052", "description": "wd theme <= 1.0 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "wd", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0"}, "RULE-CVE-2025-60052-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60052", "description": "wd theme <= 1.0 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "wd", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0"}, "RULE-CVE-2025-60053-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60053", "description": "maxcube theme <= 1.3.1 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "maxcube", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.3.1"}, "RULE-CVE-2025-60053-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60053", "description": "maxcube theme <= 1.3.1 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "maxcube", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.3.1"}, "RULE-CVE-2025-60054-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60054", "description": "onleash theme <= 1.5.2 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "onleash", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.5.2"}, "RULE-CVE-2025-60054-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60054", "description": "onleash theme <= 1.5.2 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "onleash", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.5.2"}, "RULE-CVE-2025-60055-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60055", "description": "fabrica theme <= 1.8.1 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "fabrica", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.8.1"}, "RULE-CVE-2025-60055-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60055", "description": "fabrica theme <= 1.8.1 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "fabrica", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.8.1"}, "RULE-CVE-2025-60056-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60056", "description": "winger theme <= 1.0.16 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "winger", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.16"}, "RULE-CVE-2025-60056-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60056", "description": "winger theme <= 1.0.16 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "winger", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.16"}, "RULE-CVE-2025-60057-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60057", "description": "dj-rainflow theme <= 1.3.13 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "dj-rainflow", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.3.13"}, "RULE-CVE-2025-60057-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60057", "description": "dj-rainflow theme <= 1.3.13 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "dj-rainflow", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.3.13"}, "RULE-CVE-2025-60058-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file|data)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60058", "description": "detailx theme <= 1.10.0 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "detailx", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.10.0"}, "RULE-CVE-2025-60058-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60058", "description": "detailx theme <= 1.10.0 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "detailx", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.10.0"}, "RULE-CVE-2025-60060-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60060", "description": "pubzinne theme <= 1.0.12 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "pubzinne", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.12"}, "RULE-CVE-2025-60060-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60060", "description": "pubzinne theme <= 1.0.12 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "pubzinne", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.12"}, "RULE-CVE-2025-60061-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60061", "description": "kicker theme <= 2.2.0 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "kicker", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=2.2.0"}, "RULE-CVE-2025-60061-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60061", "description": "kicker theme <= 2.2.0 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "kicker", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=2.2.0"}, "RULE-CVE-2025-60063-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60063", "description": "rosalinda theme <= 1.2.3 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "rosalinda", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.2.3"}, "RULE-CVE-2025-60063-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60063", "description": "rosalinda theme <= 1.2.3 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "rosalinda", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.2.3"}, "RULE-CVE-2025-60064-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60064", "description": "renewal theme <= 1.2.2 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "renewal", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.2.2"}, "RULE-CVE-2025-60064-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60064", "description": "renewal theme <= 1.2.2 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "renewal", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.2.2"}, "RULE-CVE-2025-60065-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60065", "description": "pinevale theme <= 1.0.14 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "pinevale", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.14"}, "RULE-CVE-2025-60065-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60065", "description": "pinevale theme <= 1.0.14 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "pinevale", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.14"}, "RULE-CVE-2025-60066-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60066", "description": "katelyn theme <= 1.0.10 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "katelyn", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.0.10"}, "RULE-CVE-2025-60066-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60066", "description": "katelyn theme <= 1.0.10 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "katelyn", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.0.10"}, "RULE-CVE-2025-60067-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:(?:\\\\.\\\\.|%2[eE]%2[eE])(?:[/\\\\\\\\]|%2[fF]|%5[cC])){2,}|(?:php|phar|expect|zip|compress\\\\.zlib|file)://|%70%68%70%3[aA]%2[fF]%2[fF]|(?:^|=)data:[a-zA-Z]~i"}], "cve": "CVE-2025-60067", "description": "giardino theme <= 1.1.10 path traversal and PHP wrapper abuse in template selector parameters. AncoraThemes/axiomthemes trx_addons framework shared LFI pattern.", "mode": "block", "severity": 8.1, "slug": "giardino", "tags": ["lfi", "path-traversal", "generic", "trx_addons"], "target": "theme", "versions": "<=1.1.10"}, "RULE-CVE-2025-60067-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-admin/|/wp-json/|\\\\?)~i"}, {"name": "ARGS:/^(type|layout|template|view|skin|style)$/", "type": "regex", "value": "~(?:wp-config|/etc/passwd|/proc/self/environ|/var/log/|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2025-60067", "description": "giardino theme <= 1.1.10 sensitive file detection in template parameters.", "mode": "block", "severity": 8.1, "slug": "giardino", "tags": ["lfi", "sensitive-file", "defense-in-depth"], "target": "theme", "versions": "<=1.1.10"}, "RULE-CVE-2025-60195-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "wpf_create_account"}, {"name": "ARGS:role", "type": "regex", "value": "~^\\\\s*(?:administrator|editor|author)\\\\s*$~i"}], "cve": "CVE-2025-60195", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-60195", "description": "Atarim Visual Collaboration <=4.2.1 unauthenticated privilege escalation via wpf_create_account AJAX action with attacker-supplied role parameter", "method": "POST", "mode": "block", "severity": 9.8, "slug": "atarim-visual-collaboration", "tags": ["privilege-escalation", "incorrect-privilege-assignment", "unauthenticated"], "target": "plugin", "versions": "<=4.2.1"}, "RULE-CVE-2025-60245-01": {"action": "init", "conditions": [{"name": "ARGS:submit_account", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~[OCa]:[0-9]+:[\\"\\\\\\\\{]~"}], "cve": "CVE-2025-60245", "description": "WP User Manager <=2.9.12 authenticated PHP object injection via account form deserialization", "mode": "block", "severity": 9.8, "slug": "wp-user-manager", "target": "plugin", "versions": "<=2.9.12"}, "RULE-CVE-2025-6025-01": {"ajax_action": "apply_tip", "conditions": [{"name": "ARGS:tip", "type": "regex", "value": "~^\\\\s*-~"}], "cve": "CVE-2025-6025", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2025-6025", "description": "Order Tip for WooCommerce <=1.5.4 unauthenticated negative tip manipulation via apply_tip AJAX action", "method": "POST", "mode": "block", "severity": 7.5, "slug": "order-tip-woo", "tags": ["improper-input-validation", "business-logic", "unauthenticated"], "target": "plugin", "versions": "<=1.5.4"}, "RULE-CVE-2025-6068-01": {"ajax_action": "foogallery_attachment_modal_save", "conditions": [{"name": "ARGS:foogallery", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_cache_timeout settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-04": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_api_timeout", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_api_timeout settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-05": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_grace_period_timeout", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_grace_period_timeout settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-06": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_google_ads_id", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_google_ads_id settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-07": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_google_tagmanager_id", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_google_tagmanager_id settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-08": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_special_render_options", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_special_render_options settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-09": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_branding", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_branding settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-10": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_alternate_subscription_page", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_alternate_subscription_page settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-11": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_redirect_page", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_redirect_page settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-12": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_detail_pagename", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_detail_pagename settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1071-13": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:option_page", "type": "regex", "value": "~^carta-online(?:\\\\b|$)~i"}, {"name": "ARGS:co_detail_redirect_name", "type": "regex", "value": "~(?:|<[^>]+\\\\bon[a-z]{3,}\\\\s*=\\\\s*(?:\\"[^\\"]+\\"|\'[^\']+\'|[^\\\\s>]+)|javascript\\\\s*:[^\\\\s\\"\'<>]+)~i"}], "cve": "CVE-2026-1071", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1071", "description": "Carta Online <=2.13.0 authenticated stored XSS via co_detail_redirect_name settings field", "method": "POST", "mode": "block", "severity": 4.4, "slug": "carta-online", "tags": ["xss", "stored", "authenticated", "settings-api"], "target": "plugin", "versions": "<=2.13.0"}, "RULE-CVE-2026-1072-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/options(?:-general)?\\\\.php~"}, {"name": "ARGS:option_page", "type": "equals", "value": "keybaseverif"}, {"name": "ARGS:keybaseverif_text", "type": "regex", "value": "~(?:)[^\'\\"]*[\'\\"]~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-1187", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1187", "description": "ZoomifyWP Free <=1.1 Contributor+ Stored XSS via zoomify shortcode filename attribute in post content", "method": "POST", "mode": "block", "severity": 6.4, "slug": "tz-zoomifywp-free", "tags": ["xss", "stored", "shortcode", "authenticated"], "target": "plugin", "versions": "<=1.1"}, "RULE-CVE-2026-11911-01": {"ajax_action": "simplefilelist_edit_job", "conditions": [{"name": "ARGS:eeSubFolder", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]|%2[Ee]%2[Ee][\\\\\\\\/]|%2[Ee]%2[Ee]%2[Ff]|%252[Ee]%252[Ee])~i"}], "cve": "CVE-2026-11911", "description": "Simple File List <=6.3.7 unauthenticated arbitrary file deletion via path traversal in eeSubFolder parameter", "mode": "block", "severity": 7.5, "slug": "simple-file-list", "target": "plugin", "versions": "<=6.3.7"}, "RULE-CVE-2026-11911-02": {"ajax_action": "simplefilelist_edit_job", "conditions": [{"name": "ARGS:eeFileName", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]|%2[Ee]%2[Ee][\\\\\\\\/]|%2[Ee]%2[Ee]%2[Ff]|%252[Ee]%252[Ee])~i"}], "cve": "CVE-2026-11911", "description": "Simple File List <=6.3.7 unauthenticated arbitrary file deletion via path traversal in eeFileName parameter", "mode": "block", "severity": 7.5, "slug": "simple-file-list", "target": "plugin", "versions": "<=6.3.7"}, "RULE-CVE-2026-11961-01": {"action": "init", "conditions": [{"name": "ARGS:member_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2026-11961", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11961", "description": "User Registration & Membership <5.2.3 unauthorized user deletion via member_id in membership AJAX cleanup path", "mode": "block", "severity": 8.1, "slug": "user-registration", "tags": ["privilege-escalation", "missing-authorization", "unauthenticated"], "target": "plugin", "versions": "<5.2.3"}, "RULE-CVE-2026-11962-01": {"ajax_action": "fileorganizer_file_folder_manager", "conditions": [{"name": "ARGS:cmd", "type": "regex", "value": "~^(?:mkfile|rename)$~"}, {"name": "ARGS", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp(?:x)?|jsp(?:x)?|cfm)(?:$|[\\"\'\\\\s&])|(?:^|[/\\\\\\\\])\\\\.htaccess(?:$|[\\"\'\\\\s&]))~i"}, {"type": "missing_capability", "value": "activate_plugins"}], "cve": "CVE-2026-11962", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11962", "description": "FileOrganizer <1.2.0 authenticated arbitrary executable file creation through elFinder", "mode": "block", "severity": 8.8, "slug": "fileorganizer", "tags": ["unrestricted-file-upload", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<1.2.0"}, "RULE-CVE-2026-11962-02": {"ajax_action": "fileorganizer_file_folder_manager", "conditions": [{"name": "ARGS:cmd", "type": "equals", "value": "put"}, {"name": "ARGS:content", "type": "regex", "value": "~<\\\\?(?:php\\\\b|=|[\\\\t\\\\r\\\\n ])~i"}, {"type": "missing_capability", "value": "activate_plugins"}], "cve": "CVE-2026-11962", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11962", "description": "FileOrganizer <1.2.0 authenticated PHP content write through elFinder", "mode": "block", "severity": 8.8, "slug": "fileorganizer", "tags": ["unrestricted-file-upload", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<1.2.0"}, "RULE-CVE-2026-11962-03": {"ajax_action": "fileorganizer_file_folder_manager", "conditions": [{"name": "ARGS:cmd", "type": "equals", "value": "extract"}, {"type": "missing_capability", "value": "activate_plugins"}], "cve": "CVE-2026-11962", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11962", "description": "FileOrganizer <1.2.0 unsafe archive extraction through elFinder", "mode": "block", "severity": 8.8, "slug": "fileorganizer", "tags": ["unrestricted-file-upload", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<1.2.0"}, "RULE-CVE-2026-11962-04": {"ajax_action": "fileorganizer_file_folder_manager", "conditions": [{"name": "ARGS:cmd", "type": "equals", "value": "put"}, {"name": "ARGS:encoding", "type": "regex", "value": "~^(?:scheme|hash)$~"}, {"type": "missing_capability", "value": "activate_plugins"}], "cve": "CVE-2026-11962", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11962", "description": "FileOrganizer <1.2.0 encoded content write through elFinder", "mode": "block", "severity": 8.8, "slug": "fileorganizer", "tags": ["unrestricted-file-upload", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<1.2.0"}, "RULE-CVE-2026-11964-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/user-registration/paypal-webhook[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:ur-membership-listener", "type": "exists"}, {"name": "ARGS:ur-membership-return", "type": "exists"}], "cve": "CVE-2026-11964", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11964", "description": "User Registration & Membership <5.2.2 unauthenticated forged PayPal webhook activates paid membership without payment", "mode": "block", "severity": 9.1, "slug": "user-registration", "tags": ["missing-authorization", "authentication-bypass", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<5.2.2"}, "RULE-CVE-2026-11964-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/user-registration/paypal-webhook[\\\\\\\\/]*$~i"}, {"name": "ARGS:ur-membership-listener", "type": "exists"}, {"name": "ARGS:ur-membership-return", "type": "exists"}], "cve": "CVE-2026-11964", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-11964", "description": "User Registration & Membership <5.2.2 unauthenticated forged PayPal webhook activates paid membership without payment", "mode": "block", "severity": 9.1, "slug": "user-registration", "tags": ["missing-authorization", "authentication-bypass", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<5.2.2"}, "RULE-CVE-2026-1206-01": {"ajax_action": "elementor_ajax", "conditions": [{"name": "ARGS:actions", "type": "contains", "value": "get_template_data"}, {"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-1206", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1206", "description": "Elementor <=3.35.7 contributor+ sensitive information disclosure via get_template_data sub-action on elementor_ajax \\u2014 authorization logic bypass (CWE-639) allows reading private/draft templates", "mode": "block", "severity": 4.3, "slug": "elementor", "tags": ["broken-access-control", "information-disclosure", "idor"], "target": "plugin", "versions": "<=3.35.7"}, "RULE-CVE-2026-1210-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:_elementor_data", "type": "regex", "value": "~age[_-]?gate[^}]*(?:desc|footer_text)[^}]*<[^>]*(?:on[a-zA-Z]+=|\\\\s*<(?:script\\\\b|[a-zA-Z]+[^>]*\\\\bon[a-zA-Z]+\\\\s*=)~i"}], "cve": "CVE-2026-16597", "description": "GTM4WP <=1.22.3 unauthenticated stored XSS via WooCommerce guest checkout billing field script-tag breakout rendered unescaped in frontend dataLayer JSON", "mode": "block", "severity": 7.2, "slug": "duracelltomi-google-tag-manager", "target": "plugin", "versions": "<=1.22.3"}, "RULE-CVE-2026-1671-01": {"ajax_action": "winter_activity_log_action", "conditions": [{"type": "missing_capability", "value": "manage_options"}, {"name": "ARGS:page", "type": "regex", "value": "~^(?:wal_favouritelogs|wal_controlsecurity|wal_history|wal_usersessions|wal_reports|wal_logalerts|wal_disabledlogs|wal_cloudintegration|winteractivitylog)$~"}, {"name": "ARGS:function", "type": "regex", "value": "~^(?:datatable|datatable_saved|edit_log|edit_history|control_log|filter_get|filter_save|filter_remove|clear_all_log|bulk_remove)$~"}], "cve": "CVE-2026-1671", "method": "POST", "mode": "block", "severity": 6.5, "slug": "winterlock", "target": "plugin", "versions": "<1.2.9"}, "RULE-CVE-2026-16747-01": {"action": "init", "conditions": [{"name": "ARGS:_kirki_form", "type": "exists"}, {"name": "ARGS:_wpnonce", "type": "exists"}, {"name": "ARGS:/^(replyTo|name|subject|emailList)$/", "type": "regex", "value": "~\\\\[[a-zA-Z][a-zA-Z0-9_-]*(?:\\\\s[^\\\\]]*)?\\\\]~i"}], "cve": "CVE-2026-16747", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-16747", "description": "Kirki <6.2.1 unauthenticated shortcode injection via front-end form submission fields leading to admin email disclosure and mail relay", "mode": "block", "severity": 6.5, "slug": "kirki", "tags": ["missing-authorization", "shortcode-injection", "unauthenticated"], "target": "plugin", "versions": "<6.2.1"}, "RULE-CVE-2026-1675-01": {"action": "init", "conditions": [{"name": "ARGS:OpenSesame", "type": "regex", "value": "~^0*1$~"}], "cve": "CVE-2026-1675", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-1675", "description": "Advanced Country Blocker <=2.3.1 unauthenticated authorization bypass via insecure default secret key", "mode": "block", "severity": 5.3, "slug": "advanced-country-blocker", "tags": ["authorization-bypass", "insecure-default", "unauthenticated"], "target": "plugin", "versions": "<=2.3.1"}, "RULE-CVE-2026-16775-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~i"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[custom-facebook-feed\\\\b.{0,200}?(?:]*(?:0*(?:34|39|60|62)|x0*(?:22|27|3c|3e));~i"}], "cve": "CVE-2026-18978", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-18978", "description": "LiteSpeed Cache <=7.8.1 unauthenticated stored XSS via numeric-entity (decimal or hex) encoded data-settings payload in comment content", "mode": "block", "severity": 7.2, "slug": "litespeed-cache", "tags": ["xss", "stored-xss", "unauthenticated", "comment-content"], "target": "plugin", "versions": "<=7.8.1"}, "RULE-CVE-2026-18983-01": {"action": "personal_options_update", "conditions": [{"name": "FILES:wpua-file", "type": "exists"}, {"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2026-18983", "description": "One User Avatar <=2.5.4 missing upload_files capability check on personal_options_update avatar upload branch", "mode": "block", "severity": 7.5, "slug": "one-user-avatar", "target": "plugin", "versions": "<=2.5.4"}, "RULE-CVE-2026-18983-02": {"action": "personal_options_update", "conditions": [{"name": "FILES:wpua-file", "type": "exists"}, {"name": "FILES:wpua-file:name", "type": "regex", "value": "~^(?!.*\\\\.(?:jpe?g|gif|png|webp|avif|heic)$).*$~i"}], "cve": "CVE-2026-18983", "description": "One User Avatar <=2.5.4 unrestricted file upload via MIME type bypass in wpua_action_process_option_update (personal_options_update) allowing non-image extensions such as dxfp", "mode": "block", "severity": 7.5, "slug": "one-user-avatar", "target": "plugin", "versions": "<=2.5.4"}, "RULE-CVE-2026-18983-03": {"action": "edit_user_profile_update", "conditions": [{"name": "FILES:wpua-file", "type": "exists"}, {"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2026-18983", "description": "One User Avatar <=2.5.4 missing upload_files capability check on edit_user_profile_update avatar upload branch", "mode": "block", "severity": 7.5, "slug": "one-user-avatar", "target": "plugin", "versions": "<=2.5.4"}, "RULE-CVE-2026-18983-04": {"action": "edit_user_profile_update", "conditions": [{"name": "FILES:wpua-file", "type": "exists"}, {"name": "FILES:wpua-file:name", "type": "regex", "value": "~^(?!.*\\\\.(?:jpe?g|gif|png|webp|avif|heic)$).*$~i"}], "cve": "CVE-2026-18983", "description": "One User Avatar <=2.5.4 unrestricted file upload via MIME type bypass in wpua_action_process_option_update (edit_user_profile_update) allowing non-image extensions such as dxfp", "mode": "block", "severity": 7.5, "slug": "one-user-avatar", "target": "plugin", "versions": "<=2.5.4"}, "RULE-CVE-2026-1900-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/link-whisper(?:-[a-z0-9-]+)?/v[0-9]+/[a-z0-9_/-]*(?:setting|option|config|update|save)~i"}, {"name": "ARGS:settings.keywords", "type": "regex", "value": "~(?:hacked|injected|evil|malware||javascript\\\\s*:|on[a-z]+\\\\s*=|]*>|]*>)~i"}], "cve": "CVE-2026-27068", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-27068", "description": "Website LLMs.txt <=8.2.6 reflected XSS via llms_generator_settings reflected in admin/admin-page.php hidden input attributes", "mode": "block", "severity": 7.1, "slug": "website-llms-txt", "tags": ["xss", "reflected-xss", "admin-page", "crafted-link"], "target": "plugin", "versions": "<=8.2.6"}, "RULE-CVE-2026-2707-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/weforms/v1/forms/[0-9]+/entries(/|\\\\?|$)~"}, {"name": "ARGS", "type": "regex", "value": "~|<[^>]+\\\\s+on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-2936", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2936", "description": "Visitors Traffic Real Time Statistics <=8.4 reflected XSS via fdt parameter in today_traffic_index AJAX handler", "mode": "block", "severity": 7.2, "slug": "visitors-traffic-real-time-statistics", "tags": ["xss", "reflected", "authenticated", "ajax"], "target": "plugin", "versions": "<=8.4"}, "RULE-CVE-2026-2936-04": {"ajax_action": "visits_time_graph", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)(?:wp-admin/admin-ajax\\\\.php)(?:\\\\?|$)~i"}, {"name": "ARGS:fdt", "type": "regex", "value": "~(?:\\"\\\\s*>|<[^>]+\\\\s+on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-2936", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2936", "description": "Visitors Traffic Real Time Statistics <=8.4 reflected XSS via fdt parameter in visits_time_graph AJAX handler", "mode": "block", "severity": 7.2, "slug": "visitors-traffic-real-time-statistics", "tags": ["xss", "reflected", "authenticated", "ajax"], "target": "plugin", "versions": "<=8.4"}, "RULE-CVE-2026-2941-01": {"ajax_action": "linksy_search_and_replace_item_details", "conditions": [{"name": "ARGS:option", "type": "equals", "value": "set"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-2941", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2941", "description": "Linksy Search and Replace <=1.0.4 missing authorization on linksy_search_and_replace_item_details allowing subscriber+ arbitrary database update", "method": "POST", "mode": "block", "severity": 8.8, "slug": "linksy-search-and-replace", "tags": ["missing-authorization", "privilege-escalation", "arbitrary-db-update"], "target": "plugin", "versions": "<=1.0.4"}, "RULE-CVE-2026-2941-02": {"ajax_action": "linksy_search_and_replace_replace_db", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-2941", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2941", "description": "Linksy Search and Replace <=1.0.4 missing authorization on linksy_search_and_replace_replace_db allowing subscriber+ bulk arbitrary database update", "method": "POST", "mode": "block", "severity": 8.8, "slug": "linksy-search-and-replace", "tags": ["missing-authorization", "privilege-escalation", "arbitrary-db-update"], "target": "plugin", "versions": "<=1.0.4"}, "RULE-CVE-2026-2941-03": {"ajax_action": "linksy_search_and_replace_fetch_db_list", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-2941", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2941", "description": "Linksy Search and Replace <=1.0.4 missing authorization on linksy_search_and_replace_fetch_db_list allowing subscriber+ database table enumeration", "method": "POST", "mode": "block", "severity": 8.8, "slug": "linksy-search-and-replace", "tags": ["missing-authorization", "information-disclosure"], "target": "plugin", "versions": "<=1.0.4"}, "RULE-CVE-2026-2942-01": {"ajax_action": "proSol_fileUploadProcess", "conditions": [{"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|(?:^|[\\\\\\\\/])\\\\.ht(?:access|passwd)$~i"}], "cve": "CVE-2026-2942", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2942", "description": "ProSolution WP Client <=1.9.9 unauthenticated arbitrary file upload via proSol_fileUploadProcess AJAX handler", "method": "POST", "mode": "block", "severity": 9.8, "slug": "prosolution-wp-client", "tags": ["arbitrary-file-upload", "remote-code-execution", "unauthenticated"], "target": "plugin", "versions": "<=1.9.9"}, "RULE-CVE-2026-2942-02": {"ajax_action": "proSol_fileUploadModalProcess", "conditions": [{"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|(?:^|[\\\\\\\\/])\\\\.ht(?:access|passwd)$~i"}], "cve": "CVE-2026-2942", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2942", "description": "ProSolution WP Client <=1.9.9 unauthenticated arbitrary file upload via proSol_fileUploadModalProcess AJAX handler", "method": "POST", "mode": "block", "severity": 9.8, "slug": "prosolution-wp-client", "tags": ["arbitrary-file-upload", "remote-code-execution", "unauthenticated"], "target": "plugin", "versions": "<=1.9.9"}, "RULE-CVE-2026-2948-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/gutenverse-client/v2/import/images(?:[/?&]|$)~"}, {"name": "ARGS:imageUrl", "type": "regex", "value": "~^(?:ftp|file|dict|gopher|ssh|smtp|news|telnet|nntp|irc|imap|mongo):|^(?:https?:)?//(?:localhost|127\\\\.0\\\\.0\\\\.1|10\\\\.\\\\d{1,3}\\\\.\\\\d{1,3}\\\\.\\\\d{1,3}|192\\\\.168\\\\.\\\\d{1,3}\\\\.\\\\d{1,3}|172\\\\.(?:1[6-9]|2[0-9]|3[01])\\\\.\\\\d{1,3}\\\\.\\\\d{1,3}|169\\\\.254\\\\.169\\\\.254|0\\\\.0\\\\.0\\\\.0|/|[a-zA-Z]:\\\\\\\\|[a-zA-Z0-9.-]+\\\\.internal)~i"}], "cve": "CVE-2026-2948", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2948", "description": "Gutenverse <=3.5.3 server-side request forgery via imageUrl in import_images REST endpoint", "method": "POST", "mode": "block", "severity": 6.4, "slug": "gutenverse", "tags": ["ssrf", "server-side-request-forgery", "authenticated"], "target": "plugin", "versions": "<=3.5.3"}, "RULE-CVE-2026-2951-01": {"ajax_action": "gutentor_deactivate_block", "conditions": [{"name": "ARGS:block_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}, {"name": "", "type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-2951", "description": "Gutentor <=3.5.5 stored XSS via gutentor_deactivate_block AJAX handler", "mode": "block", "severity": 5.4, "slug": "gutentor", "target": "plugin", "versions": "<=3.5.5"}, "RULE-CVE-2026-2951-02": {"ajax_action": "gutentor_activate_block", "conditions": [{"name": "ARGS:block_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}, {"name": "", "type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-2951", "description": "Gutentor <=3.5.5 stored XSS via gutentor_activate_block AJAX handler", "mode": "block", "severity": 5.4, "slug": "gutentor", "target": "plugin", "versions": "<=3.5.5"}, "RULE-CVE-2026-2951-03": {"ajax_action": "gutentor_bulk_activate_blocks", "conditions": [{"name": "ARGS:block_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}, {"name": "", "type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-2951", "description": "Gutentor <=3.5.5 stored XSS via gutentor_bulk_activate_blocks AJAX handler", "mode": "block", "severity": 5.4, "slug": "gutentor", "target": "plugin", "versions": "<=3.5.5"}, "RULE-CVE-2026-2951-04": {"ajax_action": "gutentor_bulk_deactivate_blocks", "conditions": [{"name": "ARGS:block_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}, {"name": "", "type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-2951", "description": "Gutentor <=3.5.5 stored XSS via gutentor_bulk_deactivate_blocks AJAX handler", "mode": "block", "severity": 5.4, "slug": "gutentor", "target": "plugin", "versions": "<=3.5.5"}, "RULE-CVE-2026-2987-01": {"action": "init", "conditions": [{"name": "ARGS:sac_text", "type": "exists"}, {"name": "ARGS:sac_text", "type": "regex", "value": "~(?:]|]*on[a-z]+=|]*on(?:error|load)\\\\s*=|javascript\\\\s*:|]|]|]|on(?:error|load|click|mouseover|focus)\\\\s*=)~i"}], "cve": "CVE-2026-2987", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2987", "description": "Simple Ajax Chat <=20260217 unauthenticated stored XSS via chat message", "method": "POST", "mode": "block", "severity": 6.1, "slug": "simple-ajax-chat", "tags": ["xss", "stored-xss", "unauthenticated"], "target": "plugin", "versions": "<=20260217"}, "RULE-CVE-2026-2991-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/kivicare/v1/auth/patient/social-login([/?&]|$)~i"}], "cve": "CVE-2026-2991", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2991", "description": "KiviCare <=4.1.2 unauthenticated authentication bypass via patient-social-login REST endpoint \\u2014 vendor deleted the entire endpoint in fix", "method": "POST", "mode": "block", "severity": 9.8, "slug": "kivicare-clinic-management-system", "tags": ["authentication-bypass", "unauthenticated", "rest-api", "improper-authentication"], "target": "plugin", "versions": "<=4.1.2"}, "RULE-CVE-2026-2992-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/kivicare/v1/setup-wizard/clinic([/?&]|$)~"}, {"name": "missing_capability", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-2992", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2992", "description": "KiviCare Clinic Management System <=4.1.2 missing authorization on setup wizard clinic REST endpoint", "method": "POST", "mode": "block", "severity": 8.2, "slug": "kivicare-clinic-management-system", "tags": ["missing-authorization", "broken-access-control", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=4.1.2"}, "RULE-CVE-2026-2992-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/kivicare/v1/setup-wizard/step-complete([/?&]|$)~"}, {"name": "missing_capability", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-2992", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2992", "description": "KiviCare Clinic Management System <=4.1.2 missing authorization on setup wizard step-complete REST endpoint", "method": "POST", "mode": "block", "severity": 8.2, "slug": "kivicare-clinic-management-system", "tags": ["missing-authorization", "broken-access-control", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=4.1.2"}, "RULE-CVE-2026-2993-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "regex", "value": "~^waic_~i"}, {"name": "ARGS:table", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-2993", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2993", "description": "AI Copilot Content Generator <1.4.18 missing authorization on waic_* AJAX actions allows unauthenticated access to getListForTbl data endpoint", "mode": "block", "severity": 7.5, "slug": "ai-copilot-content-generator", "tags": ["missing-authorization", "sql-injection", "unauthenticated", "cwe-89"], "target": "plugin", "versions": ">=1.4.0 <1.4.18"}, "RULE-CVE-2026-2993-02": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "regex", "value": "~^waic_~i"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[0-9]+\\\\s*=\\\\s*[0-9]+)~i"}], "cve": "CVE-2026-2993", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2993", "description": "AI Copilot Content Generator <1.4.18 SQL injection via orderby parameter in waic_* AJAX handler getListForTbl", "method": "POST", "mode": "block", "severity": 7.5, "slug": "ai-copilot-content-generator", "tags": ["sql-injection", "unauthenticated", "cwe-89"], "target": "plugin", "versions": ">=1.4.0 <1.4.18"}, "RULE-CVE-2026-2993-03": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "regex", "value": "~^waic_~i"}, {"name": "ARGS:search", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\'[^\']*\'\\\\s*=\\\\s*\'[^\']*\'|\\\\b(?:OR|AND)\\\\s+1\\\\s*=\\\\s*1)~i"}], "cve": "CVE-2026-2993", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2993", "description": "AI Copilot Content Generator <1.4.18 SQL injection via search parameter in waic_* AJAX handler getListForTbl", "method": "POST", "mode": "block", "severity": 7.5, "slug": "ai-copilot-content-generator", "tags": ["sql-injection", "unauthenticated", "cwe-89"], "target": "plugin", "versions": ">=1.4.0 <1.4.18"}, "RULE-CVE-2026-2996-01": {"action": "init", "conditions": [{"name": "ARGS:add-to-cart", "type": "exists"}, {"name": "ARGS:wapf_field_groups", "type": "regex", "value": "~^\\\\s*$~"}], "cve": "CVE-2026-2996", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-2996", "description": "Advanced Product Fields for WooCommerce <=1.6.21 improper input validation allows required paid addon price bypass via blank wapf_field_groups on add-to-cart", "mode": "block", "severity": 7.5, "slug": "advanced-product-fields-for-woocommerce", "tags": ["improper-input-validation", "business-logic", "price-manipulation", "unauthenticated"], "target": "plugin", "versions": "<=1.6.21"}, "RULE-CVE-2026-3003-01": {"action": "admin_init", "conditions": [{"name": "ARGS:vagaro_command", "type": "regex", "value": "~^(?:Add|Update)$~i"}, {"name": "ARGS:vagaro_code", "type": "regex", "value": "~(?:<(?:script|svg|math|embed|object)[^>]*|(?:0*60|x0*3c);?(?:script|svg|math|embed|object)|on[a-z]{3,16}[[:space:]]*=|javascript[[:space:]]*:|(?:0*106|x0*6a);?(?:0*97|x0*61);?(?:0*118|x0*76);?(?:0*97|x0*61);?(?:0*115|x0*73);?(?:0*99|x0*63);?(?:0*114|x0*72);?(?:0*105|x0*69);?(?:0*112|x0*70);?(?:0*116|x0*74);?[[:space:]]*:)~i"}], "cve": "CVE-2026-3003", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-3003", "description": "Vagaro Booking Widget <=0.3 unauthenticated stored XSS via vagaro_code on admin_init POST handler", "method": "POST", "mode": "block", "severity": 7.2, "slug": "vagaro-booking-widget", "tags": ["xss", "stored-xss", "unauthenticated", "admin-post"], "target": "plugin", "versions": "<=0.3"}, "RULE-CVE-2026-3018-01": {"ajax_action": "newsletters_api", "conditions": [{"name": "ARGS:wpmlsubscriber_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|ALTER)\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bIF\\\\s*\\\\(|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-3018", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-3018", "description": "Newsletters <=4.13 unauthenticated time-based SQL injection via wpmlsubscriber_id parameter in newsletters_api AJAX handler", "mode": "block", "severity": 7.5, "slug": "newsletters-lite", "tags": ["sql-injection", "unauthenticated", "time-based"], "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-3056-01": {"ajax_action": "seraph_accel_api", "conditions": [{"name": "ARGS:fn", "type": "equals", "value": "LogClear"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-3056", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-3056", "description": "Seraphinite Accelerator <=2.28.14 missing authorization on LogClear via seraph_accel_api AJAX handler", "mode": "block", "severity": 4.3, "slug": "seraphinite-accelerator", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=2.28.14"}, "RULE-CVE-2026-3058-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-post\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "seraph_accel_api"}, {"name": "ARGS:fn", "type": "equals", "value": "GetData"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-3058", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-3058", "description": "Seraphinite Accelerator <=2.28.14 unauthenticated sensitive information exposure via admin-post.php nopriv route with fn=GetData", "mode": "block", "severity": 4.3, "slug": "seraphinite-accelerator", "tags": ["missing-authorization", "information-exposure", "unauthenticated"], "target": "plugin", "versions": "<=2.28.14"}, "RULE-CVE-2026-3090-01": {"ajax_action": "ps-get-email-logs", "conditions": [{"name": "ARGS:search", "type": "regex", "value": "~(?:|[^>]+\\\\bon(?:click|load|error|mouseover|focus|blur)\\\\s*=|a\\\\b[^>]+\\\\bhref\\\\s*=\\\\s*[\\"\']?\\\\s*javascript\\\\s*:|img\\\\b[^>]+\\\\bsrc\\\\s*=\\\\s*[\\"\']?\\\\s*javascript\\\\s*:)~is"}, {"name": "", "type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4336", "description": "Ultimate FAQS <= 2.4.7 stored XSS via FAQ content submitted to REST API /wp/v2/ufaq", "mode": "block", "severity": 6.4, "slug": "ultimate-faqs", "target": "plugin", "versions": "<=2.4.7"}, "RULE-CVE-2026-4336-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post(?:-new)?\\\\.php~"}, {"name": "ARGS:post_type", "type": "equals", "value": "ufaq"}, {"name": "ARGS:content", "type": "regex", "value": "~]|<[^>]+on(?:click|load|error|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|<script|<[^&]*on(?:click|load|error|mouseover|focus|blur)~i"}, {"name": "", "type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4336", "description": "Ultimate FAQS <= 2.4.7 stored XSS via FAQ post_content submitted through wp-admin/post.php editor", "mode": "block", "severity": 6.4, "slug": "ultimate-faqs", "target": "plugin", "versions": "<=2.4.7"}, "RULE-CVE-2026-4338-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/activitypub/1\\\\.0/outbox(?:[/?]|$)~i"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4338", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4338", "description": "ActivityPub <8.0.2 unauthenticated information disclosure of draft/scheduled/pending posts via site-level outbox REST endpoint", "method": "GET", "mode": "block", "severity": 7.5, "slug": "activitypub", "tags": ["information-disclosure", "rest-api", "unauthenticated", "improper-access-control"], "target": "plugin", "versions": "<8.0.2"}, "RULE-CVE-2026-4341-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "save_builder"}, {"name": "ARGS:actions", "type": "regex", "value": "~follow_us_text[^}]*(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"name": "", "type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4341", "description": "Prime Slider <=4.1.10 stored XSS via follow_us_text in Mount widget (Elementor AJAX save)", "mode": "block", "severity": 6.4, "slug": "bdthemes-prime-slider-lite", "target": "plugin", "versions": "<=4.1.10"}, "RULE-CVE-2026-4341-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/elementor/v1/document/[0-9]+(?:[/?&]|$)~"}, {"name": "ARGS", "type": "regex", "value": "~follow_us_text[^}]*(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"name": "", "type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4341", "description": "Prime Slider <=4.1.10 stored XSS via follow_us_text in Mount widget (Elementor REST save)", "mode": "block", "severity": 6.4, "slug": "bdthemes-prime-slider-lite", "target": "plugin", "versions": "<=4.1.10"}, "RULE-CVE-2026-4347-01": {"action": "template_redirect", "conditions": [{"name": "ARGS:MWF_file", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env))~i"}, {"name": "ARGS:_mw_wp_form_token", "type": "exists"}], "cve": "CVE-2026-4347", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4347", "description": "MW WP Form <=5.1.0 unauthenticated path traversal via file upload move flow (generate_user_filepath / move_temp_file_to_upload_dir)", "method": "POST", "mode": "block", "severity": 8.1, "slug": "mw-wp-form", "tags": ["path-traversal", "arbitrary-file-upload", "unauthenticated"], "target": "plugin", "versions": "<=5.1.0"}, "RULE-CVE-2026-4347-02": {"action": "template_redirect", "conditions": [{"name": "ARGS:MWF_file", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9s]?|tml?|t|ar)|phs|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$~i"}, {"name": "ARGS:_mw_wp_form_token", "type": "exists"}], "cve": "CVE-2026-4347", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4347", "description": "MW WP Form <=5.1.0 unauthenticated path traversal via crafted uploaded filename in file field", "method": "POST", "mode": "block", "severity": 8.1, "slug": "mw-wp-form", "tags": ["path-traversal", "arbitrary-file-upload", "unauthenticated"], "target": "plugin", "versions": "<=5.1.0"}, "RULE-CVE-2026-4365-01": {"action": "init", "conditions": [{"name": "ARGS:lp-ajax", "type": "equals", "value": "delete_question_answer"}, {"type": "missing_capability", "value": "edit_lp_courses"}], "cve": "CVE-2026-4365", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4365", "description": "LearnPress <=4.3.2.8 unauthenticated arbitrary quiz answer deletion via lp-ajax delete_question_answer", "method": "POST", "mode": "block", "severity": 9.1, "slug": "learnpress", "tags": ["missing-authorization", "data-deletion", "unauthenticated"], "target": "plugin", "versions": "<=4.3.2.8"}, "RULE-CVE-2026-4373-01": {"ajax_action": "jet_form_builder_submit", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\"file\\"\\\\s*:\\\\s*\\"(?:[^\\"]*(?:\\\\.\\\\.[\\\\\\\\/])|/(?:etc|proc|var/log)[\\\\\\\\/])~i"}], "cve": "CVE-2026-4373", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373", "description": "JetFormBuilder <=3.5.6.2 unauthenticated arbitrary file read via path traversal in Media Field JSON preset (AJAX path)", "method": "POST", "mode": "block", "severity": 7.5, "slug": "jetformbuilder", "tags": ["path-traversal", "arbitrary-file-read", "unauthenticated"], "target": "plugin", "versions": "<=3.5.6.2"}, "RULE-CVE-2026-4373-02": {"ajax_action": "jet_form_builder_submit", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\"file\\"\\\\s*:\\\\s*\\"[^\\"]*(?:wp-config\\\\.php|\\\\.htaccess|\\\\.env(?![a-z])|debug\\\\.log|error_log(?![a-z]))~i"}], "cve": "CVE-2026-4373", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373", "description": "JetFormBuilder <=3.5.6.2 unauthenticated arbitrary file read via sensitive file path in Media Field JSON preset (AJAX path)", "method": "POST", "mode": "block", "severity": 7.5, "slug": "jetformbuilder", "tags": ["path-traversal", "arbitrary-file-read", "unauthenticated"], "target": "plugin", "versions": "<=3.5.6.2"}, "RULE-CVE-2026-4373-03": {"action": "wp_loaded", "conditions": [{"name": "ARGS:_jfb_form_id", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~\\"file\\"\\\\s*:\\\\s*\\"(?:[^\\"]*(?:\\\\.\\\\.[\\\\\\\\/])|/(?:etc|proc|var/log)[\\\\\\\\/])~i"}], "cve": "CVE-2026-4373", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373", "description": "JetFormBuilder <=3.5.6.2 unauthenticated arbitrary file read via path traversal in Media Field JSON preset (non-AJAX form submission)", "method": "POST", "mode": "block", "severity": 7.5, "slug": "jetformbuilder", "tags": ["path-traversal", "arbitrary-file-read", "unauthenticated"], "target": "plugin", "versions": "<=3.5.6.2"}, "RULE-CVE-2026-4373-04": {"action": "wp_loaded", "conditions": [{"name": "ARGS:_jfb_form_id", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~\\"file\\"\\\\s*:\\\\s*\\"[^\\"]*(?:wp-config\\\\.php|\\\\.htaccess|\\\\.env(?![a-z])|debug\\\\.log|error_log(?![a-z]))~i"}], "cve": "CVE-2026-4373", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4373", "description": "JetFormBuilder <=3.5.6.2 unauthenticated arbitrary file read via sensitive file path in Media Field JSON preset (non-AJAX form submission)", "method": "POST", "mode": "block", "severity": 7.5, "slug": "jetformbuilder", "tags": ["path-traversal", "arbitrary-file-read", "unauthenticated"], "target": "plugin", "versions": "<=3.5.6.2"}, "RULE-CVE-2026-4379-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[gallery\\\\s[^\\\\]]*group\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|[\\"\']\\\\s+on[a-z]+=|[\\"\']>)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4379", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4379", "description": "WP jQuery Lightbox <=2.3.4 Contributor+ Stored XSS via gallery shortcode group attribute in post.php", "method": "POST", "mode": "block", "severity": 6.4, "slug": "wp-jquery-lightbox", "tags": ["xss", "stored", "shortcode", "authenticated"], "target": "plugin", "versions": "<=2.3.4"}, "RULE-CVE-2026-4379-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[gallery\\\\s[^\\\\]]*group\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|[\\"\']\\\\s+on[a-z]+=|[\\"\']>)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4379", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4379", "description": "WP jQuery Lightbox <=2.3.4 Contributor+ Stored XSS via gallery shortcode group attribute in REST API", "method": "POST", "mode": "block", "severity": 6.4, "slug": "wp-jquery-lightbox", "tags": ["xss", "stored", "shortcode", "rest-api", "authenticated"], "target": "plugin", "versions": "<=2.3.4"}, "RULE-CVE-2026-4388-01": {"ajax_action": "fm_submit_form", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\"\\\\s*(?:on(?:focus|blur|click|dblclick|mouse(?:over|out|down|up|move|enter|leave)|key(?:down|up|press)|load|error|submit|reset|change|input|select|abort|resize|scroll|unload|beforeunload|hashchange|pointerdown|pointerup|pointermove|pointerover|pointerout|touchstart|touchend|touchmove|drag|dragstart|dragend|dragover|dragenter|dragleave|drop|animationstart|animationend|transitionend|contextmenu|wheel|copy|cut|paste)\\\\s*=|style\\\\s*=\\\\s*[\\"\']?[^\\"\'>]*(?:expression|url)\\\\s*\\\\()~i"}], "cve": "CVE-2026-4388", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4388", "description": "Form Maker by 10Web <=1.15.40 unauthenticated stored XSS via Matrix field attribute-context injection in fm_submit_form AJAX handler", "method": "POST", "mode": "block", "severity": 7.2, "slug": "form-maker", "tags": ["xss", "stored", "unauthenticated", "attribute-injection"], "target": "plugin", "versions": "<=1.15.40"}, "RULE-CVE-2026-4388-02": {"action": "init", "conditions": [{"name": "ARGS:fm_form_id", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~\\"\\\\s*(?:on(?:focus|blur|click|dblclick|mouse(?:over|out|down|up|move|enter|leave)|key(?:down|up|press)|load|error|submit|reset|change|input|select|abort|resize|scroll|unload|beforeunload|hashchange|pointerdown|pointerup|pointermove|pointerover|pointerout|touchstart|touchend|touchmove|drag|dragstart|dragend|dragover|dragenter|dragleave|drop|animationstart|animationend|transitionend|contextmenu|wheel|copy|cut|paste)\\\\s*=|style\\\\s*=\\\\s*[\\"\']?[^\\"\'>]*(?:expression|url)\\\\s*\\\\()~i"}], "cve": "CVE-2026-4388", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4388", "description": "Form Maker by 10Web <=1.15.40 unauthenticated stored XSS via Matrix field attribute-context injection in non-AJAX form submission", "method": "POST", "mode": "block", "severity": 7.2, "slug": "form-maker", "tags": ["xss", "stored", "unauthenticated", "attribute-injection"], "target": "plugin", "versions": "<=1.15.40"}, "RULE-CVE-2026-4429-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/(?:post|post-new)\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[osm_map_v3\\\\b[^\\\\]]*\\\\b(?:marker_name|file_color_list)\\\\s*=\\\\s*[\'\\\\\\"][^\'\\\\\\"\\\\]]*(?:<[a-z!/]|on[a-z]+\\\\s*=|javascript\\\\s*:||%3[Cc])~i"}], "cve": "CVE-2026-4429", "description": "OSM <=6.1.15 authenticated (Contributor+) stored XSS via [osm_map_v3] shortcode marker_name/file_color_list attributes saved through wp-admin/post.php", "mode": "block", "severity": 6.4, "slug": "osm", "target": "plugin", "versions": "<=6.1.15"}, "RULE-CVE-2026-4429-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages|[a-z0-9_-]+)(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[osm_map_v3\\\\b[^\\\\]]*\\\\b(?:marker_name|file_color_list)\\\\s*=\\\\s*[\'\\\\\\"][^\'\\\\\\"\\\\]]*(?:<[a-z!/]|on[a-z]+\\\\s*=|javascript\\\\s*:||%3[Cc])~i"}], "cve": "CVE-2026-4429", "description": "OSM <=6.1.15 authenticated (Contributor+) stored XSS via [osm_map_v3] shortcode marker_name/file_color_list attributes saved through REST API wp/v2/posts", "mode": "block", "severity": 6.4, "slug": "osm", "target": "plugin", "versions": "<=6.1.15"}, "RULE-CVE-2026-4484-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/masteriyo/v1/users/instructors/[0-9]+(?:[/?]|$)~"}, {"name": "ARGS:roles", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-4484", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4484", "description": "Masteriyo LMS <=2.1.6 authenticated (Student+) privilege escalation to administrator via roles parameter in instructors REST endpoint", "mode": "block", "severity": 9.8, "slug": "learning-management-system", "tags": ["missing-authorization", "privilege-escalation", "rest-api"], "target": "plugin", "versions": "<=2.1.6"}, "RULE-CVE-2026-45218-01": {"action": "wp_ajax_nopriv_wp_travel_update_trip", "conditions": [{"name": "ARGS:trip_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via wp_travel_update_trip unauthenticated endpoint", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45218-02": {"action": "wp_ajax_nopriv_wp_travel_get_trip", "conditions": [{"name": "ARGS:trip_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via wp_travel_get_trip without nonce/capability check", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45218-03": {"action": "wp_ajax_wp_travel_get_pricings", "conditions": [{"name": "ARGS:trip_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}, {"name": "missing_capability", "type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via wp_travel_get_pricings without nonce/capability check", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45218-04": {"action": "wp_ajax_nopriv_wptravel_save_user_enquiry", "conditions": [{"name": "ARGS:trip_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via wptravel_save_user_enquiry endpoint", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45218-05": {"action": "wp_ajax_nopriv_wp_travel_add_to_cart", "conditions": [{"name": "ARGS:trip_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via wp_travel_add_to_cart endpoint", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45218-06": {"action": "wp_ajax_nopriv_wp_travel_get_cart", "conditions": [{"name": "ARGS:trip_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via wp_travel_get_cart endpoint", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45218-07": {"action": "wp_ajax_delete_itinerary_enquiry", "conditions": [{"name": "ARGS:enquiry_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}, {"name": "missing_capability", "type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-45218", "description": "WP Travel <=11.4.0 SQL injection via delete_itinerary_enquiry endpoint", "mode": "block", "severity": 7.7, "slug": "wp-travel", "target": "plugin", "versions": "<=11.4.0"}, "RULE-CVE-2026-45437-01": {"ajax_action": "eszlwcf_filter_products", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*(?:img|svg|iframe|object|embed|details|math)\\\\b[^>]*\\\\bon\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-45437", "description": "Product Filter Widget for Elementor <=1.0.6 unauthenticated reflected XSS via eszlwcf_filter_products AJAX handler", "mode": "block", "severity": 7.1, "slug": "product-filter-widget-for-elementor", "target": "plugin", "versions": "<=1.0.6"}, "RULE-CVE-2026-45437-02": {"ajax_action": "eszlwcf_load_more_products", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*(?:img|svg|iframe|object|embed|details|math)\\\\b[^>]*\\\\bon\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-45437", "description": "Product Filter Widget for Elementor <=1.0.6 unauthenticated reflected XSS via eszlwcf_load_more_products AJAX handler", "mode": "block", "severity": 7.1, "slug": "product-filter-widget-for-elementor", "target": "plugin", "versions": "<=1.0.6"}, "RULE-CVE-2026-45439-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/idx_api/v1(?:import)(?:_json)?/~i"}, {"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML|LOAD_FILE)\\\\s*\\\\(|\\\\bOR\\\\s+[\'\\"]?[0-9]+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?[0-9]|\\\\bAND\\\\s+[\'\\"]?[0-9]+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?[0-9]|(?:%27|\')\\\\s*(?:UNION|OR|AND|SELECT)\\\\b)~i"}], "cve": "CVE-2026-45439", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-45439", "description": "Realtyna Organic IDX plugin <=5.1.0 unauthenticated SQL injection via IDX REST API import endpoint (token path + query parameters)", "mode": "block", "severity": 9.3, "slug": "real-estate-listing-realtyna-wpl", "tags": ["sql-injection", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=5.1.0"}, "RULE-CVE-2026-45439-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/idx_api/v1(?:update)(?:_json)?/~i"}, {"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML|LOAD_FILE)\\\\s*\\\\(|\\\\bOR\\\\s+[\'\\"]?[0-9]+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?[0-9]|\\\\bAND\\\\s+[\'\\"]?[0-9]+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?[0-9]|(?:%27|\')\\\\s*(?:UNION|OR|AND|SELECT)\\\\b)~i"}], "cve": "CVE-2026-45439", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-45439", "description": "Realtyna Organic IDX plugin <=5.1.0 unauthenticated SQL injection via IDX REST API update endpoint (token path + query parameters)", "mode": "block", "severity": 9.3, "slug": "real-estate-listing-realtyna-wpl", "tags": ["sql-injection", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=5.1.0"}, "RULE-CVE-2026-4561-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:/text_subscribed|text_error/", "type": "regex", "value": "~(?:]|]|]|]|]|on(?:error|load|click|mouseover|mouseenter|mouseleave|focus|blur)\\\\s*=|(?:javascript|data)\\\\s*:)~i"}], "cve": "CVE-2026-4561", "description": "MC4WP Mailchimp for WordPress <=4.12.0 Author+ stored XSS via text_subscribed/text_error form message post meta", "mode": "block", "slug": "mailchimp-for-wp", "target": "plugin", "versions": "<=4.12.0"}, "RULE-CVE-2026-4655-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "elementor_ajax"}, {"name": "ARGS:options", "type": "regex", "value": "~bdt-svg-image~i"}, {"name": "ARGS:options", "type": "regex", "value": "~(?:%3C|<)\\\\s*script[\\\\s/>]|on(?:error|load|click|mouseover|focus)\\\\s*(?:=|%3D)|javascript\\\\s*(?::|%3A)|%253[Cc]script~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4655", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4655", "description": "Element Pack Lite <=8.4.2 contributor+ stored XSS via SVG Image widget svg_source on elementor_ajax", "mode": "block", "severity": 6.4, "slug": "bdthemes-element-pack-lite", "tags": ["xss", "stored", "authenticated"], "target": "plugin", "versions": "<=8.4.2"}, "RULE-CVE-2026-4658-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages)~"}, {"name": "ARGS:content", "type": "regex", "value": "~essential-blocks/add-to-cart[\\\\s\\\\S]{0,500}?(?:className|classHook|blockId)[\\\\s\\\\S]{0,200}?(?:]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-4658", "description": "Essential Blocks <=6.0.4 stored XSS via AddToCart block class attributes (REST post save - className)", "mode": "block", "severity": 6.4, "slug": "essential-blocks", "target": "plugin", "versions": "<=6.0.4"}, "RULE-CVE-2026-4658-02": {"action": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~wp:essential-blocks/add-to-cart[\\\\s\\\\S]{0,500}?(?:className|classHook|blockId)[\\\\s\\\\S]{0,200}?(?:]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|"javascript)~i"}], "cve": "CVE-2026-4658", "description": "Essential Blocks <=6.0.4 stored XSS via AddToCart block markup in any request body", "method": "POST", "mode": "block", "severity": 6.4, "slug": "essential-blocks", "target": "plugin", "versions": "<=6.0.4"}, "RULE-CVE-2026-4659-01": {"ajax_action": "elementor_ajax", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[/\\\\\\\\]+){2,}|/etc/passwd|[/\\\\\\\\](?:wp-config\\\\.php|\\\\.htaccess|\\\\.env))~i"}], "cve": "CVE-2026-4659", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4659", "description": "Unlimited Elements for Elementor <=2.0.6 authenticated contributor+ arbitrary file read via path traversal in Repeater JSON/CSV URL within Elementor widget settings", "mode": "block", "severity": 7.5, "slug": "unlimited-elements-for-elementor", "tags": ["path-traversal", "arbitrary-file-read", "authenticated", "elementor"], "target": "plugin", "versions": "<=2.0.6"}, "RULE-CVE-2026-4664-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/ivole/v1/review(?:[/?&]|$)~"}, {"name": "ARGS:key", "type": "regex", "value": "~^\\\\s*$~"}], "cve": "CVE-2026-4664", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4664", "description": "Customer Reviews for WooCommerce <=5.103.0 unauthenticated authentication bypass on POST /ivole/v1/review via empty key parameter against ivole_secret_key meta", "method": "POST", "mode": "block", "severity": 5.3, "slug": "customer-reviews-woocommerce", "tags": ["authentication-bypass", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=5.103.0"}, "RULE-CVE-2026-4665-01": {"ajax_action": "wpcf_image_save_meta", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|<[a-zA-Z][^>]*\\\\son(?:load|error|click|mouseover|focus|blur|submit|change|input|toggle)\\\\s*=|javascript\\\\s*:|]|]+onerror|])~i"}], "cve": "CVE-2026-4665", "description": "WP Carousel Free <=2.7.10 stored DOM XSS via crafted data-caption in wpcf_image_save_meta AJAX handler", "mode": "block", "severity": 6.4, "slug": "wp-carousel-free", "target": "plugin", "versions": "<=2.7.10"}, "RULE-CVE-2026-4665-02": {"ajax_action": "wpcp_import_shortcodes", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|<[a-zA-Z][^>]*\\\\son(?:load|error|click|mouseover|focus|blur|submit|change|input|toggle)\\\\s*=|javascript\\\\s*:|]|]+onerror|])~i"}], "cve": "CVE-2026-4665", "description": "WP Carousel Free <=2.7.10 stored DOM XSS via shortcodes import containing malicious data-caption payloads", "mode": "block", "severity": 6.4, "slug": "wp-carousel-free", "target": "plugin", "versions": "<=2.7.10"}, "RULE-CVE-2026-4703-01": {"action": "init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]+\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-4703", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4703", "description": "WS Form LITE <=1.10.80 unauthenticated PHP object injection via unsafe deserialization of form submission meta values", "mode": "block", "severity": 9.8, "slug": "ws-form", "tags": ["object-injection", "deserialization", "unauthenticated"], "target": "plugin", "versions": "<=1.10.80"}, "RULE-CVE-2026-4758-01": {"ajax_action": "wpjobportal_ajax", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env(?:$|[^a-zA-Z0-9_])))~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-4758", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4758", "description": "WP Job Portal <=2.4.9 authenticated arbitrary file deletion via path traversal in wpjobportal_ajax", "mode": "block", "severity": 8.8, "slug": "wp-job-portal", "tags": ["path-traversal", "arbitrary-file-deletion", "authenticated"], "target": "plugin", "versions": "<=2.4.9"}, "RULE-CVE-2026-4758-02": {"ajax_action": "wpjobportal_ajax_popup", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env(?:$|[^a-zA-Z0-9_])))~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-4758", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4758", "description": "WP Job Portal <=2.4.9 authenticated arbitrary file deletion via path traversal in wpjobportal_ajax_popup", "mode": "block", "severity": 8.8, "slug": "wp-job-portal", "tags": ["path-traversal", "arbitrary-file-deletion", "authenticated"], "target": "plugin", "versions": "<=2.4.9"}, "RULE-CVE-2026-4785-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[latepoint_resources\\\\b[^\\\\]]*button_caption\\\\s*=\\\\s*(?:\\"[^\\"]*(?:<[a-zA-Z/!]|javascript:|on[a-zA-Z]+\\\\s*=)|\'[^\']*(?:<[a-zA-Z/!]|javascript:|on[a-zA-Z]+\\\\s*=))~i"}], "cve": "CVE-2026-4785", "description": "LatePoint <=5.3.0 stored XSS via button_caption parameter in [latepoint_resources] shortcode (post.php save)", "mode": "block", "severity": 6.4, "slug": "latepoint", "target": "plugin", "versions": "<=5.3.0"}, "RULE-CVE-2026-4785-02": {"ajax_action": "heartbeat", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\[latepoint_resources\\\\b[^\\\\]]*button_caption\\\\s*=\\\\s*(?:\\"[^\\"]*(?:<[a-zA-Z/!]|javascript:|on[a-zA-Z]+\\\\s*=)|\'[^\']*(?:<[a-zA-Z/!]|javascript:|on[a-zA-Z]+\\\\s*=))~i"}], "cve": "CVE-2026-4785", "description": "LatePoint <=5.3.0 stored XSS via button_caption parameter in [latepoint_resources] shortcode (heartbeat autosave)", "mode": "block", "severity": 6.4, "slug": "latepoint", "target": "plugin", "versions": "<=5.3.0"}, "RULE-CVE-2026-4785-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[latepoint_resources\\\\b[^\\\\]]*button_caption\\\\s*=\\\\s*(?:\\"[^\\"]*(?:<[a-zA-Z/!]|javascript:|on[a-zA-Z]+\\\\s*=)|\'[^\']*(?:<[a-zA-Z/!]|javascript:|on[a-zA-Z]+\\\\s*=))~i"}], "cve": "CVE-2026-4785", "description": "LatePoint <=5.3.0 stored XSS via button_caption parameter in [latepoint_resources] shortcode (REST API)", "mode": "block", "severity": 6.4, "slug": "latepoint", "target": "plugin", "versions": "<=5.3.0"}, "RULE-CVE-2026-4790-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~i"}, {"name": "ARGS:custom_svg", "type": "regex", "value": "~(?:]|\\\\son(?:load|error|click|mouseover|focus|animationstart|animationend)\\\\s*=|javascript\\\\s*:|]|]|])~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-4790", "description": "Premium Addons for Elementor <=4.11.70 contributor+ stored XSS via custom_svg parameter (CWE-79)", "mode": "block", "severity": 5.4, "slug": "premium-addons-for-elementor", "target": "plugin", "versions": "<=4.11.70"}, "RULE-CVE-2026-4801-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:pages|posts)(/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~coblocks/events[\\\\s\\\\S]*?(?:icalFeedUrl|eventsTitle|eventsDescription|eventsLocation)[\\\\s\\\\S]*?<[^>]+(?:on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|])~i"}], "cve": "CVE-2026-4801", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4801", "description": "CoBlocks <=3.1.16 stored XSS via Events block iCal feed attributes in Gutenberg REST API", "mode": "block", "severity": 6.4, "slug": "coblocks", "tags": ["xss", "stored", "authenticated", "gutenberg"], "target": "plugin", "versions": "<=3.1.16"}, "RULE-CVE-2026-4801-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:pages|posts)(/|\\\\?|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~coblocks/events[\\\\s\\\\S]*?icalFeedUrl[\\\\s\\\\S]*?(?:javascript\\\\s*:|<[^>]+on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-4801", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4801", "description": "CoBlocks <=3.1.16 stored XSS via Events block iCal feed URL attribute", "mode": "block", "severity": 6.4, "slug": "coblocks", "tags": ["xss", "stored", "authenticated", "gutenberg"], "target": "plugin", "versions": "<=3.1.16"}, "RULE-CVE-2026-4812-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:action", "type": "equals", "value": "acf/fields/post_object/query"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4812", "description": "Advanced Custom Fields <=6.7.0 unauthenticated post_object enumeration", "mode": "block", "severity": 5.3, "slug": "advanced-custom-fields", "target": "plugin", "versions": "<=6.7.0"}, "RULE-CVE-2026-4812-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:action", "type": "equals", "value": "acf/fields/relationship/query"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4812", "description": "Advanced Custom Fields <=6.7.0 unauthenticated relationship enumeration", "mode": "block", "severity": 5.3, "slug": "advanced-custom-fields", "target": "plugin", "versions": "<=6.7.0"}, "RULE-CVE-2026-4812-03": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:action", "type": "equals", "value": "acf/fields/page_link/query"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4812", "description": "Advanced Custom Fields <=6.7.0 unauthenticated page_link enumeration", "mode": "block", "severity": 5.3, "slug": "advanced-custom-fields", "target": "plugin", "versions": "<=6.7.0"}, "RULE-CVE-2026-4812-04": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:action", "type": "equals", "value": "acf/fields/user/query"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4812", "description": "Advanced Custom Fields <=6.7.0 unauthenticated user enumeration", "mode": "block", "severity": 5.3, "slug": "advanced-custom-fields", "target": "plugin", "versions": "<=6.7.0"}, "RULE-CVE-2026-4812-05": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:action", "type": "equals", "value": "acf/fields/select/query"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4812", "description": "Advanced Custom Fields <=6.7.0 unauthenticated select enumeration", "mode": "block", "severity": 5.3, "slug": "advanced-custom-fields", "target": "plugin", "versions": "<=6.7.0"}, "RULE-CVE-2026-4812-06": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:action", "type": "equals", "value": "acf/fields/taxonomy/query"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-4812", "description": "Advanced Custom Fields <=6.7.0 unauthenticated taxonomy enumeration", "mode": "block", "severity": 5.3, "slug": "advanced-custom-fields", "target": "plugin", "versions": "<=6.7.0"}, "RULE-CVE-2026-4817-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/lms/stm-lms/order/items(?:/|\\\\?|$)~"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s+(?:UNION|SELECT|DROP|DELETE|INSERT|UPDATE|TABLE|INTO|VALUES|FROM|WHERE|version)\\\\s)~i"}], "cve": "CVE-2026-4817", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4817", "description": "MasterStudy LMS <=3.7.25 SQL injection via orderby parameter in stm-lms/order/items REST endpoint", "method": "POST", "mode": "block", "severity": 6.5, "slug": "masterstudy-lms-learning-management-system", "tags": ["sql-injection", "rest-api", "authenticated"], "target": "plugin", "versions": "<=3.7.25"}, "RULE-CVE-2026-4880-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "barcodeScannerConfigs"}, {"name": "ARGS:token", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-4880", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4880", "description": "Barcode Scanner and Inventory manager <=1.11.0 unauthenticated token leak via barcodeScannerConfigs AJAX action (GET or POST)", "mode": "block", "severity": 9.8, "slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders", "tags": ["privilege-escalation", "authentication-bypass", "unauthenticated", "token-leak"], "target": "plugin", "versions": "<=1.11.0"}, "RULE-CVE-2026-4880-02": {"ajax_action": "setUserMeta", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:wp_capabilities|wp_user_level)~"}], "cve": "CVE-2026-4880", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4880", "description": "Barcode Scanner and Inventory manager <=1.11.0 unauthenticated privilege escalation via setUserMeta AJAX action (wp_capabilities)", "mode": "block", "severity": 9.8, "slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders", "tags": ["privilege-escalation", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=1.11.0"}, "RULE-CVE-2026-4880-03": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[?&]action=barcodeScannerConfigs(?:&|$)~"}, {"name": "ARGS:token", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-4880", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4880", "description": "Barcode Scanner <=1.11.0 unauthenticated token leak via barcodeScannerConfigs AJAX GET request (REQUEST_URI detection)", "mode": "block", "severity": 9.8, "slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders", "tags": ["privilege-escalation", "authentication-bypass", "unauthenticated", "token-leak"], "target": "plugin", "versions": "<=1.11.0"}, "RULE-CVE-2026-4880-04": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[/\\\\\\\\]barcode-scanner-lite-pos-to-manage-products-inventory-and-orders[/\\\\\\\\]request\\\\.php~"}, {"name": "ARGS:route", "type": "equals", "value": "setUserMeta"}, {"name": "ARGS", "type": "regex", "value": "~(?:wp_capabilities|wp_user_level)~"}], "cve": "CVE-2026-4880", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4880", "description": "Barcode Scanner and Inventory manager <=1.11.0 unauthenticated privilege escalation via direct request.php setUserMeta endpoint (wp_capabilities)", "method": "POST", "mode": "block", "severity": 9.8, "slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders", "tags": ["privilege-escalation", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=1.11.0"}, "RULE-CVE-2026-48835-01": {"ajax_action": "wpforms_connect_process", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-48835", "description": "WPForms Lite <=1.10.0.4 unauthenticated broken access control via wpforms_connect_process AJAX handler", "mode": "block", "severity": 7.5, "slug": "wpforms-lite", "target": "plugin", "versions": "<=1.10.0.4"}, "RULE-CVE-2026-48874-01": {"ajax_action": "ct_ajax_list_table_request", "conditions": [{"name": "ARGS:query_args[orderby]", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|CASE\\\\s+WHEN\\\\s.*\\\\s+THEN\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-48874", "description": "GamiPress <=7.8.7 subscriber+ SQL injection via orderby in ct_ajax_list_table_request", "mode": "block", "severity": 8.5, "slug": "gamipress", "target": "plugin", "versions": "<=7.8.7"}, "RULE-CVE-2026-48874-02": {"ajax_action": "ct_ajax_list_table_request", "conditions": [{"name": "ARGS:query_args[order]", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|CASE\\\\s+WHEN\\\\s.*\\\\s+THEN\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-48874", "description": "GamiPress <=7.8.7 subscriber+ SQL injection via order in ct_ajax_list_table_request", "mode": "block", "severity": 8.5, "slug": "gamipress", "target": "plugin", "versions": "<=7.8.7"}, "RULE-CVE-2026-48876-01": {"ajax_action": "sfs_sub", "conditions": [{"name": "ARGS:comment_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-48968", "description": "Master Slider <=3.10.8 Contributor+ reflected XSS via slider_params in preview view", "mode": "block", "severity": 6.5, "slug": "master-slider", "target": "plugin", "versions": "<=3.10.8"}, "RULE-CVE-2026-48968-02": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "masterslider"}, {"name": "ARGS:slider_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-48968", "description": "Master Slider <=3.10.8 Contributor+ reflected XSS via slider_id in preview view", "mode": "block", "severity": 6.5, "slug": "master-slider", "target": "plugin", "versions": "<=3.10.8"}, "RULE-CVE-2026-48968-03": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "masterslider"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-48968", "description": "Master Slider <=3.10.8 Contributor+ reflected XSS via orderby in list table", "mode": "block", "severity": 6.5, "slug": "master-slider", "target": "plugin", "versions": "<=3.10.8"}, "RULE-CVE-2026-48968-04": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "masterslider"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-48968", "description": "Master Slider <=3.10.8 Contributor+ reflected XSS via order in list table", "mode": "block", "severity": 6.5, "slug": "master-slider", "target": "plugin", "versions": "<=3.10.8"}, "RULE-CVE-2026-49044-01": {"action": "admin_init", "conditions": [{"name": "ARGS:option_page", "type": "equals", "value": "acffa_settings"}, {"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-49044", "description": "Advanced Custom Fields: Font Awesome Field <=5.0.2 authenticated stored XSS via acffa_settings option values", "mode": "block", "severity": 6.5, "slug": "advanced-custom-fields-font-awesome", "target": "plugin", "versions": "<=5.0.2"}, "RULE-CVE-2026-49055-01": {"ajax_action": "dnd_codedropz_upload_delete", "conditions": [{"name": "ARGS:path", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus)\\\\s*=|javascript\\\\s*:|]*\\\\bsrc\\\\s*=|]|])~i"}], "cve": "CVE-2026-49055", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49055", "description": "Drag and Drop Multiple File Upload CF7 <=1.3.9.7 unauthenticated reflected XSS via path parameter in dnd_codedropz_upload_delete", "mode": "block", "severity": 7.1, "slug": "drag-and-drop-multiple-file-upload-contact-form-7", "tags": ["xss", "reflected-xss", "unauthenticated"], "target": "plugin", "versions": "<=1.3.9.7"}, "RULE-CVE-2026-49055-02": {"ajax_action": "dnd_codedropz_upload", "conditions": [{"name": "FILES:upload-file:name", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus)\\\\s*=|javascript\\\\s*:|]*\\\\bsrc\\\\s*=|]|])~i"}], "cve": "CVE-2026-49055", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49055", "description": "Drag and Drop Multiple File Upload CF7 <=1.3.9.7 unauthenticated stored XSS via uploaded filename in dnd_codedropz_upload", "mode": "block", "severity": 7.1, "slug": "drag-and-drop-multiple-file-upload-contact-form-7", "tags": ["xss", "stored-xss", "unauthenticated", "file-upload"], "target": "plugin", "versions": "<=1.3.9.7"}, "RULE-CVE-2026-49060-01": {"ajax_action": "hippoo_save_permission_role", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-49060", "description": "Hippoo Mobile App for WooCommerce <=1.9.4 authenticated privilege escalation via hippoo_save_permission_role AJAX handler", "mode": "block", "severity": 9.8, "slug": "hippoo", "target": "plugin", "versions": "<=1.9.4"}, "RULE-CVE-2026-49060-02": {"ajax_action": "hippoo_add_permission_role", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-49060", "description": "Hippoo Mobile App for WooCommerce <=1.9.4 authenticated privilege escalation via hippoo_add_permission_role AJAX handler", "mode": "block", "severity": 9.8, "slug": "hippoo", "target": "plugin", "versions": "<=1.9.4"}, "RULE-CVE-2026-49060-03": {"ajax_action": "hippoo_delete_permission_role", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-49060", "description": "Hippoo Mobile App for WooCommerce <=1.9.4 authenticated privilege escalation via hippoo_delete_permission_role AJAX handler", "mode": "block", "severity": 9.8, "slug": "hippoo", "target": "plugin", "versions": "<=1.9.4"}, "RULE-CVE-2026-49063-01": {"ajax_action": "lsd_register", "conditions": [{"name": "ARGS:lsd_role", "type": "exists"}], "cve": "CVE-2026-49063", "description": "Listdom <= 5.5.0 - Unauthenticated Privilege Escalation via lsd_register (role injection)", "mode": "block", "severity": 7.3, "slug": "listdom", "target": "plugin", "versions": "<=5.5.0"}, "RULE-CVE-2026-49063-02": {"ajax_action": "lsd_login", "conditions": [{"name": "ARGS:lsd_role", "type": "exists"}], "cve": "CVE-2026-49063", "description": "Listdom <= 5.5.0 - Unauthenticated Privilege Escalation via lsd_login (role injection)", "mode": "block", "severity": 7.3, "slug": "listdom", "target": "plugin", "versions": "<=5.5.0"}, "RULE-CVE-2026-49063-03": {"ajax_action": "lsd_activation", "conditions": [{"name": "ARGS:lsd_role", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-49063", "description": "Listdom <= 5.5.0 - Authenticated Privilege Escalation via lsd_activation (role injection)", "mode": "block", "severity": 7.3, "slug": "listdom", "target": "plugin", "versions": "<=5.5.0"}, "RULE-CVE-2026-49067-01": {"action": "init", "conditions": [{"name": "ARGS:page", "type": "regex", "value": "~^yydev[_-]redirect~"}, {"name": "ARGS:id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|/\\\\*[!+]|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-49067", "description": "Advanced 301 and 302 Redirect <=1.6.9 unauthenticated SQL injection via id parameter on admin page endpoint", "mode": "block", "severity": 9.3, "slug": "advanced-301-and-302-redirect", "target": "plugin", "versions": "<=1.6.9"}, "RULE-CVE-2026-49069-01": {"ajax_action": "wpzoom_load_more_items", "conditions": [{"name": "ARGS:taxonomy", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+(?:src\\\\s*=\\\\s*[\'\\"]?(?:javascript|data):|onerror\\\\s*=)|=6.15.12 <=6.16.2 unauthenticated blind SQL injection via event_ids parameter on attendee registration page", "mode": "block", "severity": 9.3, "slug": "the-events-calendar", "tags": ["sql-injection", "unauthenticated", "blind-sqli"], "target": "plugin", "versions": ">=6.15.12 <=6.16.2"}, "RULE-CVE-2026-49772-02": {"ajax_action": "tec_qr_code_modal", "conditions": [{"name": "ARGS:post_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?[0-9]+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?[0-9]+|SLEEP\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|/\\\\*[^*]*\\\\*/|\\\\bCASE\\\\s+WHEN\\\\b|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-49772", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49772", "description": "The Events Calendar >=6.15.12 <=6.16.2 authenticated blind SQL injection via post_id in tec_qr_code_modal AJAX handler", "mode": "block", "severity": 9.3, "slug": "the-events-calendar", "tags": ["sql-injection", "authenticated", "blind-sqli"], "target": "plugin", "versions": ">=6.15.12 <=6.16.2"}, "RULE-CVE-2026-49774-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:rd_station_form_identifier", "type": "exists"}, {"name": "ARGS:rd_station_form_identifier", "type": "regex", "value": "~(?:php://|data://|phar://|expect://|glob://|(?:\\\\.\\\\.[\\\\\\\\/]){2,}|]|javascript\\\\s*:|<[^>]*\\\\bon[a-z]{3,20}\\\\s*=)~i"}, {"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 stored code injection via rd_station_form_identifier metabox field blocked for users lacking edit_others_posts capability", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["code-injection", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49774-02": {"ajax_action": "rd-persist-tokens", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 missing authorization on rd-persist-tokens AJAX handler (CWE-862)", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49774-03": {"ajax_action": "rd-persist-legacy-tokens", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 missing authorization on rd-persist-legacy-tokens AJAX handler (CWE-862)", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49774-04": {"ajax_action": "rdsm-disconnect-oauth", "conditions": [{"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 missing authorization on rdsm-disconnect-oauth AJAX handler (CWE-862) - blocks contributor and below", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49774-05": {"ajax_action": "rdsm-update-tracking-code-status", "conditions": [{"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 missing authorization on rdsm-update-tracking-code-status AJAX handler (CWE-862) - blocks contributor and below", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49774-08": {"ajax_action": "rdsm-authorization-check", "conditions": [{"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 missing authorization on rdsm-authorization-check AJAX handler (CWE-862) - blocks contributor and below", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49774-09": {"ajax_action": "rdsm-custom-fields", "conditions": [{"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-49774", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-49774", "description": "RD Station <=5.6.0 missing authorization on rdsm-custom-fields AJAX handler (CWE-862) - blocks contributor and below", "mode": "block", "severity": 9.9, "slug": "integracao-rd-station", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<=5.6.0"}, "RULE-CVE-2026-49776-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/gptranslate/v1/request(?:/|\\\\?|$)~"}, {"name": "ARGS:id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[!+]|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|MAKE_SET|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-49776", "description": "GPTranslate <=2.32.6 unauthenticated SQL injection via id parameter in gptranslate/v1/request REST endpoint", "mode": "block", "severity": 9.3, "slug": "gptranslate", "target": "plugin", "versions": "<=2.32.6"}, "RULE-CVE-2026-49781-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/suretriggers/v1/~"}, {"name": "ARGS", "type": "regex", "value": "~[OCa]:[0-9]+:[\\"\\\\{]~"}], "cve": "CVE-2026-49781", "description": "OttoKit (SureTriggers) <=1.1.27 unauthenticated PHP object injection via REST API", "mode": "block", "severity": 9.8, "slug": "suretriggers", "target": "plugin", "versions": "<=1.1.27"}, "RULE-CVE-2026-4987-01": {"ajax_action": "srfm_create_payment_intent", "conditions": [{"name": "ARGS:form_id", "type": "regex", "value": "~^(?![1-9][0-9]*$)~"}], "cve": "CVE-2026-4987", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4987", "description": "SureForms <=2.5.2 unauthenticated payment amount validation bypass via invalid form_id in srfm_create_payment_intent", "mode": "block", "severity": 7.5, "slug": "sureforms", "tags": ["improper-input-validation", "payment-bypass", "unauthenticated"], "target": "plugin", "versions": "<=2.5.2"}, "RULE-CVE-2026-4987-02": {"ajax_action": "srfm_create_subscription_intent", "conditions": [{"name": "ARGS:form_id", "type": "regex", "value": "~^(?![1-9][0-9]*$)~"}], "cve": "CVE-2026-4987", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-4987", "description": "SureForms <=2.5.2 unauthenticated payment amount validation bypass via invalid form_id in srfm_create_subscription_intent", "mode": "block", "severity": 7.5, "slug": "sureforms", "tags": ["improper-input-validation", "payment-bypass", "unauthenticated"], "target": "plugin", "versions": "<=2.5.2"}, "RULE-CVE-2026-5127-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "wpuf_submit_post"}, {"name": "ARGS:wpuf_files", "type": "regex", "value": "~(?:^|[^a-zA-Z0-9])(?:O|C|a):[0-9]+:(?:\\"|%22|%2522)~i"}], "cve": "CVE-2026-5127", "description": "WP User Frontend <=4.3.1 PHP object injection via wpuf_files parameter on admin-ajax.php action=wpuf_submit_post", "mode": "block", "severity": 8.8, "slug": "wp-user-frontend", "target": "plugin", "versions": "<=4.3.1"}, "RULE-CVE-2026-5149-01": {"ajax_action": "get_submission_content", "conditions": [{"name": "ARGS:entries_id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-5149", "description": "RTMKit <=2.0.7 missing authorization on get_submission_content allows contributor+ to view arbitrary form submissions via entries_id IDOR", "mode": "block", "severity": 6.5, "slug": "rometheme-for-elementor", "target": "plugin", "versions": "<=2.0.7"}, "RULE-CVE-2026-5159-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/(?:admin-ajax\\\\.php|post\\\\.php|admin-post\\\\.php)~i"}, {"name": "ARGS", "type": "regex", "value": "~instagram_follow_text[\\"\'\\\\\\\\\\\\s:]+[^\\"\']*(?:<[a-zA-Z/!]|javascript\\\\s*:|on(?:error|load|click|mouseover|focus|blur)\\\\s*=)~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-5159", "description": "Royal Elementor Addons <=1.7.1056 Contributor+ stored XSS via Instagram Feed widget instagram_follow_text setting", "mode": "block", "severity": 6.4, "slug": "royal-elementor-addons", "target": "plugin", "versions": "<=1.7.1056"}, "RULE-CVE-2026-5162-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "elementor_ajax"}, {"name": "ARGS:elementor_data", "type": "regex", "value": "~instagram_follow_text[^}]{0,4000}?(?:<(?:\\\\\\\\?/?)?(?:script[\\\\s/>]|iframe|object|embed|applet|svg|img\\\\b)|on(?:error|load|click|mouseover|mouseout|focus|blur|change|submit)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-5162", "description": "Royal Elementor Addons <=1.7.1056 stored XSS via instagram_follow_text in Instagram Feed widget", "mode": "block", "severity": 6.4, "slug": "royal-elementor-addons", "target": "plugin", "versions": "<=1.7.1056"}, "RULE-CVE-2026-5192-01": {"ajax_action": "forminator_submit_form_cform", "conditions": [{"name": "ARGS:upload-1[file][file_path]", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\/]){2,}|wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2026-5192", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5192", "description": "Forminator <=1.52.1 unauthenticated path traversal via upload-1[file][file_path] in form submit AJAX handler", "mode": "block", "severity": 7.5, "slug": "forminator", "tags": ["path-traversal", "file-upload", "unauthenticated"], "target": "plugin", "versions": "<=1.52.1"}, "RULE-CVE-2026-5192-02": {"ajax_action": "forminator_multiple_file_upload", "conditions": [{"name": "ARGS:file_data[file_path]", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\/]){2,}|wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)~i"}], "cve": "CVE-2026-5192", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5192", "description": "Forminator <=1.52.1 unauthenticated path traversal via file_data[file_path] in multiple file upload AJAX handler", "mode": "block", "severity": 7.5, "slug": "forminator", "tags": ["path-traversal", "file-upload", "unauthenticated"], "target": "plugin", "versions": "<=1.52.1"}, "RULE-CVE-2026-5200-01": {"ajax_action": "acymailing_router", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "acymailing_router"}, {"name": "ARGS:task", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-5200", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5200", "description": "AcyMailing <=10.8.2 missing authorization on acymailing_router allows authenticated subscriber+ privilege escalation", "mode": "block", "severity": 8.8, "slug": "acymailing", "tags": ["missing-authorization", "privilege-escalation", "authenticated"], "target": "plugin", "versions": "<=10.8.2"}, "RULE-CVE-2026-5207-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~admin-ajax\\\\.php~"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|IF\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[^*]*\\\\*/)~i"}], "cve": "CVE-2026-5207", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5207", "description": "LifterLMS <=9.2.1 authenticated SQL injection via order parameter in quiz non-attempts reporting (AJAX vector)", "mode": "block", "severity": 6.5, "slug": "lifterlms", "tags": ["sql-injection", "authenticated", "reporting"], "target": "plugin", "versions": "<=9.2.1"}, "RULE-CVE-2026-5207-02": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "llms-reporting"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|IF\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[^*]*\\\\*/)~i"}], "cve": "CVE-2026-5207", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5207", "description": "LifterLMS <=9.2.1 authenticated SQL injection via order parameter in quiz non-attempts reporting (admin page vector)", "method": "GET", "mode": "block", "severity": 6.5, "slug": "lifterlms", "tags": ["sql-injection", "authenticated", "reporting"], "target": "plugin", "versions": "<=9.2.1"}, "RULE-CVE-2026-5229-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/form-notify/v1/callback(?:[/?]|$)~"}, {"name": "REQUEST_COOKIES:form_notify_line_email", "type": "exists"}], "cve": "CVE-2026-5229", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5229", "description": "Form Notify <=1.1.10 unauthenticated authentication bypass via form_notify_line_email cookie on LINE OAuth callback", "mode": "block", "severity": 9.8, "slug": "form-notify", "tags": ["authentication-bypass", "improper-authentication", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=1.1.10"}, "RULE-CVE-2026-5231-01": {"action": "admin_init", "conditions": [{"name": "ARGS:tab", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+on[a-z]+=|]|]|]|])~i"}], "cve": "CVE-2026-5231", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5231", "description": "WP Statistics <=14.16.4 reflected XSS via unsanitized tab parameter in admin template", "mode": "block", "severity": 7.2, "slug": "wp-statistics", "tags": ["xss", "reflected", "admin-template"], "target": "plugin", "versions": "<=14.16.4"}, "RULE-CVE-2026-52693-01": {"ajax_action": "get_viariation_details", "conditions": [{"name": "ARGS:cart_content[/\\\\d+/]", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:SELECT|CONCAT)\\\\s*\\\\(.*FROM|INFORMATION_SCHEMA|LOAD_FILE\\\\s*\\\\()~i"}], "cve": "CVE-2026-52693", "description": "eCommerce Product Catalog <=3.5.5 unauthenticated SQL injection via cart_content in get_viariation_details AJAX handler", "mode": "block", "severity": 9.3, "slug": "ecommerce-product-catalog", "target": "plugin", "versions": "<=3.5.5"}, "RULE-CVE-2026-52693-02": {"ajax_action": "shopping_cart_products", "conditions": [{"name": "ARGS:raw", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:SELECT|CONCAT)\\\\s*\\\\(.*FROM|INFORMATION_SCHEMA|LOAD_FILE\\\\s*\\\\()~i"}], "cve": "CVE-2026-52693", "description": "eCommerce Product Catalog <=3.5.5 unauthenticated SQL injection via raw parameter in shopping_cart_products AJAX handler", "mode": "block", "severity": 9.3, "slug": "ecommerce-product-catalog", "target": "plugin", "versions": "<=3.5.5"}, "RULE-CVE-2026-52694-01": {"action": "init", "conditions": [{"name": "ARGS:document", "type": "exists"}, {"name": "ARGS:invitation", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}, {"name": "REQUEST_URI", "type": "regex", "value": "~^(?!/wp-admin/)~i"}], "cve": "CVE-2026-52694", "description": "Signature Add-On for WooCommerce <=2.0 unauthenticated sensitive data exposure via document and invitation parameters", "mode": "block", "severity": 7.5, "slug": "woocommerce-digital-signature", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2026-52694-02": {"action": "init", "conditions": [{"name": "ARGS:document", "type": "exists"}, {"name": "ARGS:download", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-52694", "description": "Signature Add-On for WooCommerce <=2.0 unauthenticated sensitive document download via document and download parameters", "mode": "block", "severity": 7.5, "slug": "woocommerce-digital-signature", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2026-52694-03": {"ajax_action": "esig_create_order_agreement", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-52694", "description": "Signature Add-On for WooCommerce <=2.0 missing authorization on esig_create_order_agreement AJAX handler", "mode": "block", "severity": 7.5, "slug": "woocommerce-digital-signature", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2026-52697-01": {"ajax_action": "wppm_filter_autocomplete", "conditions": [{"name": "ARGS:project_search", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-52697", "description": "Taskbuilder <=5.0.7 authenticated SQL injection via project_search in wppm_filter_autocomplete AJAX handler", "mode": "block", "severity": 8.5, "slug": "taskbuilder", "target": "plugin", "versions": "<=5.0.7"}, "RULE-CVE-2026-52697-02": {"ajax_action": "wppm_get_project_list", "conditions": [{"name": "ARGS:project_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-52697", "description": "Taskbuilder <=5.0.7 authenticated SQL injection via project_id in wppm_get_project_list AJAX handler", "mode": "block", "severity": 8.5, "slug": "taskbuilder", "target": "plugin", "versions": "<=5.0.7"}, "RULE-CVE-2026-52697-03": {"ajax_action": "wppm_get_task_list", "conditions": [{"name": "ARGS:task_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-52697", "description": "Taskbuilder <=5.0.7 authenticated SQL injection via task_id in wppm_get_task_list AJAX handler", "mode": "block", "severity": 8.5, "slug": "taskbuilder", "target": "plugin", "versions": "<=5.0.7"}, "RULE-CVE-2026-52697-04": {"ajax_action": "wppm_edit_task_status", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-52697", "description": "Taskbuilder <=5.0.7 authenticated SQL injection via id parameter in wppm_edit_task_status AJAX handler", "mode": "block", "severity": 8.5, "slug": "taskbuilder", "target": "plugin", "versions": "<=5.0.7"}, "RULE-CVE-2026-52697-05": {"ajax_action": "wppm_get_task_list_card_view", "conditions": [{"name": "ARGS:page_no", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-52697", "description": "Taskbuilder <=5.0.7 authenticated SQL injection via page_no in wppm_get_task_list_card_view AJAX handler", "mode": "block", "severity": 8.5, "slug": "taskbuilder", "target": "plugin", "versions": "<=5.0.7"}, "RULE-CVE-2026-52697-06": {"ajax_action": "wppm_drag_and_drop_card", "conditions": [{"name": "ARGS:proj_ids", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-52697", "description": "Taskbuilder <=5.0.7 authenticated SQL injection via proj_ids in wppm_drag_and_drop_card AJAX handler", "mode": "block", "severity": 8.5, "slug": "taskbuilder", "target": "plugin", "versions": "<=5.0.7"}, "RULE-CVE-2026-52702-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "seo-redirection.php"}, {"name": "ARGS:redirect_from", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|%3Cscript|%3[Ee]|]+on[a-z]+=)~i"}], "cve": "CVE-2026-52702", "description": "SEO Redirection <=9.17 unauthenticated reflected XSS via redirect_from parameter on admin page", "mode": "block", "severity": 7.1, "slug": "seo-redirection", "target": "plugin", "versions": "<=9.17"}, "RULE-CVE-2026-52702-02": {"ajax_action": "customAddUpdate", "conditions": [{"name": "ARGS:redirect_from", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:\'|%27)\\\\s*(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d)~i"}, {"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-52702", "description": "SEO Redirection <=9.17 authenticated SQL injection via redirect_from in customAddUpdate AJAX handler", "mode": "block", "severity": 7.1, "slug": "seo-redirection", "target": "plugin", "versions": "<=9.17"}, "RULE-CVE-2026-52703-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/njt-fastdup/v1/packages/download(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-52703", "description": "FastDup <=2.7.2 unauthenticated path traversal via packages/download REST endpoint", "mode": "block", "severity": 9.6, "slug": "fastdup", "target": "plugin", "versions": "<=2.7.2"}, "RULE-CVE-2026-52703-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/njt-fastdup/v1/packages/view-log(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-52703", "description": "FastDup <=2.7.2 unauthenticated path traversal via packages/view-log REST endpoint", "mode": "block", "severity": 9.6, "slug": "fastdup", "target": "plugin", "versions": "<=2.7.2"}, "RULE-CVE-2026-52703-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/njt-fastdup/v1/template/directory-tree(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-52703", "description": "FastDup <=2.7.2 unauthenticated path traversal via template/directory-tree REST endpoint", "mode": "block", "severity": 9.6, "slug": "fastdup", "target": "plugin", "versions": "<=2.7.2"}, "RULE-CVE-2026-5294-01": {"ajax_action": "geekybot_frontendajax", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-5294", "description": "Geeky Bot <=1.2.2 unauthenticated arbitrary plugin installation via geekybot_frontendajax AJAX handler", "mode": "block", "severity": 9.8, "slug": "geeky-bot", "target": "plugin", "versions": "<=1.2.2"}, "RULE-CVE-2026-5324-01": {"ajax_action": "brizy_form_submit", "conditions": [{"name": "ARGS:data[fields][FileUpload]", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-5324", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5324", "description": "Brizy \\u2013 Page Builder <=2.8.11 unauthenticated stored XSS via form submission FileUpload field value", "mode": "block", "severity": 7.2, "slug": "brizy", "tags": ["xss", "stored", "unauthenticated"], "target": "plugin", "versions": "<=2.8.11"}, "RULE-CVE-2026-5364-01": {"ajax_action": "cf7_file_uploads", "conditions": [{"name": "ARGS:type", "type": "regex", "value": "~(?:^|\\\\|)\\\\s*(?:ph(?:p[2-9s]?|tml?|ar)|s?html?|cgi|aspx?|jspx?|cfm|htaccess|user\\\\.ini)\\\\s*(?:\\\\||$)~i"}], "cve": "CVE-2026-5364", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5364", "description": "Drag and Drop File Upload for Contact Form 7 <=1.1.3 unauthenticated arbitrary PHP file upload via extension validation bypass in cf7_file_uploads AJAX handler", "mode": "block", "severity": 8.1, "slug": "drag-and-drop-file-upload-for-contact-form-7", "tags": ["arbitrary-file-upload", "remote-code-execution", "unauthenticated", "extension-bypass"], "target": "plugin", "versions": "<=1.1.3"}, "RULE-CVE-2026-5371-01": {"ajax_action": "monsterinsights_ads_get_token", "conditions": [{"type": "missing_capability", "value": "monsterinsights_save_settings"}], "cve": "CVE-2026-5371", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5371", "description": "MonsterInsights Google Analytics for WordPress <=10.1.2 Subscriber+ unauthorized access to Google OAuth access tokens via monsterinsights_ads_get_token AJAX handler", "mode": "block", "severity": 7.1, "slug": "google-analytics-for-wordpress", "tags": ["missing-authorization", "privilege-escalation", "oauth-token-exposure"], "target": "plugin", "versions": "<=10.1.2"}, "RULE-CVE-2026-5371-02": {"ajax_action": "monsterinsights_ads_reset_experience", "conditions": [{"type": "missing_capability", "value": "monsterinsights_save_settings"}], "cve": "CVE-2026-5371", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5371", "description": "MonsterInsights Google Analytics for WordPress <=10.1.2 Subscriber+ unauthorized reset of Google Ads integration via monsterinsights_ads_reset_experience AJAX handler", "mode": "block", "severity": 7.1, "slug": "google-analytics-for-wordpress", "tags": ["missing-authorization", "privilege-escalation", "integration-reset"], "target": "plugin", "versions": "<=10.1.2"}, "RULE-CVE-2026-5371-03": {"ajax_action": "monsterinsights_ads_get_settings", "conditions": [{"type": "missing_capability", "value": "monsterinsights_save_settings"}], "cve": "CVE-2026-5371", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5371", "description": "MonsterInsights Google Analytics for WordPress <=10.1.2 Subscriber+ unauthorized access to Google Ads settings via monsterinsights_ads_get_settings AJAX handler", "mode": "block", "severity": 7.1, "slug": "google-analytics-for-wordpress", "tags": ["missing-authorization", "information-disclosure", "settings-exposure"], "target": "plugin", "versions": "<=10.1.2"}, "RULE-CVE-2026-5399-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/(?:profile|user-edit)\\\\.php~i"}, {"name": "ARGS:redux_users_meta_nonce", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~[0-9]+(?:\\\\.[0-9]+)?\\\\s+[^\\"\'<>]{0,80}?\\\\bon[a-z]+\\\\s*=~i"}], "cve": "CVE-2026-5399", "description": "Redux Framework <=4.5.13.1 authenticated (subscriber+) stored XSS via slider field attribute breakout in profile save handler", "mode": "block", "slug": "redux-framework", "target": "plugin", "versions": "<=4.5.13.1"}, "RULE-CVE-2026-5400-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/(?:profile|user-edit)\\\\.php~i"}, {"name": "ARGS:redux_users_meta_nonce", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|mouseout|click|dblclick|focus|blur|change|input|submit|keydown|keyup)\\\\s*=|javascript\\\\s*:|data\\\\s*:\\\\s*text/html)~i"}], "cve": "CVE-2026-5400", "description": "Redux Framework <=4.5.13 subscriber+ stored XSS via unsanitized nested Media field filter value in profile save (user_meta_save)", "mode": "block", "slug": "redux-framework", "target": "plugin", "versions": "<=4.5.13"}, "RULE-CVE-2026-5410-01": {"action": "personal_options_update", "conditions": [{"name": "ARGS:redux_users_meta_nonce", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|mouseout|click|dblclick|focus|blur|change|keyup|keydown|submit|animationstart|pointerover|focusin)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-5410", "description": "Redux Framework <=4.5.13 authenticated (subscriber+) stored XSS via spinner field in own profile save (user_meta_save)", "mode": "block", "severity": 6.4, "slug": "redux-framework", "target": "plugin", "versions": "<=4.5.13"}, "RULE-CVE-2026-5410-02": {"action": "edit_user_profile_update", "conditions": [{"name": "ARGS:redux_users_meta_nonce", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|mouseout|click|dblclick|focus|blur|change|keyup|keydown|submit|animationstart|pointerover|focusin)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-5410", "description": "Redux Framework <=4.5.13 authenticated (subscriber+) stored XSS via spinner field when saving another user\'s profile (user_meta_save)", "mode": "block", "severity": 6.4, "slug": "redux-framework", "target": "plugin", "versions": "<=4.5.13"}, "RULE-CVE-2026-54191-01": {"ajax_action": "pq_loadpod", "conditions": [{"name": "ARGS:pod", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]|]*on[a-z]+=|]|]|])~i"}], "cve": "CVE-2026-54191", "description": "Pods <=3.3.8 reflected XSS via pod parameter in pq_loadpod AJAX handler", "mode": "block", "severity": 7.1, "slug": "pods", "target": "plugin", "versions": "<=3.3.8"}, "RULE-CVE-2026-54192-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "ays-pb"}, {"name": "ARGS:ays_pb_tab", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*img[^>]+on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-54192", "description": "Popup Box <=6.2.9 unauthenticated reflected XSS via ays_pb_tab parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.2.9"}, "RULE-CVE-2026-54192-02": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "ays-pb"}, {"name": "ARGS:popup_category", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*img[^>]+on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-54192", "description": "Popup Box <=6.2.9 unauthenticated reflected XSS via popup_category parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.2.9"}, "RULE-CVE-2026-54192-03": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "ays-pb"}, {"name": "ARGS:type", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*img[^>]+on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-54192", "description": "Popup Box <=6.2.9 unauthenticated reflected XSS via type parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.2.9"}, "RULE-CVE-2026-54192-04": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "ays-pb"}, {"name": "ARGS:popupbox", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|<\\\\s*img[^>]+on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-54192", "description": "Popup Box <=6.2.9 unauthenticated reflected XSS via popupbox parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.2.9"}, "RULE-CVE-2026-54196-01": {"ajax_action": "jet_form_builder_submit", "conditions": [{"name": "ARGS:_jf_form_id", "type": "exists"}, {"name": "ARGS:role", "type": "exists"}, {"type": "missing_capability", "value": "promote_users"}], "cve": "CVE-2026-54196", "description": "JetFormBuilder <= 3.6.1 - Authenticated (Subscriber+) Privilege Escalation via Update User Action", "mode": "block", "severity": 6.8, "slug": "jetformbuilder", "target": "plugin", "versions": "<=3.6.1"}, "RULE-CVE-2026-5425-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/trustindex-feed-instagram/v1/webhook(?:[/?]|$)~"}, {"name": "ARGS:data[feed_data]", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-5425", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5425", "description": "Social Photo Feed Widget <=1.7.9 unauthenticated stored XSS via REST webhook feed_data injection", "method": "POST", "mode": "block", "severity": 7.2, "slug": "social-photo-feed-widget", "tags": ["xss", "stored", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=1.7.9"}, "RULE-CVE-2026-5427-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages|templates|template-parts)(?:/[0-9]+)?(?:[/?]|$)~i"}, {"name": "ARGS:content", "type": "regex", "value": "~\\"kubio\\"[\\\\s\\\\S]{0,1000}?\\\\bhttps?://~i"}, {"name": "", "type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2026-5427", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5427", "description": "Kubio AI Page Builder <=2.7.2 missing authorization on rest_pre_insert allows contributor-level arbitrary remote file import via kubio block attribute URL", "mode": "block", "severity": 5.3, "slug": "kubio", "tags": ["missing-authorization", "arbitrary-file-upload", "authenticated"], "target": "plugin", "versions": "<=2.7.2"}, "RULE-CVE-2026-5465-01": {"ajax_action": "wpamelia_api", "conditions": [{"name": "ARGS:call", "type": "regex", "value": "~users/providers/~i"}, {"name": "ARGS:externalId", "type": "exists"}, {"name": "ARGS:password", "type": "exists"}], "cve": "CVE-2026-5465", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5465", "description": "Amelia Booking <=2.1.3 IDOR account takeover via externalId in provider profile update (wpamelia_api)", "method": "POST", "mode": "block", "severity": 8.8, "slug": "ameliabooking", "tags": ["idor", "account-takeover", "insecure-direct-object-reference", "authenticated"], "target": "plugin", "versions": "<=2.1.3"}, "RULE-CVE-2026-5478-01": {"action": "init", "conditions": [{"name": "ARGS:everest_forms", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\\\\\/]){2,}(?:.*(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log))?~i"}], "cve": "CVE-2026-5478", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5478", "description": "Everest Forms <=3.4.4 unauthenticated arbitrary file read and deletion via path traversal in old_files parameter", "method": "POST", "mode": "block", "severity": 8.1, "slug": "everest-forms", "tags": ["path-traversal", "local-file-inclusion", "arbitrary-file-deletion", "unauthenticated"], "target": "plugin", "versions": "<=3.4.4"}, "RULE-CVE-2026-54802-01": {"ajax_action": "process_campaign", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54802", "description": "Block unauthenticated access to process_campaign AJAX action (CWE-862 Missing Authorization)", "mode": "block", "severity": 7.5, "slug": "sms-alert", "target": "plugin", "versions": "<=3.9.3"}, "RULE-CVE-2026-54805-01": {"action": "personal_options_update", "conditions": [{"name": "ARGS:falang_user", "type": "exists"}, {"name": "ARGS:user_id", "type": "not_current_user"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2026-54805", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805", "description": "Falang multilanguage <=1.4.2 subscriber+ privilege escalation via profile update IDOR (personal_options_update)", "mode": "block", "severity": 8.8, "slug": "falang", "tags": ["privilege-escalation", "missing-authorization", "idor"], "target": "plugin", "versions": "<=1.4.2"}, "RULE-CVE-2026-54805-02": {"action": "edit_user_profile_update", "conditions": [{"name": "ARGS:falang_user", "type": "exists"}, {"name": "ARGS:user_id", "type": "not_current_user"}, {"type": "missing_capability", "value": "edit_users"}], "cve": "CVE-2026-54805", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54805", "description": "Falang multilanguage <=1.4.2 subscriber+ privilege escalation via profile update IDOR (edit_user_profile_update)", "mode": "block", "severity": 8.8, "slug": "falang", "tags": ["privilege-escalation", "missing-authorization", "idor"], "target": "plugin", "versions": "<=1.4.2"}, "RULE-CVE-2026-54810-01": {"ajax_action": "build_payment_payload", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54810", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54810", "description": "Nexi XPay <=8.3.1 missing authorization on build_payment_payload AJAX handler allows unauthenticated DoS", "mode": "block", "severity": 7.5, "slug": "cartasi-x-pay", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=8.3.1"}, "RULE-CVE-2026-54810-02": {"ajax_action": "apple_pay_validate_merchant", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54810", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54810", "description": "Nexi XPay <=8.3.1 missing authorization on apple_pay_validate_merchant AJAX handler allows unauthenticated DoS", "mode": "block", "severity": 7.5, "slug": "cartasi-x-pay", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=8.3.1"}, "RULE-CVE-2026-54810-03": {"ajax_action": "validate_checkout_form", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54810", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54810", "description": "Nexi XPay <=8.3.1 missing authorization on validate_checkout_form AJAX handler allows unauthenticated DoS", "mode": "block", "severity": 7.5, "slug": "cartasi-x-pay", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=8.3.1"}, "RULE-CVE-2026-54810-04": {"ajax_action": "get_build_fields", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54810", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54810", "description": "Nexi XPay <=8.3.1 missing authorization on get_build_fields AJAX handler allows unauthenticated DoS", "mode": "block", "severity": 7.5, "slug": "cartasi-x-pay", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<=8.3.1"}, "RULE-CVE-2026-54813-01": {"ajax_action": "suredash_lost_password", "conditions": [{"name": "ARGS:login", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|(?:SLEEP|BENCHMARK|WAITFOR)\\\\s*\\\\(|(?:\'|\\"|\\\\.\\\\.)\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-54813", "description": "SureDash <=1.8.0 blind SQL injection via login parameter in suredash_lost_password AJAX handler", "mode": "block", "severity": 8.5, "slug": "suredash", "target": "plugin", "versions": "<=1.8.0"}, "RULE-CVE-2026-54813-02": {"ajax_action": "suredash_reset_password", "conditions": [{"name": "ARGS:login", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|(?:SLEEP|BENCHMARK|WAITFOR)\\\\s*\\\\(|(?:\'|\\"|\\\\.\\\\.)\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-54813", "description": "SureDash <=1.8.0 blind SQL injection via login parameter in suredash_reset_password AJAX handler", "mode": "block", "severity": 8.5, "slug": "suredash", "target": "plugin", "versions": "<=1.8.0"}, "RULE-CVE-2026-54813-03": {"ajax_action": "suredash_lost_password", "conditions": [{"name": "ARGS:key", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|(?:SLEEP|BENCHMARK|WAITFOR)\\\\s*\\\\(|(?:\'|\\"|\\\\.\\\\.)\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-54813", "description": "SureDash <=1.8.0 blind SQL injection via key parameter in suredash_lost_password AJAX handler", "mode": "block", "severity": 8.5, "slug": "suredash", "target": "plugin", "versions": "<=1.8.0"}, "RULE-CVE-2026-54813-04": {"ajax_action": "suredash_reset_password", "conditions": [{"name": "ARGS:key", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|(?:SLEEP|BENCHMARK|WAITFOR)\\\\s*\\\\(|(?:\'|\\"|\\\\.\\\\.)\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-54813", "description": "SureDash <=1.8.0 blind SQL injection via key parameter in suredash_reset_password AJAX handler", "mode": "block", "severity": 8.5, "slug": "suredash", "target": "plugin", "versions": "<=1.8.0"}, "RULE-CVE-2026-54814-01": {"ajax_action": "mvl_motors_starter_template", "conditions": [{"name": "ARGS:template", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log|error_log))~i"}], "cve": "CVE-2026-54814", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54814", "description": "Motors <=1.4.109 unauthenticated local file inclusion via template parameter in mvl_motors_starter_template AJAX handler", "mode": "block", "severity": 8.1, "slug": "motors-car-dealership-classified-listings", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=1.4.109"}, "RULE-CVE-2026-54814-02": {"ajax_action": "mvl_motors_starter_demo_install", "conditions": [{"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-54814", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54814", "description": "Motors <=1.4.109 missing authorization on mvl_motors_starter_demo_install allows unauthenticated file write/delete", "mode": "block", "severity": 8.1, "slug": "motors-car-dealership-classified-listings", "tags": ["missing-authorization", "arbitrary-file-write", "unauthenticated"], "target": "plugin", "versions": "<=1.4.109"}, "RULE-CVE-2026-54818-01": {"ajax_action": "slimstat_load_report", "conditions": [{"name": "ARGS:pageview_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|SELECT)\\\\s|\\\\b(?:AND|OR)\\\\s+(?:\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()|/\\\\*[^*]*\\\\*/|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-54818", "description": "Slimstat Analytics <=5.4.11 authenticated (Subscriber+) blind SQL injection via pageview_id in slimstat_load_report AJAX handler", "mode": "block", "severity": 8.5, "slug": "wp-slimstat", "target": "plugin", "versions": "<=5.4.11"}, "RULE-CVE-2026-54819-01": {"ajax_action": "lsd_accordion_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in accordion sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-02": {"ajax_action": "lsd_grid_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in grid sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-03": {"ajax_action": "lsd_list_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in list sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-04": {"ajax_action": "lsd_gallery_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in gallery sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-05": {"ajax_action": "lsd_halfmap_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in halfmap sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-06": {"ajax_action": "lsd_masonry_load_more", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in masonry load_more AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-07": {"ajax_action": "lsd_mosaic_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in mosaic sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-08": {"ajax_action": "lsd_listgrid_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in listgrid sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-09": {"ajax_action": "lsd_side_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in side sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-10": {"ajax_action": "lsd_table_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in table sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54819-11": {"ajax_action": "lsd_timeline_sort", "conditions": [{"name": "ARGS:sort", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\\"\']+\\\\s*=\\\\s*[\\\\d\\"\']|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|FIELD|IF|CASE\\\\s+WHEN)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54819", "description": "Listdom <=5.4.0 unauthenticated blind SQL injection via sort parameter in timeline sort AJAX handler", "mode": "block", "severity": 9.3, "slug": "listdom", "target": "plugin", "versions": "<=5.4.0"}, "RULE-CVE-2026-54821-01": {"ajax_action": "vlp_get_template", "conditions": [{"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-54821", "description": "Visual Link Preview <=2.3.1 subscriber+ sensitive data exposure via vlp_get_template AJAX handler missing capability check", "mode": "block", "severity": 7.4, "slug": "visual-link-preview", "target": "plugin", "versions": "<=2.3.1"}, "RULE-CVE-2026-54822-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/salesmanago/~"}, {"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+\\\\b|\\\\bAND\\\\s+(?:SLEEP|BENCHMARK)\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|/\\\\*[!+]|(?:--|#)\\\\s)~i"}, {"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54822", "description": "SALESmanago & Leadoo <=3.11.2 subscriber+ SQL injection via REST API endpoint", "mode": "block", "severity": 8.5, "slug": "salesmanago", "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-54823-01": {"ajax_action": "widgetopts_get_settings_ajax", "conditions": [{"name": "ARGS:post_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-54823", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54823", "description": "Widget Options <=4.2.3 authenticated (Contributor+) broken access control on arbitrary post_id via widgetopts_get_settings_ajax AJAX handler", "mode": "pass", "severity": 9.9, "slug": "widget-options", "tags": ["missing-authorization", "broken-access-control", "authenticated"], "target": "plugin", "versions": "<=4.2.3"}, "RULE-CVE-2026-54825-01": {"ajax_action": "wdtable_update_cache", "conditions": [{"name": "ARGS:table_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML|LOAD_FILE)\\\\s*\\\\(|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-54825", "description": "wpDataTables <=7.4 unauthenticated SQL injection via table_id in wdtable_update_cache AJAX handler", "mode": "block", "severity": 9.3, "slug": "wpdatatables", "target": "plugin", "versions": "<=7.4"}, "RULE-CVE-2026-54828-01": {"ajax_action": "mvl_motors_starter_template", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54828", "description": "Block unauthenticated access to mvl_motors_starter_template AJAX handler (LFI via include sink)", "mode": "block", "severity": 7.5, "slug": "motors-car-dealership-classified-listings", "target": "plugin", "versions": "<=1.4.109"}, "RULE-CVE-2026-54828-02": {"ajax_action": "mvl_motors_starter_demo_install", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54828", "description": "Block unauthenticated access to mvl_motors_starter_demo_install AJAX handler (file_put_contents/unlink sinks)", "mode": "block", "severity": 7.5, "slug": "motors-car-dealership-classified-listings", "target": "plugin", "versions": "<=1.4.109"}, "RULE-CVE-2026-54831-01": {"ajax_action": "geodir_get_sort_options", "conditions": [{"name": "ARGS:sort_order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\'\\"]+\\\\s*=\\\\s*[\\\\d\'\\"]+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:EX|EXTRAC)TRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|(?:IF|CASE)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54831", "description": "GeoDirectory <=2.8.162 unauthenticated SQL injection via sort_order in geodir_get_sort_options AJAX handler", "mode": "block", "severity": 9.3, "slug": "geodirectory", "target": "plugin", "versions": "<=2.8.162"}, "RULE-CVE-2026-54831-02": {"ajax_action": "geodir_get_sort_options", "conditions": [{"name": "ARGS:package_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\'\\"]+\\\\s*=\\\\s*[\\\\d\'\\"]+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:EX|EXTRAC)TRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-54831", "description": "GeoDirectory <=2.8.162 unauthenticated SQL injection via package_id in geodir_get_sort_options AJAX handler", "mode": "block", "severity": 9.3, "slug": "geodirectory", "target": "plugin", "versions": "<=2.8.162"}, "RULE-CVE-2026-54831-03": {"ajax_action": "geodir_get_sort_options", "conditions": [{"name": "ARGS:sort_by", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\\\\d\'\\"]+\\\\s*=\\\\s*[\\\\d\'\\"]+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:EX|EXTRAC)TRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|(?:IF|CASE)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54831", "description": "GeoDirectory <=2.8.162 unauthenticated SQL injection via sort_by in geodir_get_sort_options AJAX handler", "mode": "block", "severity": 9.3, "slug": "geodirectory", "target": "plugin", "versions": "<=2.8.162"}, "RULE-CVE-2026-54832-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/gutenverse-essence/v1/gutenverse-essence-proxy~"}, {"type": "missing_capability", "value": "edit_theme_options"}], "cve": "CVE-2026-54832", "description": "Block unauthenticated access to gutenverse-essence REST proxy route (missing authorization \\u2013 permission_callback was __return_true in <=2.5.0)", "mode": "block", "severity": 7.5, "slug": "gutenverse-companion", "target": "plugin", "versions": "<=2.5.0"}, "RULE-CVE-2026-54836-01": {"ajax_action": "ymc_get_posts", "conditions": [{"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54836", "description": "YMC Filter <=3.11.5 unauthenticated SQL injection via order parameter in ymc_get_posts AJAX handler", "mode": "block", "severity": 9.3, "slug": "ymc-smart-filter", "target": "plugin", "versions": "<=3.11.5"}, "RULE-CVE-2026-54836-02": {"ajax_action": "ymc_get_posts", "conditions": [{"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54836", "description": "YMC Filter <=3.11.5 unauthenticated SQL injection via orderby parameter in ymc_get_posts AJAX handler", "mode": "block", "severity": 9.3, "slug": "ymc-smart-filter", "target": "plugin", "versions": "<=3.11.5"}, "RULE-CVE-2026-54836-03": {"ajax_action": "ymc_autocomplete_search", "conditions": [{"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54836", "description": "YMC Filter <=3.11.5 unauthenticated SQL injection via order parameter in ymc_autocomplete_search AJAX handler", "mode": "block", "severity": 9.3, "slug": "ymc-smart-filter", "target": "plugin", "versions": "<=3.11.5"}, "RULE-CVE-2026-54836-04": {"ajax_action": "ymc_autocomplete_search", "conditions": [{"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54836", "description": "YMC Filter <=3.11.5 unauthenticated SQL injection via orderby parameter in ymc_autocomplete_search AJAX handler", "mode": "block", "severity": 9.3, "slug": "ymc-smart-filter", "target": "plugin", "versions": "<=3.11.5"}, "RULE-CVE-2026-54836-05": {"ajax_action": "get_post_popup", "conditions": [{"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54836", "description": "YMC Filter <=3.11.5 unauthenticated SQL injection via order parameter in get_post_popup AJAX handler", "mode": "block", "severity": 9.3, "slug": "ymc-smart-filter", "target": "plugin", "versions": "<=3.11.5"}, "RULE-CVE-2026-54836-06": {"ajax_action": "get_post_popup", "conditions": [{"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}], "cve": "CVE-2026-54836", "description": "YMC Filter <=3.11.5 unauthenticated SQL injection via orderby parameter in get_post_popup AJAX handler", "mode": "block", "severity": 9.3, "slug": "ymc-smart-filter", "target": "plugin", "versions": "<=3.11.5"}, "RULE-CVE-2026-54840-01": {"ajax_action": "newsletters_forms_createform", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_forms_createform AJAX handler allows subscriber+ form creation", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54840-02": {"ajax_action": "newsletters_forms_addfield", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_forms_addfield AJAX handler allows subscriber+ form field addition", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54840-03": {"ajax_action": "newsletters_forms_deletefield", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_forms_deletefield AJAX handler allows subscriber+ form field deletion", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54840-04": {"ajax_action": "newsletters_admin_mode", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_admin_mode AJAX handler allows subscriber+ admin mode toggle", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54840-05": {"ajax_action": "newsletters_change_themefolder", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_change_themefolder AJAX handler allows subscriber+ theme folder change", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54840-06": {"ajax_action": "newsletters_delete_option", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_delete_option AJAX handler allows subscriber+ option deletion", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54840-07": {"ajax_action": "newsletters_pause_queue", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54840", "description": "Newsletters <=4.13 missing authorization on newsletters_pause_queue AJAX handler allows subscriber+ queue manipulation", "mode": "block", "severity": 7.3, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-54841-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/apbd-vtpos/v1/(?:current-user|get-logged-user|cashier-details|cash-drawer-info|cash-drawer-list|all-outlet-list|all-categories|all-taxes|heart-bit|list|details|end-of-day-data|categories|countries|attributes|getStock|close-cash-drawer|logout|email)(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54841", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-54841", "description": "VitePOS Lite <=3.4.2 unauthenticated sensitive data exposure via REST API endpoints missing permission callbacks", "mode": "block", "severity": 7.5, "slug": "vitepos-lite", "tags": ["missing-authorization", "information-disclosure", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=3.4.2"}, "RULE-CVE-2026-54842-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/royal-mcp/v1/messages(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-54842", "description": "Royal MCP <=1.4.25 missing authorization on royal-mcp/v1/messages REST endpoint allows subscriber+ access to privileged integration handlers", "mode": "block", "severity": 8.1, "slug": "royal-mcp", "target": "plugin", "versions": "<=1.4.25"}, "RULE-CVE-2026-54844-01": {"ajax_action": "checkview_get_status", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54844", "description": "Block unauthenticated/unauthorized access to checkview_get_status AJAX action (CWE-862: Missing Authorization). Patch removes both wp_ajax_nopriv_checkview_get_status and wp_ajax_checkview_get_status hooks entirely.", "mode": "block", "severity": 7.5, "slug": "checkview", "target": "plugin", "versions": "<=2.1.0"}, "RULE-CVE-2026-54844-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/checkview/v1/checkview-status(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-54844", "description": "Block unauthenticated/unauthorized access to checkview/v1/checkview-status REST route (CWE-862: Missing Authorization). Patch adds permission_callback with current_user_can(\'manage_options\') and nonce verification.", "mode": "block", "severity": 7.5, "slug": "checkview", "target": "plugin", "versions": "<=2.1.0"}, "RULE-CVE-2026-54849-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/premmerce/wishlist/~i"}, {"name": "ARGS:productId", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|\\\\bAND\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2026-54849", "description": "Premmerce Wishlist for WooCommerce <=1.1.11 unauthenticated SQL injection via productId in REST API wishlist endpoints", "mode": "block", "severity": 9.3, "slug": "premmerce-woocommerce-wishlist", "target": "plugin", "versions": "<=1.1.11"}, "RULE-CVE-2026-54849-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/premmerce/wishlist/~i"}, {"name": "ARGS:wishlist_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|\\\\bAND\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2026-54849", "description": "Premmerce Wishlist for WooCommerce <=1.1.11 unauthenticated SQL injection via wishlist_id in REST API wishlist endpoints", "mode": "block", "severity": 9.3, "slug": "premmerce-woocommerce-wishlist", "target": "plugin", "versions": "<=1.1.11"}, "RULE-CVE-2026-54849-03": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[?&]wc-ajax=premmerce_wishlist_popup~"}, {"name": "ARGS:productId", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|\\\\bAND\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2026-54849", "description": "Premmerce Wishlist for WooCommerce <=1.1.11 unauthenticated SQL injection via productId in WC AJAX wishlist popup handler", "mode": "block", "severity": 9.3, "slug": "premmerce-woocommerce-wishlist", "target": "plugin", "versions": "<=1.1.11"}, "RULE-CVE-2026-5488-01": {"ajax_action": "exactmetrics_ads_get_token", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-5488", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5488", "description": "ExactMetrics <=9.1.2 missing authorization on exactmetrics_ads_get_token allows subscriber+ role access to Google Ads OAuth token", "mode": "block", "severity": 5.3, "slug": "google-analytics-dashboard-for-wp", "tags": ["missing-authorization", "authenticated", "broken-access-control"], "target": "plugin", "versions": "<=9.1.2"}, "RULE-CVE-2026-5488-02": {"ajax_action": "exactmetrics_ads_reset_experience", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-5488", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5488", "description": "ExactMetrics <=9.1.2 missing authorization on exactmetrics_ads_reset_experience allows subscriber+ role to reset Google Ads experience", "mode": "block", "severity": 5.3, "slug": "google-analytics-dashboard-for-wp", "tags": ["missing-authorization", "authenticated", "broken-access-control"], "target": "plugin", "versions": "<=9.1.2"}, "RULE-CVE-2026-5502-01": {"ajax_action": "tutor_update_course_content_order", "conditions": [{"name": "ARGS:data", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-5502", "mode": "block", "severity": 5.3, "slug": "tutor", "target": "plugin", "versions": "<=3.9.7"}, "RULE-CVE-2026-56006-01": {"ajax_action": "h5p_embed", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-56006", "description": "H5P <=1.17.6 unauthenticated reflected XSS via id parameter in h5p_embed AJAX handler", "mode": "block", "severity": 7.1, "slug": "h5p", "target": "plugin", "versions": "<=1.17.6"}, "RULE-CVE-2026-56011-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/mapp/v1/(?:maps|maps/(?:clone|import))(?:/|\\\\?|$)~"}, {"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]*on\\\\w+\\\\s*=|]*on\\\\w+\\\\s*=|]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-56014", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56014", "description": "Master Slider <=3.11.2 reflected XSS via slider_params parameter on admin preview page", "mode": "block", "severity": 7.1, "slug": "master-slider", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-56014-02": {"action": "init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "masterslider"}, {"name": "ARGS:slider_id", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-56014", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56014", "description": "Master Slider <=3.11.2 reflected XSS via slider_id parameter on admin preview page", "mode": "block", "severity": 7.1, "slug": "master-slider", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-56014-03": {"action": "init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "masterslider"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-56014", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56014", "description": "Master Slider <=3.11.2 reflected XSS via orderby parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "master-slider", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-56014-04": {"action": "init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "masterslider"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-56014", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56014", "description": "Master Slider <=3.11.2 reflected XSS via order parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "master-slider", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-56014-05": {"action": "init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "masterslider"}, {"name": "ARGS:post_mime_type", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-56014", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56014", "description": "Master Slider <=3.11.2 reflected XSS via post_mime_type parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "master-slider", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-56014-06": {"action": "init", "conditions": [{"name": "ARGS:page", "type": "contains", "value": "masterslider"}, {"name": "ARGS:detached", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-56014", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56014", "description": "Master Slider <=3.11.2 reflected XSS via detached parameter on admin list table page", "mode": "block", "severity": 7.1, "slug": "master-slider", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=3.11.2"}, "RULE-CVE-2026-56027-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~wcj-my-products~i"}, {"name": "FILES:wcj_add_new_product_image:name", "type": "regex", "value": "~(?:\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar|gif)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$)~i"}], "cve": "CVE-2026-56027", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56027", "description": "Booster for WooCommerce (woocommerce-jetpack) <=8.0.1 authenticated Customer arbitrary file upload via Product by User image field", "mode": "pass", "severity": 9.9, "slug": "woocommerce-jetpack", "tags": ["arbitrary-file-upload", "unrestricted-upload", "authenticated"], "target": "plugin", "versions": "<=8.0.1"}, "RULE-CVE-2026-56028-01": {"ajax_action": "eel_register", "conditions": [{"name": "ARGS:role", "type": "regex", "value": "~^(?:administrator|editor|author)$~i"}], "cve": "CVE-2026-56028", "description": "Easy Elements for Elementor <=1.4.9 unauthenticated privilege escalation via role parameter in eel_register AJAX handler", "mode": "block", "severity": 9.8, "slug": "easy-elements", "target": "plugin", "versions": "<=1.4.9"}, "RULE-CVE-2026-56030-01": {"ajax_action": "pt_ajax_check_item_limits", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56030", "description": "Paytium <=5.0.2 unauthenticated privilege escalation via pt_ajax_check_item_limits", "mode": "block", "severity": 9.8, "slug": "paytium", "target": "plugin", "versions": "<=5.0.2"}, "RULE-CVE-2026-56036-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:order_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-56036", "description": "PGAll for WooCommerce <=5.5.6 unauthenticated SQL injection via order_id parameter", "mode": "block", "severity": 9.3, "slug": "pgall-for-woocommerce", "target": "plugin", "versions": "<=5.5.6"}, "RULE-CVE-2026-56036-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:refund_id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-56036", "description": "PGAll for WooCommerce <=5.5.6 unauthenticated SQL injection via refund_id parameter", "mode": "block", "severity": 9.3, "slug": "pgall-for-woocommerce", "target": "plugin", "versions": "<=5.5.6"}, "RULE-CVE-2026-56036-03": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:payment_action", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-56036", "description": "PGAll for WooCommerce <=5.5.6 unauthenticated SQL injection via payment_action parameter", "mode": "block", "severity": 9.3, "slug": "pgall-for-woocommerce", "target": "plugin", "versions": "<=5.5.6"}, "RULE-CVE-2026-56036-04": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:_pafw_uid", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*.*\\\\*/|(?:--|#)\\\\s|\'\\\\s*(?:OR|AND)\\\\s)~i"}], "cve": "CVE-2026-56036", "description": "PGAll for WooCommerce <=5.5.6 unauthenticated SQL injection via _pafw_uid parameter", "mode": "block", "severity": 9.3, "slug": "pgall-for-woocommerce", "target": "plugin", "versions": "<=5.5.6"}, "RULE-CVE-2026-56040-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/gutenverse-form/~"}, {"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]*on\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-56040", "description": "Gutenverse Form <=2.4.7 unauthenticated stored XSS via form submission REST API", "mode": "block", "severity": 7.1, "slug": "gutenverse-form", "target": "plugin", "versions": "<=2.4.7"}, "RULE-CVE-2026-56042-01": {"action": "admin_init", "conditions": [{"name": "ARGS:woe_bulk_mark_exported", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-56042", "description": "Advanced Order Export For WooCommerce <=4.0.9 reflected XSS via woe_bulk_mark_exported parameter in admin notices", "mode": "block", "severity": 7.1, "slug": "woo-order-export-lite", "target": "plugin", "versions": "<=4.0.9"}, "RULE-CVE-2026-56042-02": {"action": "admin_init", "conditions": [{"name": "ARGS:woe_bulk_unmark_exported", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-56042", "description": "Advanced Order Export For WooCommerce <=4.0.9 reflected XSS via woe_bulk_unmark_exported parameter in admin notices", "mode": "block", "severity": 7.1, "slug": "woo-order-export-lite", "target": "plugin", "versions": "<=4.0.9"}, "RULE-CVE-2026-56043-01": {"ajax_action": "cr_submit_review", "conditions": [{"name": "ARGS:comment", "type": "regex", "value": "~<(?:script|img|svg|iframe|object|embed|math|details|marquee|video|audio|body|form|input|button|select|textarea|style|link|base|meta|applet|frame|frameset|isindex|layer|bgsound|table)[\\\\s/>]|\\\\bon(?:error|load|click|mouseover|focus|blur|submit|change|input|keydown|keyup|keypress|mouseout|mouseenter|mouseleave|dblclick|contextmenu|wheel|pointerover|animationend|beforeprint)\\\\s*=~i"}], "cve": "CVE-2026-56043", "description": "Blocks unauthenticated stored XSS via cr_submit_review AJAX action by detecting HTML/script injection in the comment parameter", "mode": "block", "severity": 7.1, "slug": "customer-reviews-woocommerce", "target": "plugin", "versions": "<5.111.0"}, "RULE-CVE-2026-56043-02": {"ajax_action": "cr_local_forms_submit", "conditions": [{"name": "ARGS:comment", "type": "regex", "value": "~<(?:script|img|svg|iframe|object|embed|math|details|marquee|video|audio|body|form|input|button|select|textarea|style|link|base|meta|applet|frame|frameset|isindex|layer|bgsound|table)[\\\\s/>]|\\\\bon(?:error|load|click|mouseover|focus|blur|submit|change|input|keydown|keyup|keypress|mouseout|mouseenter|mouseleave|dblclick|contextmenu|wheel|pointerover|animationend|beforeprint)\\\\s*=~i"}], "cve": "CVE-2026-56043", "description": "Blocks unauthenticated stored XSS via cr_local_forms_submit AJAX action by detecting HTML/script injection in the comment parameter", "mode": "block", "severity": 7.1, "slug": "customer-reviews-woocommerce", "target": "plugin", "versions": "<5.111.0"}, "RULE-CVE-2026-56053-01": {"ajax_action": "eventprime_api", "conditions": [{"name": "ARGS", "type": "regex", "value": "~[OCa]:[0-9]+:(?:\\\\\\"|\\\\{)~"}], "cve": "CVE-2026-56053", "description": "EventPrime <=4.3.4.1 subscriber+ PHP Object Injection via eventprime_api AJAX handler", "mode": "block", "severity": 8.8, "slug": "eventprime-event-calendar-management", "target": "plugin", "versions": "<=4.3.4.1"}, "RULE-CVE-2026-56054-01": {"ajax_action": "jsticket_ajax", "conditions": [{"name": "ARGS:jsst_dir", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env(?:\\\\b|[._])|error_log|debug\\\\.log))~i"}], "cve": "CVE-2026-56054", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56054", "description": "JS Help Desk <=3.1.1 subscriber+ arbitrary file/directory deletion via jsticket_ajax AJAX handler (path traversal in jsst_dir)", "mode": "block", "severity": 7.7, "slug": "js-support-ticket", "tags": ["path-traversal", "arbitrary-file-deletion", "missing-authorization"], "target": "plugin", "versions": "<=3.1.1"}, "RULE-CVE-2026-56060-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wcdn/v1/(?:settings|dashboard|templates|fonts)(?:/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_woocommerce"}], "cve": "CVE-2026-56060", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56060", "description": "Print Invoice & Delivery Notes for WooCommerce <=7.1.1 unauthenticated sensitive data exposure via REST API endpoints (wcdn/v1/settings, dashboard, templates, fonts)", "mode": "block", "severity": 7.5, "slug": "woocommerce-delivery-notes", "tags": ["missing-authorization", "information-disclosure", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=7.1.1"}, "RULE-CVE-2026-56063-01": {"ajax_action": "mcbSubmit_Form_Data", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56063", "description": "Block for Mailchimp <=1.1.15 unauthenticated broken access control on mcbSubmit_Form_Data AJAX handler", "mode": "block", "severity": 8.3, "slug": "block-for-mailchimp", "target": "plugin", "versions": "<=1.1.15"}, "RULE-CVE-2026-56063-02": {"ajax_action": "mcb_get_access_token", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56063", "description": "Block for Mailchimp <=1.1.15 missing authorization on mcb_get_access_token allows subscriber+ OAuth token retrieval", "mode": "block", "severity": 8.3, "slug": "block-for-mailchimp", "target": "plugin", "versions": "<=1.1.15"}, "RULE-CVE-2026-56063-03": {"ajax_action": "mcbAudienceList", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56063", "description": "Block for Mailchimp <=1.1.15 missing authorization on mcbAudienceList allows subscriber+ audience list retrieval", "mode": "block", "severity": 8.3, "slug": "block-for-mailchimp", "target": "plugin", "versions": "<=1.1.15"}, "RULE-CVE-2026-56063-04": {"ajax_action": "mcbSubmit_Form_AudienceId", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56063", "description": "Block for Mailchimp <=1.1.15 missing authorization on mcbSubmit_Form_AudienceId allows subscriber+ audience ID modification", "mode": "block", "severity": 8.3, "slug": "block-for-mailchimp", "target": "plugin", "versions": "<=1.1.15"}, "RULE-CVE-2026-56064-01": {"ajax_action": "tf_booking_calendar_filter", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56064", "description": "Tourfic <=2.22.5 authenticated SQL injection via tf_booking_calendar_filter AJAX handler", "mode": "block", "severity": 8.5, "slug": "tourfic", "tags": ["sql-injection", "authenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.22.5"}, "RULE-CVE-2026-56064-02": {"ajax_action": "tf_booking_details_popup", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56064", "description": "Tourfic <=2.22.5 authenticated SQL injection via tf_booking_details_popup AJAX handler", "mode": "block", "severity": 8.5, "slug": "tourfic", "tags": ["sql-injection", "authenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.22.5"}, "RULE-CVE-2026-56064-03": {"ajax_action": "tf_order_bulk_action_edit", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56064", "description": "Tourfic <=2.22.5 authenticated SQL injection via tf_order_bulk_action_edit AJAX handler", "mode": "block", "severity": 8.5, "slug": "tourfic", "tags": ["sql-injection", "authenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.22.5"}, "RULE-CVE-2026-56064-04": {"ajax_action": "tf_order_status_edit", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56064", "description": "Tourfic <=2.22.5 authenticated SQL injection via tf_order_status_edit AJAX handler", "mode": "block", "severity": 8.5, "slug": "tourfic", "tags": ["sql-injection", "authenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.22.5"}, "RULE-CVE-2026-56064-05": {"ajax_action": "tf_visitor_details_edit", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56064", "description": "Tourfic <=2.22.5 authenticated SQL injection via tf_visitor_details_edit AJAX handler", "mode": "block", "severity": 8.5, "slug": "tourfic", "tags": ["sql-injection", "authenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.22.5"}, "RULE-CVE-2026-56064-06": {"ajax_action": "tf_checkinout_details_edit", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|/\\\\*[!+]|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-56064", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-56064", "description": "Tourfic <=2.22.5 authenticated SQL injection via tf_checkinout_details_edit AJAX handler", "mode": "block", "severity": 8.5, "slug": "tourfic", "tags": ["sql-injection", "authenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.22.5"}, "RULE-CVE-2026-56070-01": {"ajax_action": "thaps_ajax_get_search_value", "conditions": [{"name": "ARGS:search", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|LOAD_FILE\\\\s*\\\\(|INTO\\\\s+(?:OUT|DUMP)FILE\\\\s)~i"}], "cve": "CVE-2026-56070", "description": "Unauthenticated SQL Injection via thaps_ajax_get_search_value AJAX handler in TH Advance Product Search <= 1.4.4", "mode": "block", "severity": 9.3, "slug": "th-advance-product-search", "target": "plugin", "versions": "<=1.4.4"}, "RULE-CVE-2026-56071-01": {"ajax_action": "forminator_submit_form_custom-forms", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|\\\\bon(?:error|load|mouseover|click|focus|blur|mouse(?:over|out|enter|move))\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-56071", "description": "Forminator <=1.53.1 unauthenticated stored XSS via form submission field values", "mode": "block", "severity": 7.1, "slug": "forminator", "target": "plugin", "versions": "<=1.53.1"}, "RULE-CVE-2026-56071-02": {"ajax_action": "forminator_submit_preview_form_custom-forms", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|\\\\bon(?:error|load|mouseover|click|focus|blur|mouse(?:over|out|enter|move))\\\\s*=|javascript\\\\s*:|data\\\\s*:(?!\\\\s*(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-56071", "description": "Forminator <=1.53.1 unauthenticated stored XSS via preview form submission", "mode": "block", "severity": 7.1, "slug": "forminator", "target": "plugin", "versions": "<=1.53.1"}, "RULE-CVE-2026-5710-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/contact-form-7/v1/contact-forms/[0-9]+/feedback(?:[/?]|$)~"}, {"name": "ARGS:mfile", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]|[\\\\\\\\/])~"}], "cve": "CVE-2026-5710", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5710", "description": "Drag and Drop Multiple File Upload for CF7 <=1.3.9.6 unauthenticated path traversal leading to arbitrary file read via mfile[] parameter on CF7 REST feedback endpoint", "method": "POST", "mode": "block", "severity": 7.5, "slug": "drag-and-drop-multiple-file-upload-contact-form-7", "tags": ["path-traversal", "arbitrary-file-read", "unauthenticated", "rest-api"], "target": "plugin", "versions": "<=1.3.9.6"}, "RULE-CVE-2026-5714-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "enable-media-replace/enable-media-replace.php"}, {"name": "ARGS:location_dir", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]|]*on[a-z]+=|]|]|])~i"}], "cve": "CVE-2026-5714", "description": "Enable Media Replace <=4.1.8 authenticated (Author+) stored XSS via location_dir parameter", "mode": "block", "severity": 6.4, "slug": "enable-media-replace", "target": "plugin", "versions": "<=4.1.8"}, "RULE-CVE-2026-5722-01": {"ajax_action": "wlfmc_waitlist_signup", "conditions": [{"name": "ARGS:token", "type": "exists"}, {"name": "ARGS:email", "type": "exists"}], "cve": "CVE-2026-5722", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5722", "description": "Smart Wishlist for More Convert <=1.9.14 authentication bypass via waitlist token reuse with email change", "mode": "block", "severity": 9.8, "slug": "smart-wishlist-for-more-convert", "tags": ["authentication-bypass", "token-reuse", "cwe-287"], "target": "plugin", "versions": "<=1.9.14"}, "RULE-CVE-2026-5722-02": {"action": "init", "conditions": [{"name": "ARGS:waitlist_verify", "type": "equals", "value": "1"}, {"name": "ARGS:token", "type": "exists"}, {"name": "ARGS:email", "type": "exists"}], "cve": "CVE-2026-5722", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5722", "description": "Smart Wishlist for More Convert <=1.9.14 authentication bypass via waitlist verification link token reuse (blocks verification endpoint on vulnerable version; legitimate verification clicks also blocked until patched to 1.9.15)", "mode": "block", "severity": 9.8, "slug": "smart-wishlist-for-more-convert", "tags": ["authentication-bypass", "token-reuse", "verification-link", "cwe-287"], "target": "plugin", "versions": "<=1.9.14"}, "RULE-CVE-2026-57317-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~simply-schedule-appointments/booking-app-new/iframe-inner\\\\.php~"}, {"name": "ARGS:token", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|data\\\\s*:(?![\\\\s])(?!(?:image|audio|video|font)/))~i"}], "cve": "CVE-2026-57317", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57317", "description": "Simply Schedule Appointments <=1.6.12.2 unauthenticated reflected XSS via token parameter in booking iframe", "mode": "block", "severity": 7.1, "slug": "simply-schedule-appointments", "tags": ["xss", "unauthenticated", "reflected"], "target": "plugin", "versions": "<=1.6.12.2"}, "RULE-CVE-2026-57319-01": {"ajax_action": "woocs_convert_currency", "conditions": [{"name": "ARGS:precision", "type": "exists"}, {"name": "ARGS:precision", "type": "regex", "value": "~[<>\\"\'`]|javascript\\\\s*:|on\\\\w+\\\\s*=~i"}], "cve": "CVE-2026-57319", "description": "Blocks unauthenticated Reflected XSS via the \'precision\' parameter in the woocs_convert_currency AJAX handler (wp_die sink at woocs.php:3728). The parameter is passed unsanitized to wp_die output in versions <=1.4.8.", "mode": "block", "severity": 7.1, "slug": "woocommerce-currency-switcher", "target": "plugin", "versions": "<=1.4.8"}, "RULE-CVE-2026-57319-02": {"ajax_action": "woocs_rates_current_currency", "conditions": [{"name": "ARGS:exclude", "type": "exists"}, {"name": "ARGS:exclude", "type": "regex", "value": "~[<>\\"\'`]|javascript\\\\s*:|on\\\\w+\\\\s*=~i"}], "cve": "CVE-2026-57319", "description": "Blocks unauthenticated Reflected XSS via the \'exclude\' parameter in the woocs_rates_current_currency AJAX handler (wp_die sink at woocs.php:3754). The parameter is passed unsanitized to wp_die output in versions <=1.4.8.", "mode": "block", "severity": 7.1, "slug": "woocommerce-currency-switcher", "target": "plugin", "versions": "<=1.4.8"}, "RULE-CVE-2026-57321-01": {"ajax_action": "h5p_files", "conditions": [{"name": "ARGS:filePath", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log))~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-57321", "description": "H5P <=1.17.7 contributor+ arbitrary file deletion via path traversal in h5p_files AJAX handler", "mode": "block", "severity": 7.1, "slug": "h5p", "target": "plugin", "versions": "<=1.17.7"}, "RULE-CVE-2026-57631-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "ays-pb"}, {"name": "ARGS:popup_category", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[\\\\s\\\\S]*?\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2026-57631", "description": "Popup Box <=6.0.1 authenticated SQL injection via popup_category parameter", "mode": "block", "severity": 7.6, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.0.1"}, "RULE-CVE-2026-57631-02": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "ays-pb"}, {"name": "ARGS:popupbox", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[\\\\s\\\\S]*?\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2026-57631", "description": "Popup Box <=6.0.1 authenticated SQL injection via popupbox parameter", "mode": "block", "severity": 7.6, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.0.1"}, "RULE-CVE-2026-57631-03": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "ays-pb"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[\\\\s\\\\S]*?\\\\*/|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2026-57631", "description": "Popup Box <=6.0.1 authenticated SQL injection via orderby parameter", "mode": "block", "severity": 7.6, "slug": "ays-popup-box", "target": "plugin", "versions": "<=6.0.1"}, "RULE-CVE-2026-57636-01": {"ajax_action": "wpforo_ai_action", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-57636", "description": "wpForo Forum <=3.0.9 contributor+ SQL injection via wpforo_ai_action AJAX handler", "mode": "block", "severity": 8.5, "slug": "wpforo", "target": "plugin", "versions": "<=3.0.9"}, "RULE-CVE-2026-57644-01": {"ajax_action": "mprm_process_checkout", "conditions": [{"name": "ARGS:mprm-purchase-var", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[!+]|\\\\b(?:OR|AND)\\\\s+[\\\\d\'\\"]+\\\\s*=\\\\s*[\\\\d\'\\"]+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML|LOAD_FILE)\\\\s*\\\\()~i"}], "cve": "CVE-2026-57644", "description": "Restaurant Menu by MotoPress <=2.4.10 SQL injection via mprm-purchase-var in mprm_process_checkout AJAX handler", "mode": "block", "severity": 8.5, "slug": "mp-restaurant-menu", "target": "plugin", "versions": "<=2.4.10"}, "RULE-CVE-2026-57644-02": {"ajax_action": "mprm_process_checkout_login", "conditions": [{"name": "ARGS:mprm-purchase-var", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[!+]|\\\\b(?:OR|AND)\\\\s+[\\\\d\'\\"]+\\\\s*=\\\\s*[\\\\d\'\\"]+|(?:SLEEP|BENCHMARK|EXTRACTVALUE|UPDATEXML|LOAD_FILE)\\\\s*\\\\()~i"}], "cve": "CVE-2026-57644", "description": "Restaurant Menu by MotoPress <=2.4.10 SQL injection via mprm-purchase-var in mprm_process_checkout_login AJAX handler", "mode": "block", "severity": 8.5, "slug": "mp-restaurant-menu", "target": "plugin", "versions": "<=2.4.10"}, "RULE-CVE-2026-57645-01": {"ajax_action": "newsletters_executemultiple", "conditions": [{"type": "missing_capability", "value": "newsletters_subscribers"}], "cve": "CVE-2026-57645", "description": "Newsletters <=4.13 missing authorization on newsletters_executemultiple AJAX handler allows subscriber+ batch operations", "mode": "block", "severity": 8.1, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-57645-02": {"ajax_action": "newsletters_exportmultiple", "conditions": [{"type": "missing_capability", "value": "newsletters_subscribers"}], "cve": "CVE-2026-57645", "description": "Newsletters <=4.13 missing authorization on newsletters_exportmultiple AJAX handler allows subscriber+ data export", "mode": "block", "severity": 8.1, "slug": "newsletters-lite", "target": "plugin", "versions": "<=4.13"}, "RULE-CVE-2026-57663-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "zrdn-recipes"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bIF\\\\s*\\\\(|\\\\(\\\\s*SELECT\\\\b|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[^*]*\\\\*/|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-57663", "description": "Zip Recipes <=8.2.7 authenticated (Contributor+) SQL injection via orderby parameter in admin Recipe_Table", "mode": "block", "severity": 8.5, "slug": "zip-recipes", "target": "plugin", "versions": "<=8.2.7"}, "RULE-CVE-2026-57663-02": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "zrdn-recipes"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bIF\\\\s*\\\\(|\\\\(\\\\s*SELECT\\\\b|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[^*]*\\\\*/|(?:--|#)\\\\s)~i"}], "cve": "CVE-2026-57663", "description": "Zip Recipes <=8.2.7 authenticated (Contributor+) SQL injection via order parameter in admin Recipe_Table", "mode": "block", "severity": 8.5, "slug": "zip-recipes", "target": "plugin", "versions": "<=8.2.7"}, "RULE-CVE-2026-57713-01": {"action": "admin_init", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]+\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-57713", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57713", "description": "Events Manager <=7.3.6 PHP Object Injection via unserialize() in multilingual/install data handling (CWE-502)", "mode": "block", "severity": 8.8, "slug": "events-manager", "tags": ["object-injection", "deserialization", "csrf"], "target": "plugin", "versions": "<=7.3.6"}, "RULE-CVE-2026-57724-01": {"ajax_action": "kirki_wp_admin_post_apis", "conditions": [{"name": "ARGS:endpoint", "type": "equals", "value": "update-form-cell"}, {"name": "ARGS:data", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]+\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-57724", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57724", "description": "Kirki <=6.0.12 authenticated PHP object injection via update-form-cell request writing to data field later unserialized without allowed_classes restriction", "mode": "block", "severity": 9.8, "slug": "kirki", "tags": ["object-injection", "deserialization", "authenticated"], "target": "plugin", "versions": "<=6.0.12"}, "RULE-CVE-2026-57726-01": {"ajax_action": "kirki_wp_admin_get_apis", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "kirki_wp_admin_get_apis"}, {"name": "missing_capability", "type": "missing_capability", "value": "edit_theme_options"}], "cve": "CVE-2026-57726", "description": "Blocks unauthorized access to Kirki\'s kirki_wp_admin_get_apis AJAX endpoint, which the plugin\'s own code treats as admin-only (nopriv variant dispatches to kirki_wp_admin_unauthorized) but lacked a current_user_can() capability check prior to 6.0.13.", "mode": "block", "slug": "kirki", "target": "plugin", "versions": "<=6.0.12"}, "RULE-CVE-2026-57726-02": {"ajax_action": "kirki_wp_admin_post_apis", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "kirki_wp_admin_post_apis"}, {"name": "missing_capability", "type": "missing_capability", "value": "edit_theme_options"}], "cve": "CVE-2026-57726", "description": "Blocks unauthorized access to Kirki\'s kirki_wp_admin_post_apis AJAX endpoint, which the plugin\'s own code treats as admin-only (nopriv variant dispatches to kirki_wp_admin_unauthorized) but lacked a current_user_can() capability check prior to 6.0.13.", "mode": "block", "slug": "kirki", "target": "plugin", "versions": "<=6.0.12"}, "RULE-CVE-2026-57727-01": {"ajax_action": "kirki_get_apis", "conditions": [{"name": "ARGS:/post_id|session_id|term_id/", "type": "exists"}, {"type": "missing_capability", "value": "edit_theme_options"}], "cve": "CVE-2026-57727", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57727", "description": "Kirki <=6.0.13 missing authorization on kirki_get_apis AJAX handler allows unauthenticated IDOR access via post_id/session_id/term_id", "mode": "block", "severity": 7.5, "slug": "kirki", "tags": ["missing-authorization", "broken-access-control", "unauthenticated", "idor"], "target": "plugin", "versions": "<=6.0.13"}, "RULE-CVE-2026-57728-01": {"action": "wp_footer", "conditions": [{"name": "ARGS:block", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-57728", "description": "Flatsome theme <=3.20.5 unauthenticated reflected XSS via block parameter in ux_block_frontend()", "mode": "block", "severity": 7.1, "slug": "flatsome", "target": "theme", "versions": "<=3.20.5"}, "RULE-CVE-2026-57737-01": {"ajax_action": "auxin_templates_data", "conditions": [{"name": "ARGS:ID", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:(?=\\\\S)|]+\\\\bonerror\\\\s*=|]|])~i"}], "cve": "CVE-2026-57737", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57737", "description": "Shortcodes and extra features for Phlox theme <=2.17.16 reflected XSS via ID parameter in auxin_templates_data AJAX handler", "mode": "block", "severity": 6.5, "slug": "auxin-elements", "tags": ["xss", "reflected", "authenticated"], "target": "plugin", "versions": "<=2.17.16"}, "RULE-CVE-2026-57737-02": {"ajax_action": "auxin_templates_data", "conditions": [{"name": "ARGS:type", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:(?=\\\\S)|]+\\\\bonerror\\\\s*=|]|])~i"}], "cve": "CVE-2026-57737", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57737", "description": "Shortcodes and extra features for Phlox theme <=2.17.16 reflected XSS via type parameter in auxin_templates_data AJAX handler", "mode": "block", "severity": 6.5, "slug": "auxin-elements", "tags": ["xss", "reflected", "authenticated"], "target": "plugin", "versions": "<=2.17.16"}, "RULE-CVE-2026-57737-03": {"ajax_action": "auxin_templates_data", "conditions": [{"name": "ARGS:tmpl", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:(?=\\\\S)|]+\\\\bonerror\\\\s*=|]|])~i"}], "cve": "CVE-2026-57737", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57737", "description": "Shortcodes and extra features for Phlox theme <=2.17.16 reflected XSS via tmpl parameter in auxin_templates_data AJAX handler", "mode": "block", "severity": 6.5, "slug": "auxin-elements", "tags": ["xss", "reflected", "authenticated"], "target": "plugin", "versions": "<=2.17.16"}, "RULE-CVE-2026-57737-04": {"ajax_action": "auxin_templates_data", "conditions": [{"name": "ARGS:title", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:(?=\\\\S)|]+\\\\bonerror\\\\s*=|]|])~i"}], "cve": "CVE-2026-57737", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57737", "description": "Shortcodes and extra features for Phlox theme <=2.17.16 reflected XSS via title parameter in auxin_templates_data AJAX handler", "mode": "block", "severity": 6.5, "slug": "auxin-elements", "tags": ["xss", "reflected", "authenticated"], "target": "plugin", "versions": "<=2.17.16"}, "RULE-CVE-2026-57737-05": {"ajax_action": "aux_ajax_lightbox", "conditions": [{"name": "ARGS:preview", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:(?=\\\\S)|]+\\\\bonerror\\\\s*=|]|])~i"}], "cve": "CVE-2026-57737", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57737", "description": "Shortcodes and extra features for Phlox theme <=2.17.16 reflected XSS via preview parameter in aux_ajax_lightbox AJAX handler", "mode": "block", "severity": 6.5, "slug": "auxin-elements", "tags": ["xss", "reflected", "authenticated"], "target": "plugin", "versions": "<=2.17.16"}, "RULE-CVE-2026-57737-06": {"ajax_action": "aux_the_recent_products", "conditions": [{"name": "ARGS:data", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:(?=\\\\S)|]+\\\\bonerror\\\\s*=|]|])~i"}], "cve": "CVE-2026-57737", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-57737", "description": "Shortcodes and extra features for Phlox theme <=2.17.16 unauthenticated reflected XSS via data parameter in aux_the_recent_products AJAX handler", "mode": "block", "severity": 6.5, "slug": "auxin-elements", "tags": ["xss", "reflected", "unauthenticated"], "target": "plugin", "versions": "<=2.17.16"}, "RULE-CVE-2026-57773-01": {"ajax_action": "wc_ast_upload_csv_form_update", "conditions": [{"name": "ARGS:tracking_provider", "type": "regex", "value": "~(?:\'\\\\s*(?:OR|AND)\\\\s|\\\\bUNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\b|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|--\\\\s|#|/\\\\*)~i"}], "cve": "CVE-2026-57773", "description": "Advanced Shipment Tracking for WooCommerce <=4.0 authenticated (Shop Manager+) blind SQL injection via tracking_provider parameter in CSV import AJAX handler", "mode": "block", "slug": "woo-advanced-shipment-tracking", "target": "plugin", "versions": "<=4.0"}, "RULE-CVE-2026-57813-01": {"ajax_action": "mailoptin_connect_process", "conditions": [{"name": "", "type": "missing_capability", "value": "administrator"}], "cve": "CVE-2026-57813", "description": "MailOptin <=1.2.77.3 unauthenticated privilege escalation via mailoptin_connect_process AJAX handler (removed wp_ajax_nopriv exposure, missing capability check)", "mode": "block", "severity": 9.8, "slug": "mailoptin", "target": "plugin", "versions": "<=1.2.77.3"}, "RULE-CVE-2026-57813-02": {"action": "admin_post_mailoptin_upgrader", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-57813", "description": "MailOptin <=1.2.77.3 missing authorization on admin_post_mailoptin_upgrader allows unauthorized upgrade/install action", "mode": "block", "severity": 9.8, "slug": "mailoptin", "target": "plugin", "versions": "<=1.2.77.3"}, "RULE-CVE-2026-5809-01": {"ajax_action": "wpforo_ai_wp_get_post_types", "conditions": [{"name": "ARGS:post_type", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)|(?:php|data|expect|phar)://)~i"}], "cve": "CVE-2026-5809", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5809", "description": "wpForo <=3.0.2 authenticated LFI via post_type param in wpforo_ai_wp_get_post_types AJAX handler", "mode": "block", "severity": 7.1, "slug": "wpforo", "tags": ["local-file-inclusion", "path-traversal", "authenticated", "cwe-73"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2026-5809-02": {"ajax_action": "wpforo_ai_wp_get_taxonomies", "conditions": [{"name": "ARGS:taxonomy", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)|(?:php|data|expect|phar)://)~i"}], "cve": "CVE-2026-5809", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5809", "description": "wpForo <=3.0.2 authenticated LFI via taxonomy param in wpforo_ai_wp_get_taxonomies AJAX handler", "mode": "block", "severity": 7.1, "slug": "wpforo", "tags": ["local-file-inclusion", "path-traversal", "authenticated", "cwe-73"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2026-5809-03": {"ajax_action": "wpforo_ai_wp_get_taxonomy_terms", "conditions": [{"name": "ARGS:taxonomy", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)|(?:php|data|expect|phar)://)~i"}], "cve": "CVE-2026-5809", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5809", "description": "wpForo <=3.0.2 authenticated LFI via taxonomy param in wpforo_ai_wp_get_taxonomy_terms AJAX handler", "mode": "block", "severity": 7.1, "slug": "wpforo", "tags": ["local-file-inclusion", "path-traversal", "authenticated", "cwe-73"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2026-5809-04": {"ajax_action": "wpforo_ai_wp_index_by_taxonomy", "conditions": [{"name": "ARGS:taxonomy", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)|(?:php|data|expect|phar)://)~i"}], "cve": "CVE-2026-5809", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5809", "description": "wpForo <=3.0.2 authenticated LFI via taxonomy param in wpforo_ai_wp_index_by_taxonomy AJAX handler", "mode": "block", "severity": 7.1, "slug": "wpforo", "tags": ["local-file-inclusion", "path-traversal", "authenticated", "cwe-73"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2026-5809-05": {"ajax_action": "wpforo_ai_wp_index_custom", "conditions": [{"name": "ARGS:post_type", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log)|(?:php|data|expect|phar)://)~i"}], "cve": "CVE-2026-5809", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5809", "description": "wpForo <=3.0.2 authenticated LFI via post_type param in wpforo_ai_wp_index_custom AJAX handler", "mode": "block", "severity": 7.1, "slug": "wpforo", "tags": ["local-file-inclusion", "path-traversal", "authenticated", "cwe-73"], "target": "plugin", "versions": "<=3.0.2"}, "RULE-CVE-2026-5821-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:metakeyinput", "type": "equals", "value": "image_optimizer_metadata"}, {"name": "ARGS:metavalue", "type": "regex", "value": "~s:7:\\"backups\\";a:[0-9]+:{~i"}], "cve": "CVE-2026-5821", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5821", "description": "Image Optimizer <=1.7.4 arbitrary file deletion via untrusted absolute paths injected into image_optimizer_metadata post meta backups array", "mode": "pass", "severity": 8.1, "slug": "image-optimization", "tags": ["arbitrary-file-deletion", "insufficient-path-validation", "authenticated"], "target": "plugin", "versions": "<=1.7.4"}, "RULE-CVE-2026-59525-01": {"ajax_action": "pdb_list_filter", "conditions": [{"name": "ARGS:search_field", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[0-9a-zA-Z\'\\"]+\\\\s*=\\\\s*[0-9a-zA-Z\'\\"]+|\\\\bSLEEP\\\\s*\\\\(|\\\\bBENCHMARK\\\\s*\\\\(|\\\\bEXTRACTVALUE\\\\s*\\\\(|\\\\bUPDATEXML\\\\s*\\\\(|/\\\\*.*?\\\\*/|--\\\\s|#\\\\s)~i"}], "cve": "CVE-2026-59525", "description": "Participants Database <=2.7.8.3 unauthenticated SQL injection via search_field in pdb_list_filter AJAX handler", "mode": "block", "severity": 9.3, "slug": "participants-database", "target": "plugin", "versions": "<=2.7.8.3"}, "RULE-CVE-2026-59530-01": {"ajax_action": "wc_stripe_admin_request", "conditions": [{"name": "ARGS:path", "type": "exists"}, {"name": "ARGS:path", "type": "regex", "value": "~^/?(?:wp/v2/(?:users|settings|plugins|themes|application-passwords|options)|wc/v3(?:/|$)|wc-admin|wc-analytics|jwt-auth)~i"}], "cve": "CVE-2026-59530", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-59530", "description": "Stripe For WooCommerce (woo-stripe-payment) <=4.0.7 broken access control via wc_stripe_admin_request AJAX-to-REST dispatch bridge allowing pivot to sensitive REST namespaces", "mode": "block", "severity": 7.5, "slug": "woo-stripe-payment", "tags": ["missing-authorization", "broken-access-control", "rest-api-pivot"], "target": "plugin", "versions": "<=4.0.7"}, "RULE-CVE-2026-59549-01": {"ajax_action": "rtmedia_rt_album_import", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-59549", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-59549", "description": "rtMedia for WordPress, BuddyPress and bbPress <=4.7.10 missing authorization on BuddyPress album import AJAX handler (rtmedia_rt_album_import), hardened in the same 4.7.11 release that addresses CVE-2026-59549", "mode": "block", "severity": 9.3, "slug": "buddypress-media", "tags": ["missing-authorization", "broken-access-control", "authenticated"], "target": "plugin", "versions": "<=4.7.10"}, "RULE-CVE-2026-59558-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "wpbc-settings"}, {"name": "ARGS:form_visible_section", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-59558", "description": "Booking Calendar <=11.4.3 reflected XSS via form_visible_section parameter on wpbc-settings admin page", "mode": "block", "severity": 7.1, "slug": "booking", "target": "plugin", "versions": "<=11.4.3"}, "RULE-CVE-2026-5957-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/emailkit/v1/create[_-]template(?:/|\\\\?|&|$)~"}, {"name": "ARGS:emailkit-editor-template", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[/\\\\\\\\]){2,}|/(?:etc|proc|root|var)/|wp-config\\\\.php|\\\\.htaccess|\\\\.htpasswd|\\\\.env|debug\\\\.log|error_log|id_rsa|id_dsa|/home/[^/]+/\\\\.|php://(?:filter|input)|file://|expect://|data://)~i"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-5957", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5957", "description": "EmailKit <=1.6.5 authenticated arbitrary file read via REST create_template emailkit-editor-template parameter", "mode": "block", "severity": 6.5, "slug": "emailkit", "tags": ["local-file-inclusion", "path-traversal", "authenticated"], "target": "plugin", "versions": "<=1.6.5"}, "RULE-CVE-2026-5957-03": {"ajax_action": "emailkit_admin_action", "conditions": [{"name": "ARGS:emailkit-editor-template", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[/\\\\\\\\]){2,}|/(?:etc|proc|root|var)/|wp-config\\\\.php|\\\\.htaccess|\\\\.htpasswd|\\\\.env|debug\\\\.log|error_log|id_rsa|id_dsa|/home/[^/]+/\\\\.|php://(?:filter|input)|file://|expect://|data://)~i"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-5957", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5957", "description": "EmailKit <=1.6.5 path traversal defense-in-depth on emailkit_admin_action AJAX emailkit-editor-template parameter", "mode": "block", "severity": 6.5, "slug": "emailkit", "tags": ["local-file-inclusion", "path-traversal", "authenticated"], "target": "plugin", "versions": "<=1.6.5"}, "RULE-CVE-2026-5957-04": {"ajax_action": "emailkit_filter_save_as_template", "conditions": [{"name": "ARGS:emailkit-editor-template", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[/\\\\\\\\]){2,}|/(?:etc|proc|root|var)/|wp-config\\\\.php|\\\\.htaccess|\\\\.htpasswd|\\\\.env|debug\\\\.log|error_log|id_rsa|id_dsa|/home/[^/]+/\\\\.|php://(?:filter|input)|file://|expect://|data://)~i"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-5957", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-5957", "description": "EmailKit <=1.6.5 path traversal defense-in-depth on emailkit_filter_save_as_template AJAX emailkit-editor-template parameter", "mode": "block", "severity": 6.5, "slug": "emailkit", "tags": ["local-file-inclusion", "path-traversal", "authenticated"], "target": "plugin", "versions": "<=1.6.5"}, "RULE-CVE-2026-60137-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/batch/v1[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:/^requests$/", "type": "regex", "value": "~(?:[?&](?:author_exclude|author__not_in)=[^]{0,256}?|(?:^|[^A-Za-z0-9_?&=])-?\\\\d+\\\\)?[\\\\s+]{0,8})(?:\\\\b(?:or|and)\\\\b[\\\\s+]*(?:\\\\([\\\\s+]*)*(?:(?:sleep|benchmark|extractvalue|updatexml|gtid_subset|ascii|substring|ord|if)[\\\\s+]*\\\\(|(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\')[\\\\s+]*(?:=|!=|<>|<=>|like)[\\\\s+]*(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\'))|\\\\bunion[\\\\s+/\\\\*]+(?:all[\\\\s+/\\\\*]+)?select\\\\b|;[\\\\s+]*(?:select|insert|update|delete|drop)\\\\b|--[\\\\s+]|/\\\\*|#)~i"}], "cve": "CVE-2026-60137", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137", "description": "WordPress core facilitated SQL injection through nested REST batch author exclusion path; covers URL and parsed rest_route carriers", "mode": "block", "severity": 9.1, "tags": ["sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=6.9.0 <6.9.5"}, "RULE-CVE-2026-60137-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/batch/v1[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:/^requests$/", "type": "regex", "value": "~(?:[?&](?:author_exclude|author__not_in)=[^]{0,256}?|(?:^|[^A-Za-z0-9_?&=])-?\\\\d+\\\\)?[\\\\s+]{0,8})(?:\\\\b(?:or|and)\\\\b[\\\\s+]*(?:\\\\([\\\\s+]*)*(?:(?:sleep|benchmark|extractvalue|updatexml|gtid_subset|ascii|substring|ord|if)[\\\\s+]*\\\\(|(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\')[\\\\s+]*(?:=|!=|<>|<=>|like)[\\\\s+]*(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\'))|\\\\bunion[\\\\s+/\\\\*]+(?:all[\\\\s+/\\\\*]+)?select\\\\b|;[\\\\s+]*(?:select|insert|update|delete|drop)\\\\b|--[\\\\s+]|/\\\\*|#)~i"}], "cve": "CVE-2026-60137", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137", "description": "WordPress core facilitated SQL injection through nested REST batch author exclusion path; covers URL and parsed rest_route carriers", "mode": "block", "severity": 9.1, "tags": ["sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=7.0.0 <7.0.2"}, "RULE-CVE-2026-60137-03": {"action": "init", "conditions": [{"name": "ARGS:/^author_exclude$|^author__not_in$/", "type": "detectSQLi"}], "cve": "CVE-2026-60137", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137", "description": "WordPress Core SQL injection via author__not_in / REST author_exclude in WP_Query (wp2shell SQLi primitive) - standalone/plugin-mediated parameter and WP 6.8.x coverage not addressed by the batch-scoped rules -01/-02.", "mode": "block", "severity": 9.1, "tags": ["sql-injection", "unauthenticated", "wp-core", "wp2shell", "defense-in-depth"], "target": "core", "versions": ">=6.8.0 <6.8.6 || >=6.9.0 <6.9.5 || >=7.0.0 <7.0.2"}, "RULE-CVE-2026-60137-04": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/batch/v1[\\\\\\\\/]*$~i"}, {"name": "ARGS:/^requests$/", "type": "regex", "value": "~(?:[?&](?:author_exclude|author__not_in)=[^]{0,256}?|(?:^|[^A-Za-z0-9_?&=])-?\\\\d+\\\\)?[\\\\s+]{0,8})(?:\\\\b(?:or|and)\\\\b[\\\\s+]*(?:\\\\([\\\\s+]*)*(?:(?:sleep|benchmark|extractvalue|updatexml|gtid_subset|ascii|substring|ord|if)[\\\\s+]*\\\\(|(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\')[\\\\s+]*(?:=|!=|<>|<=>|like)[\\\\s+]*(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\'))|\\\\bunion[\\\\s+/\\\\*]+(?:all[\\\\s+/\\\\*]+)?select\\\\b|;[\\\\s+]*(?:select|insert|update|delete|drop)\\\\b|--[\\\\s+]|/\\\\*|#)~i"}], "cve": "CVE-2026-60137", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137", "description": "WordPress core facilitated SQL injection through nested REST batch author exclusion path; covers URL and parsed rest_route carriers", "mode": "block", "severity": 9.1, "tags": ["sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=6.9.0 <6.9.5"}, "RULE-CVE-2026-60137-05": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/batch/v1[\\\\\\\\/]*$~i"}, {"name": "ARGS:/^requests$/", "type": "regex", "value": "~(?:[?&](?:author_exclude|author__not_in)=[^]{0,256}?|(?:^|[^A-Za-z0-9_?&=])-?\\\\d+\\\\)?[\\\\s+]{0,8})(?:\\\\b(?:or|and)\\\\b[\\\\s+]*(?:\\\\([\\\\s+]*)*(?:(?:sleep|benchmark|extractvalue|updatexml|gtid_subset|ascii|substring|ord|if)[\\\\s+]*\\\\(|(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\')[\\\\s+]*(?:=|!=|<>|<=>|like)[\\\\s+]*(?:-?\\\\d+|0x[0-9a-f]+|\'[^\']{0,64}\'))|\\\\bunion[\\\\s+/\\\\*]+(?:all[\\\\s+/\\\\*]+)?select\\\\b|;[\\\\s+]*(?:select|insert|update|delete|drop)\\\\b|--[\\\\s+]|/\\\\*|#)~i"}], "cve": "CVE-2026-60137", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137", "description": "WordPress core facilitated SQL injection through nested REST batch author exclusion path; covers URL and parsed rest_route carriers", "mode": "block", "severity": 9.1, "tags": ["sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=7.0.0 <7.0.2"}, "RULE-CVE-2026-6101-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "amp_settings"}, {"name": "ARGS:ampforwp-local-font-zip", "type": "regex", "value": "~(?:\\\\.\\\\.[/\\\\\\\\]|%2[Ee]{1,2}%2[Ee]{0,1}[/\\\\\\\\%]|%252[Ee]%252[Ee]%25(?:2[Ff]|5[Cc]))~i"}], "cve": "CVE-2026-6101", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6101", "description": "AMP for WP <=1.1.12 authenticated Author+ arbitrary file write via ZIP-slip path traversal in ampforwp_save_local_font local font upload", "mode": "block", "severity": 7.5, "slug": "accelerated-mobile-pages", "tags": ["arbitrary-file-write", "path-traversal", "zip-slip", "authenticated"], "target": "plugin", "versions": "<=1.1.12"}, "RULE-CVE-2026-61949-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin-ajax\\\\.php~i"}, {"name": "ARGS:import", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[0-9]+\\\\s*=\\\\s*[0-9]+|/\\\\*.*?\\\\*/|--\\\\s|#\\\\s|`[^`]*`\\\\s*(?:=|,)|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2026-61949", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-61949", "description": "Bookly <=27.7 unauthenticated SQL injection via import parameter reaching $wpdb->query in diagnostics AJAX handler", "mode": "block", "severity": 9.3, "slug": "bookly-responsive-appointment-booking-tool", "tags": ["sql-injection", "unauthenticated", "diagnostics"], "target": "plugin", "versions": "<=27.7"}, "RULE-CVE-2026-61961-01": {"ajax_action": "fetch_video_description", "conditions": [{"name": "ARGS:vid", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouseover|focus|input|blur)\\\\s*=|javascript\\\\s*:|\\"\\\\s*;)~i"}], "cve": "CVE-2026-6275", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6275", "description": "StatCounter <=2.1.1 Author+ stored XSS via nickname field echoed unescaped into JavaScript context by statcounter_addToTags()", "method": "POST", "mode": "block", "severity": 6.4, "slug": "official-statcounter-plugin-for-wordpress", "tags": ["xss", "stored", "authenticated"], "target": "plugin", "versions": "<=2.1.1"}, "RULE-CVE-2026-63030-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/batch/v1[\\\\\\\\/]*(?:[?&]|$)~i"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-63030", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030", "description": "WordPress core REST batch route confusion chained with SQL injection; emergency anonymous mitigation across URL and parsed rest_route carriers", "mode": "block", "severity": 7.5, "tags": ["remote-code-execution", "sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=6.9.0 <6.9.5"}, "RULE-CVE-2026-63030-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/batch/v1[\\\\\\\\/]*(?:[?&]|$)~i"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-63030", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030", "description": "WordPress core REST batch route confusion chained with SQL injection; emergency anonymous mitigation across URL and parsed rest_route carriers", "mode": "block", "severity": 7.5, "tags": ["remote-code-execution", "sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=7.0.0 <7.0.2"}, "RULE-CVE-2026-63030-03": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/batch/v1[\\\\\\\\/]*$~i"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-63030", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030", "description": "WordPress core REST batch route confusion chained with SQL injection; emergency anonymous mitigation across URL and parsed rest_route carriers", "mode": "block", "severity": 7.5, "tags": ["remote-code-execution", "sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=6.9.0 <6.9.5"}, "RULE-CVE-2026-63030-04": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/batch/v1[\\\\\\\\/]*$~i"}, {"type": "missing_capability", "value": "read"}], "cve": "CVE-2026-63030", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030", "description": "WordPress core REST batch route confusion chained with SQL injection; emergency anonymous mitigation across URL and parsed rest_route carriers", "mode": "block", "severity": 7.5, "tags": ["remote-code-execution", "sql-injection", "rest-api", "unauthenticated", "waf-bypass"], "target": "core", "versions": ">=7.0.0 <7.0.2"}, "RULE-CVE-2026-6320-01": {"ajax_action": "salon", "conditions": [{"name": "ARGS:file", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log|error_log))~i"}], "cve": "CVE-2026-6320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6320", "description": "Salon Booking System <=10.30.25 unauthenticated arbitrary file read via booking attachment file field path traversal", "mode": "block", "severity": 7.5, "slug": "salon-booking-system", "tags": ["arbitrary-file-read", "path-traversal", "unauthenticated", "file-inclusion"], "target": "plugin", "versions": "<=10.30.25"}, "RULE-CVE-2026-6372-01": {"action": "init", "conditions": [{"name": "ARGS:wc-api", "type": "regex", "value": "~^WC_Gateway_Plisio$~i"}, {"name": "ARGS:status", "type": "regex", "value": "~^(?:completed|mismatch|expired|cancelled)$~i"}], "cve": "CVE-2026-6372", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6372", "description": "Accept Cryptocurrencies with Plisio <=2.0.5 unauthenticated payment bypass via forged wc-api callback", "mode": "block", "severity": 7.5, "slug": "plisio-payment-gateway-for-woocommerce", "tags": ["missing-authorization", "payment-bypass", "unauthenticated", "woocommerce"], "target": "plugin", "versions": "<=2.0.5"}, "RULE-CVE-2026-6403-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/quickplayground/v1/blueprint/[^/?]+(?:[/?]|$)~"}, {"name": "ARGS:stylesheet", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|/(?:etc/passwd|wp-config\\\\.php|\\\\.htaccess|\\\\.env)|[a-z]:[/\\\\\\\\]|\\\\\\\\\\\\\\\\)~i"}], "cve": "CVE-2026-6403", "description": "Quick Playground <=1.3.3 unauthenticated path traversal via stylesheet parameter in blueprint REST endpoint", "mode": "block", "severity": 7.5, "slug": "quick-playground", "target": "plugin", "versions": "<=1.3.3"}, "RULE-CVE-2026-6427-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~]*(?:on(?:focus|error|load|mouseover|click|mouseenter)\\\\s*=|autofocus[\\\\s/>])~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-6427", "description": "a3 Lazy Load <=2.7.6 contributor+ stored XSS via crafted video element in post content (post editor)", "mode": "block", "severity": 6.4, "slug": "a3-lazy-load", "target": "plugin", "versions": "<=2.7.6"}, "RULE-CVE-2026-6427-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~]*(?:on(?:focus|error|load|mouseover|click|mouseenter)\\\\s*=|autofocus[\\\\s/>])~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-6427", "description": "a3 Lazy Load <=2.7.6 contributor+ stored XSS via crafted video element in post content (REST API)", "mode": "block", "severity": 6.4, "slug": "a3-lazy-load", "target": "plugin", "versions": "<=2.7.6"}, "RULE-CVE-2026-6431-01": {"action": "init", "conditions": [{"name": "ARGS:description", "type": "regex", "value": "~(?:]|]|]|on(?:error|load|mouseover|click|focus|blur|mouseenter|mouseleave)\\\\s*=|javascript\\\\s*:|data\\\\s*:\\\\s*text/html)~i"}], "cve": "CVE-2026-6431", "description": "Profile Builder <=3.15.7 unauthenticated stored XSS via Biographical Info \'description\' field on front-end registration/edit-profile forms", "mode": "block", "slug": "profile-builder", "target": "plugin", "versions": "<=3.15.7"}, "RULE-CVE-2026-6456-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/account-switcher/v1/remember-login(/|\\\\?|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6456", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6456", "description": "Account Switcher <=1.0.2 privilege escalation via rememberLogin REST endpoint loose comparison", "mode": "block", "severity": 8.8, "slug": "account-switcher", "tags": ["authentication-bypass", "privilege-escalation", "rest-api", "unauthenticated-from-subscriber"], "target": "plugin", "versions": "<=1.0.2"}, "RULE-CVE-2026-64638-01": {"action": "wp_authenticate", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-login\\\\.php(?:/[^?\\\\s]*)?(?:\\\\?|$)~i"}, {"name": "ARGS:/^log$/", "type": "regex", "value": "~<\\\\s+[a-z][a-z0-9:-]*(?:\\\\s|/?>)~i"}], "cve": "CVE-2026-64638", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf", "description": "WordPress core pre-auth reflected XSS through the wp-login.php username or email field", "method": "POST", "mode": "block", "severity": 8.9, "tags": ["cross-site-scripting", "reflected-xss", "unauthenticated", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.34 || >=4.8.0 <4.8.29 || >=4.9.0 <4.9.30 || >=5.0.0 <5.0.26 || >=5.1.0 <5.1.23 || >=5.2.0 <5.2.25 || >=5.3.0 <5.3.22 || >=5.4.0 <5.4.20 || >=5.5.0 <5.5.19 || >=5.6.0 <5.6.18 || >=5.7.0 <5.7.16 || >=5.8.0 <5.8.14 || >=5.9.0 <5.9.14 || >=6.0.0 <6.0.13 || >=6.1.0 <6.1.11 || >=6.2.0 <6.2.10 || >=6.3.0 <6.3.9 || >=6.4.0 <6.4.9 || >=6.5.0 <6.5.9 || >=6.6.0 <6.6.6 || >=6.7.0 <6.7.6 || >=6.8.0 <6.8.7 || >=6.9.0 <6.9.6 || >=7.0.0 <7.0.3"}, "RULE-CVE-2026-64638-02": {"action": "wp_authenticate", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-login\\\\.php(?:/[^?\\\\s]*)?(?:\\\\?|$)~i"}, {"name": "REQUEST_HEADERS:X-HTTP-Method-Override", "type": "regex", "value": "~^(?:GET|PUT|PATCH|DELETE)$~i"}, {"name": "ARGS:/^log$/", "type": "regex", "value": "~<\\\\s+[a-z][a-z0-9:-]*(?:\\\\s|/?>)~i"}], "cve": "CVE-2026-64638", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf", "description": "WordPress core pre-auth reflected XSS through wp-login.php with an HTTP method-override header", "mode": "block", "severity": 8.9, "tags": ["cross-site-scripting", "reflected-xss", "unauthenticated", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.34 || >=4.8.0 <4.8.29 || >=4.9.0 <4.9.30 || >=5.0.0 <5.0.26 || >=5.1.0 <5.1.23 || >=5.2.0 <5.2.25 || >=5.3.0 <5.3.22 || >=5.4.0 <5.4.20 || >=5.5.0 <5.5.19 || >=5.6.0 <5.6.18 || >=5.7.0 <5.7.16 || >=5.8.0 <5.8.14 || >=5.9.0 <5.9.14 || >=6.0.0 <6.0.13 || >=6.1.0 <6.1.11 || >=6.2.0 <6.2.10 || >=6.3.0 <6.3.9 || >=6.4.0 <6.4.9 || >=6.5.0 <6.5.9 || >=6.6.0 <6.6.6 || >=6.7.0 <6.7.6 || >=6.8.0 <6.8.7 || >=6.9.0 <6.9.6 || >=7.0.0 <7.0.3"}, "RULE-CVE-2026-64638-03": {"action": "wp_authenticate", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^|/)wp-login\\\\.php(?:/[^?\\\\s]*)?(?:\\\\?|$)~i"}, {"name": "ARGS:/^_method$/", "type": "regex", "value": "~^(?:GET|PUT|PATCH|DELETE)$~i"}, {"name": "ARGS:/^log$/", "type": "regex", "value": "~<\\\\s+[a-z][a-z0-9:-]*(?:\\\\s|/?>)~i"}], "cve": "CVE-2026-64638", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf", "description": "WordPress core pre-auth reflected XSS through wp-login.php with a form method override", "mode": "block", "severity": 8.9, "tags": ["cross-site-scripting", "reflected-xss", "unauthenticated", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.34 || >=4.8.0 <4.8.29 || >=4.9.0 <4.9.30 || >=5.0.0 <5.0.26 || >=5.1.0 <5.1.23 || >=5.2.0 <5.2.25 || >=5.3.0 <5.3.22 || >=5.4.0 <5.4.20 || >=5.5.0 <5.5.19 || >=5.6.0 <5.6.18 || >=5.7.0 <5.7.16 || >=5.8.0 <5.8.14 || >=5.9.0 <5.9.14 || >=6.0.0 <6.0.13 || >=6.1.0 <6.1.11 || >=6.2.0 <6.2.10 || >=6.3.0 <6.3.9 || >=6.4.0 <6.4.9 || >=6.5.0 <6.5.9 || >=6.6.0 <6.6.6 || >=6.7.0 <6.7.6 || >=6.8.0 <6.8.7 || >=6.9.0 <6.9.6 || >=7.0.0 <7.0.3"}, "RULE-CVE-2026-6495-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more~"}, {"name": "ARGS:alm_container_type", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_container_type", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-02": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more~"}, {"name": "ARGS:alm_class", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_class", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-03": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more~"}, {"name": "ARGS:alm_btn_color", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_btn_color", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-04": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more~"}, {"name": "ARGS:alm_btn_class", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_btn_class", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-05": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more~"}, {"name": "ARGS:alm_custom_js", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_custom_js", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-06": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more-repeaters~"}, {"name": "ARGS:alm_default_repeater", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_default_repeater", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-07": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more-repeaters~"}, {"name": "ARGS:alm_repeater", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_repeater", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-08": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more-theme-templates~"}, {"name": "ARGS:alm_theme_repeater", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_theme_repeater", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-09": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more-licenses~"}, {"name": "ARGS:alm_license_key", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_license_key", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-6495-10": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin\\\\.php.*page=ajax-load-more~"}, {"name": "ARGS:alm_preview", "type": "regex", "value": "~[<>\\"]|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2026-6495", "description": "Ajax Load More <=7.8.3 reflected XSS via alm_preview", "mode": "block", "severity": 7.1, "slug": "ajax-load-more", "target": "plugin", "versions": "<=7.8.3"}, "RULE-CVE-2026-65048-01": {"ajax_action": "nf_ajax_submit", "conditions": [{"name": "ARGS:formData", "type": "regex", "value": "~(?:]|<[^>]*\\\\bon[a-z]{3,20}\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-65048", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-65048", "description": "Ninja Forms >=3.10.4 <3.14.9 unauthenticated stored XSS via crafted repeater submission index in nf_ajax_submit formData", "mode": "block", "severity": 9.3, "slug": "ninja-forms", "tags": ["xss", "stored-xss", "unauthenticated", "form-submission"], "target": "plugin", "versions": ">=3.10.4 <3.14.9"}, "RULE-CVE-2026-65048-02": {"ajax_action": "nf_ajax_resume", "conditions": [{"name": "ARGS:formData", "type": "regex", "value": "~(?:]|<[^>]*\\\\bon[a-z]{3,20}\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-65048", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-65048", "description": "Ninja Forms >=3.10.4 <3.14.9 unauthenticated stored XSS via crafted repeater submission index in nf_ajax_resume formData", "mode": "block", "severity": 9.3, "slug": "ninja-forms", "tags": ["xss", "stored-xss", "unauthenticated", "form-submission"], "target": "plugin", "versions": ">=3.10.4 <3.14.9"}, "RULE-CVE-2026-65050-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_ID", "type": "exists"}, {"name": "ARGS", "type": "regex", "value": "~ninja-forms/submissions-table~"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-65050", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-65050", "description": "Ninja Forms <=3.14.8 missing authorization allows Author-level users to embed the ninja-forms/submissions-table block with an arbitrary formID via post save, exposing signed bearer tokens to unauthenticated visitors", "mode": "block", "severity": 6.5, "slug": "ninja-forms", "tags": ["missing-authorization", "information-disclosure", "broken-access-control"], "target": "plugin", "versions": "<=3.14.8"}, "RULE-CVE-2026-65051-01": {"ajax_action": "nf_ajax_submit", "conditions": [{"name": "ARGS:formData", "type": "regex", "value": "~\\"type\\"\\\\s*:\\\\s*\\"[a-z_]+\\".{0,200}\\"(?:required|settings)\\"\\\\s*:~is"}], "cve": "CVE-2026-65051", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-65051", "description": "Ninja Forms <3.14.9 unauthenticated server-side validation bypass via client-controlled field metadata (type/required/settings) merge in nf_ajax_submit AJAX handler", "mode": "block", "severity": 6.5, "slug": "ninja-forms", "tags": ["client-side-enforcement", "validation-bypass", "unauthenticated"], "target": "plugin", "versions": "<3.14.9"}, "RULE-CVE-2026-65051-02": {"ajax_action": "nf_ajax_resume", "conditions": [{"name": "ARGS:formData", "type": "regex", "value": "~\\"type\\"\\\\s*:\\\\s*\\"[a-z_]+\\".{0,200}\\"(?:required|settings)\\"\\\\s*:~is"}], "cve": "CVE-2026-65051", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-65051", "description": "Ninja Forms <3.14.9 unauthenticated server-side validation bypass via client-controlled field metadata (type/required/settings) merge in nf_ajax_resume AJAX handler", "mode": "block", "severity": 6.5, "slug": "ninja-forms", "tags": ["client-side-enforcement", "validation-bypass", "unauthenticated"], "target": "plugin", "versions": "<3.14.9"}, "RULE-CVE-2026-6518-01": {"ajax_action": "cmp_theme_update_install", "conditions": [{"name": "ARGS:file", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6518", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6518", "description": "CMP Coming Soon & Maintenance <=4.1.16 authenticated arbitrary file upload via cmp_theme_update_install AJAX action", "mode": "block", "severity": 8.8, "slug": "cmp-coming-soon-maintenance", "tags": ["arbitrary-file-upload", "remote-code-execution", "missing-authorization"], "target": "plugin", "versions": "<=4.1.16"}, "RULE-CVE-2026-65437-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/~i"}, {"name": "ARGS:m", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur|mouseenter|mouseleave)\\\\s*=|javascript\\\\s*:|]|]|]*onerror)~i"}], "cve": "CVE-2026-65437", "description": "Spam protection, AntiSpam, FireWall by CleanTalk <=6.82 unauthenticated reflected XSS via \'m\' parameter in CleantalkListTable::months_dropdown printf sink", "mode": "block", "slug": "cleantalk-spam-protect", "target": "plugin", "versions": "<=6.82"}, "RULE-CVE-2026-65439-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|%3[Cc]script|%6[Aa]%61%76%61%73%63%72%69%70%74)~i"}], "cve": "CVE-2026-65439", "description": "Ultimate Addons for Contact Form 7 <=3.5.45 reflected XSS via unescaped REQUEST_URI echoed by dynamic-text current-url shortcode", "mode": "block", "severity": 7.1, "slug": "ultimate-addons-for-contact-form-7", "target": "plugin", "versions": "<=3.5.45"}, "RULE-CVE-2026-65509-01": {"ajax_action": "wpdatatables_get_columns_data_by_table_id", "conditions": [{"name": "ARGS:table_id", "type": "regex", "value": "~^(?!^[0-9]+$).+$~"}], "cve": "CVE-2026-65509", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-65509", "description": "wpDataTables <7.5.2 reflected XSS via unescaped table_id echoed by wpdatatables_get_columns_data_by_table_id AJAX handler", "mode": "block", "severity": 7.1, "slug": "wpdatatables", "tags": ["xss", "reflected-xss", "authenticated"], "target": "plugin", "versions": "<7.5.2"}, "RULE-CVE-2026-65640-01": {"action": "init", "conditions": [{"name": "FILES:async-upload:content", "type": "regex", "value": "~\\\\A(?:%!|\\\\x04%!|\\\\xC5\\\\xD0\\\\xD3\\\\xC6|\\\\xFFWPC)~s"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core async-upload multipart field whose inspected bytes start with a plain PostScript resource header", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "postscript", "multipart-partial-coverage", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-02": {"action": "rest_api_init", "conditions": [{"name": "FILES:file:content", "type": "regex", "value": "~\\\\A(?:%!|\\\\x04%!|\\\\xC5\\\\xD0\\\\xD3\\\\xC6|\\\\xFFWPC)~s"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core REST multipart file field whose inspected bytes start with a plain PostScript resource header", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "postscript", "multipart-partial-coverage", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-03": {"action": "init", "conditions": [{"name": "FILES:async-upload:content", "type": "regex", "value": "~application/pdf.*(?:%!|\\\\x04%!|\\\\xC5\\\\xD0\\\\xD3\\\\xC6|\\\\xFFWPC)~s"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core async-upload multipart field carrying visible PDF cover metadata followed by a plain PostScript signature in the inspected prefix", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "postscript", "audio-cover", "multipart-partial-coverage", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-04": {"action": "rest_api_init", "conditions": [{"name": "FILES:file:content", "type": "regex", "value": "~application/pdf.*(?:%!|\\\\x04%!|\\\\xC5\\\\xD0\\\\xD3\\\\xC6|\\\\xFFWPC)~s"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core REST multipart file field carrying visible PDF cover metadata followed by a plain PostScript signature in the inspected prefix", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "postscript", "audio-cover", "multipart-partial-coverage", "wp-core"], "target": "core", "versions": ">=4.7.0 <4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-05": {"action": "init", "conditions": [{"name": "FILES:async-upload:name", "type": "regex", "value": "~\\\\.(?:dps|epi|eps[23fi]?|ept[23]?|ps[23]?|wpg)\\\\s*\\\\z~i"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core PostScript-family upload extension on the WordPress async-upload multipart field, which selects the Imagick PostScript coder and reaches Ghostscript without needing a visible signature", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "wp-core", "postscript", "postscript-extension"], "target": "core", "versions": "<4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-06": {"action": "rest_api_init", "conditions": [{"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:dps|epi|eps[23fi]?|ept[23]?|ps[23]?|wpg)\\\\s*\\\\z~i"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core PostScript-family upload extension on a multipart file field on requests reaching rest_api_init, which selects the Imagick PostScript coder and reaches Ghostscript without needing a visible signature", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "wp-core", "postscript", "postscript-extension"], "target": "core", "versions": "<4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-07": {"action": "init", "conditions": [{"name": "FILES:async-upload:name", "type": "regex", "value": "~\\\\.(?:ai|epdf|pdf|pdfa|pocketmod)\\\\s*\\\\z~i"}, {"name": "FILES:async-upload:content", "type": "regex", "value": "~\\\\A(?!%PDF-)~"}, {"name": "FILES:async-upload:content", "type": "regex", "value": "~(?:%!|\\\\xC5\\\\xD0\\\\xD3\\\\xC6|\\\\xFFWPC)~s"}, {"name": "FILES:async-upload:content", "type": "regex", "value": "~%pipe%|/OutputFile|putdeviceprops|\\\\.forceput|\\\\.libfile|\\\\.tempfile|\\\\.rsdparams|\\\\.setglobal|\\\\.actonuserparams|\\\\.bindnow|deletefile|renamefile~i"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core PDF-family upload on the WordPress async-upload multipart field that lacks the %PDF- signature yet carries a PostScript signature later in the inspected prefix, the pdf_load_source Ghostscript path", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "wp-core", "postscript", "pdf-signature-mismatch"], "target": "core", "versions": "<4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-08": {"action": "rest_api_init", "conditions": [{"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:ai|epdf|pdf|pdfa|pocketmod)\\\\s*\\\\z~i"}, {"name": "FILES:file:content", "type": "regex", "value": "~\\\\A(?!%PDF-)~"}, {"name": "FILES:file:content", "type": "regex", "value": "~(?:%!|\\\\xC5\\\\xD0\\\\xD3\\\\xC6|\\\\xFFWPC)~s"}, {"name": "FILES:file:content", "type": "regex", "value": "~%pipe%|/OutputFile|putdeviceprops|\\\\.forceput|\\\\.libfile|\\\\.tempfile|\\\\.rsdparams|\\\\.setglobal|\\\\.actonuserparams|\\\\.bindnow|deletefile|renamefile~i"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core PDF-family upload on a multipart file field on requests reaching rest_api_init that lacks the %PDF- signature yet carries a PostScript signature later in the inspected prefix, the pdf_load_source Ghostscript path", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "wp-core", "postscript", "pdf-signature-mismatch"], "target": "core", "versions": "<4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-09": {"action": "init", "conditions": [{"name": "FILES:async-upload:content", "type": "regex", "value": "~\\\\A(?:\\\\x1F\\\\x8B\\\\x08|BZh|\\\\x1F\\\\x9D)~s"}, {"name": "FILES:async-upload:name", "type": "regex", "value": "~\\\\.(?:jpe?g|jpe|png|gif|bmp|tiff?|webp|avif|ico|heic|heif|heics|heifs|ai|epdf|pdf|pdfa|pocketmod)\\\\s*\\\\z~i"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core compressed payload wearing an image or PDF extension on the WordPress async-upload multipart field, which Imagick transparently decompresses before deciding the format", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "wp-core", "postscript", "compressed-wrapper"], "target": "core", "versions": "<4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-65640-10": {"action": "rest_api_init", "conditions": [{"name": "FILES:file:content", "type": "regex", "value": "~\\\\A(?:\\\\x1F\\\\x8B\\\\x08|BZh|\\\\x1F\\\\x9D)~s"}, {"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:jpe?g|jpe|png|gif|bmp|tiff?|webp|avif|ico|heic|heif|heics|heifs|ai|epdf|pdf|pdfa|pocketmod)\\\\s*\\\\z~i"}], "cve": "CVE-2026-65640", "cve_link": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w", "description": "WordPress core compressed payload wearing an image or PDF extension on a multipart file field on requests reaching rest_api_init, which Imagick transparently decompresses before deciding the format", "mode": "block", "severity": 8.8, "tags": ["remote-code-execution", "malicious-file-upload", "wp-core", "postscript", "compressed-wrapper"], "target": "core", "versions": "<4.7.35 || >=4.8.0 <4.8.30 || >=4.9.0 <4.9.31 || >=5.0.0 <5.0.27 || >=5.1.0 <5.1.24 || >=5.2.0 <5.2.26 || >=5.3.0 <5.3.23 || >=5.4.0 <5.4.21 || >=5.5.0 <5.5.20 || >=5.6.0 <5.6.19 || >=5.7.0 <5.7.17 || >=5.8.0 <5.8.15 || >=5.9.0 <5.9.16 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.12 || >=6.2.0 <6.2.11 || >=6.3.0 <6.3.10 || >=6.4.0 <6.4.10 || >=6.5.0 <6.5.10 || >=6.6.0 <6.6.7 || >=6.7.0 <6.7.7 || >=6.8.0 <6.8.8 || >=6.9.0 <6.9.7 || >=7.0.0 <7.0.4"}, "RULE-CVE-2026-66424-01": {"ajax_action": "activate_pending_vendor", "conditions": [{"name": "ARGS:id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-66424", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66424", "description": "SMS Alert Order Notifications <=3.9.7 missing authorization on activate_pending_vendor AJAX action allows privilege escalation", "mode": "block", "severity": 9.8, "slug": "sms-alert", "tags": ["missing-authorization", "privilege-escalation", "broken-access-control"], "target": "plugin", "versions": "<=3.9.7"}, "RULE-CVE-2026-66424-02": {"ajax_action": "reject_pending_vendor", "conditions": [{"name": "ARGS:id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-66424", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66424", "description": "SMS Alert Order Notifications <=3.9.7 missing authorization on reject_pending_vendor AJAX action allows privilege escalation", "mode": "block", "severity": 9.8, "slug": "sms-alert", "tags": ["missing-authorization", "privilege-escalation", "broken-access-control"], "target": "plugin", "versions": "<=3.9.7"}, "RULE-CVE-2026-66424-03": {"ajax_action": "wcmp_suspend_vendor", "conditions": [{"name": "ARGS:id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-66424", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66424", "description": "SMS Alert Order Notifications <=3.9.7 missing authorization on wcmp_suspend_vendor AJAX action allows privilege escalation", "mode": "block", "severity": 9.8, "slug": "sms-alert", "tags": ["missing-authorization", "privilege-escalation", "broken-access-control"], "target": "plugin", "versions": "<=3.9.7"}, "RULE-CVE-2026-66424-04": {"ajax_action": "wcmp_activate_vendor", "conditions": [{"name": "ARGS:id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-66424", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66424", "description": "SMS Alert Order Notifications <=3.9.7 missing authorization on wcmp_activate_vendor AJAX action allows privilege escalation", "mode": "block", "severity": 9.8, "slug": "sms-alert", "tags": ["missing-authorization", "privilege-escalation", "broken-access-control"], "target": "plugin", "versions": "<=3.9.7"}, "RULE-CVE-2026-66439-01": {"ajax_action": "berocket_aapf_color_listener", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-66439", "description": "WooCommerce Ajax Product Filters (BeRocket) <=3.2.0.3 reflected XSS via br_product_filter/type parameters in berocket_aapf_color_listener AJAX handler", "mode": "block", "slug": "woocommerce-ajax-filters", "target": "plugin", "versions": "<=3.2.0.3"}, "RULE-CVE-2026-66439-02": {"ajax_action": "br_include_exclude_list", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-66439", "description": "WooCommerce Ajax Product Filters (BeRocket) <=3.2.0.3 reflected XSS via br_product_filter parameter in br_include_exclude_list AJAX handler", "mode": "block", "slug": "woocommerce-ajax-filters", "target": "plugin", "versions": "<=3.2.0.3"}, "RULE-CVE-2026-66446-01": {"ajax_action": "ifso_analytics_req", "conditions": [{"name": "ARGS:an_action", "type": "regex", "value": "~^(?:getTriggerReport|resetFields|resetAllAnalytics)$~i"}, {"type": "missing_capability", "value": "administrator"}, {"type": "missing_capability", "value": "editor"}], "cve": "CVE-2026-66446", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66446", "description": "If-So Dynamic Content Personalization <1.10.0.1 authorization bypass in ifso_analytics_req AJAX handler (handle()) allows subscriber-level access to administrative report/reset actions (getTriggerReport, resetFields, resetAllAnalytics) that feed SQL injection in records-service queries", "mode": "block", "severity": 9.3, "slug": "if-so", "tags": ["sql-injection", "missing-authorization", "broken-access-control", "authenticated"], "target": "plugin", "versions": "<1.10.0.1"}, "RULE-CVE-2026-66457-01": {"ajax_action": "search_events_grouped", "conditions": [{"name": "ARGS:header_format", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-66457", "description": "Events Manager <=7.4.1 unauthenticated reflected XSS via header_format parameter in grouped event list AJAX search", "mode": "block", "slug": "events-manager", "target": "plugin", "versions": "<=7.4.1"}, "RULE-CVE-2026-66457-02": {"ajax_action": "search_events_grouped", "conditions": [{"name": "ARGS:date_format", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-66457", "description": "Events Manager <=7.4.1 unauthenticated reflected XSS via date_format parameter in grouped event list AJAX search", "mode": "block", "slug": "events-manager", "target": "plugin", "versions": "<=7.4.1"}, "RULE-CVE-2026-66574-01": {"action": "init", "conditions": [{"name": "ARGS:/title_tag|title_tags|sub_title_size|title_size/", "type": "regex", "value": "~[\\"\'<>\\\\s]|on\\\\w+\\\\s*=|javascript\\\\s*:~i"}, {"type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-66574", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66574", "description": "Element Pack Elementor Addons <=8.8.3 Contributor stored XSS via unsanitized dynamic HTML tag settings (title_tag, title_tags, sub_title_size, title_size) in animated-card, custom-gallery, and fancy-list widgets", "mode": "block", "severity": 6.5, "slug": "bdthemes-element-pack-lite", "tags": ["xss", "stored", "contributor", "elementor-widget"], "target": "plugin", "versions": "<=8.8.3"}, "RULE-CVE-2026-66583-01": {"action": "init", "conditions": [{"name": "ARGS:form_uid", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]*\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-66583", "description": "Forminator <=1.57.0.5 unauthenticated PHP Object Injection via form_uid parameter", "mode": "block", "severity": 9.8, "slug": "forminator", "target": "plugin", "versions": "<=1.57.0.5"}, "RULE-CVE-2026-66602-01": {"action": "admin_init", "conditions": [{"name": "ARGS:action", "type": "regex", "value": "~^csf_.*_ajax_save$~"}, {"name": "ARGS:data", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-66602", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66602", "description": "HashBar - WordPress Notification Bar <=2.0.0 CSRF via unprotected Codestar admin options ajax_save handler", "mode": "block", "severity": 8.8, "slug": "hashbar-wp-notification-bar", "tags": ["csrf", "missing-authorization", "authenticated"], "target": "plugin", "versions": "<=2.0.0"}, "RULE-CVE-2026-66608-01": {"ajax_action": "unitecreator_elementor_import_template", "conditions": [{"type": "missing_capability", "value": "edit_pages"}], "cve": "CVE-2026-66608", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66608", "description": "Unlimited Elements For Elementor <=2.0.19 Contributor-level SSRF exposure via unauthorized elementor_integrate template import AJAX action", "mode": "block", "severity": 6.4, "slug": "unlimited-elements-for-elementor", "tags": ["ssrf", "authenticated", "missing-authorization", "elementor"], "target": "plugin", "versions": "<=2.0.19"}, "RULE-CVE-2026-66608-02": {"ajax_action": "unitecreator_elementor_export_template", "conditions": [{"type": "missing_capability", "value": "edit_pages"}], "cve": "CVE-2026-66608", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66608", "description": "Unlimited Elements For Elementor <=2.0.19 Contributor-level SSRF exposure via unauthorized elementor_integrate template export AJAX action", "mode": "block", "severity": 6.4, "slug": "unlimited-elements-for-elementor", "tags": ["ssrf", "authenticated", "missing-authorization", "elementor"], "target": "plugin", "versions": "<=2.0.19"}, "RULE-CVE-2026-66618-01": {"action": "init", "conditions": [{"name": "ARGS:map_locations[/[0-9]+/]", "type": "regex", "value": "~^(?![0-9]+$).+$~"}], "cve": "CVE-2026-66618", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66618", "description": "WP Maps (wp-google-map-plugin) <5.0.0 administrator SQL injection via non-numeric map_locations array values reaching the shared IN() query builder", "mode": "block", "severity": 7.6, "slug": "wp-google-map-plugin", "tags": ["sql-injection", "administrator", "authenticated"], "target": "plugin", "versions": "<5.0.0"}, "RULE-CVE-2026-66618-02": {"action": "init", "conditions": [{"name": "ARGS:map_locations", "type": "regex", "value": "~^(?![0-9]+$).+$~"}], "cve": "CVE-2026-66618", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66618", "description": "WP Maps (wp-google-map-plugin) <5.0.0 administrator SQL injection via non-numeric map_locations scalar value reaching the shared IN() query builder", "mode": "block", "severity": 7.6, "slug": "wp-google-map-plugin", "tags": ["sql-injection", "administrator", "authenticated"], "target": "plugin", "versions": "<5.0.0"}, "RULE-CVE-2026-66659-01": {"ajax_action": "get_redirection_data", "conditions": [{"name": "ARGS:redirect_token", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+[0-9]+\\\\s*=\\\\s*[0-9]+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|[\'\\"]\\\\s*(?:OR|AND)\\\\s|--\\\\s|/\\\\*.*?\\\\*/)~i"}], "cve": "CVE-2026-66659", "description": "Tablesome Table <=1.2.9 unauthenticated blind SQL injection via redirect_token parameter in get_redirection_data AJAX action", "mode": "block", "slug": "tablesome", "target": "plugin", "versions": "<=1.2.9"}, "RULE-CVE-2026-66667-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~i"}, {"name": "ARGS:action", "type": "regex", "value": "~^templately_pack_~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-66667", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66667", "description": "Templately <=3.7.1 missing authorization on templately_pack_* full-site/template pack import AJAX handler enabling unauthenticated stored XSS via unsanitized custom CSS option", "mode": "block", "severity": 7.1, "slug": "templately", "tags": ["missing-authorization", "stored-xss", "template-import"], "target": "plugin", "versions": "<=3.7.1"}, "RULE-CVE-2026-66708-01": {"ajax_action": "boldgrid_transfer_resync_database", "conditions": [{"type": "missing_capability", "value": "update_plugins"}], "cve": "CVE-2026-66708", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-66708", "description": "Total Upkeep (boldgrid-backup) <1.17.3 missing authorization on boldgrid_transfer_resync_database AJAX handler allows any authenticated user to trigger database resync file read/write/delete", "mode": "block", "severity": 8.2, "slug": "boldgrid-backup", "tags": ["missing-authorization", "broken-access-control", "authenticated"], "target": "plugin", "versions": "<1.17.3"}, "RULE-CVE-2026-6690-01": {"ajax_action": "lp_update_mds", "conditions": [{"name": "ARGS:n", "type": "regex", "value": "~(?:]|on[a-z]+\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-6690", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6690", "description": "LifePress <=2.2.2 unauthenticated stored XSS via lp_update_mds AJAX action", "mode": "block", "severity": 7.2, "slug": "lifepress", "tags": ["xss", "stored", "unauthenticated"], "target": "plugin", "versions": "<=2.2.2"}, "RULE-CVE-2026-6741-01": {"ajax_action": "latepoint_route_call", "conditions": [{"name": "ARGS:wp_user_id", "type": "exists"}, {"name": "ARGS:customer_id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6741", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6741", "description": "LatePoint <=5.4.1 privilege escalation via unauthorized customer-to-WordPress-user account linking in latepoint_route_call AJAX action", "mode": "block", "severity": 8.8, "slug": "latepoint", "tags": ["privilege-escalation", "missing-authorization", "account-takeover"], "target": "plugin", "versions": "<=5.4.1"}, "RULE-CVE-2026-6817-01": {"ajax_action": "ays_rate_the_quiz", "conditions": [{"name": "ARGS:rate_reason", "type": "regex", "value": "~(?:<\\\\s*(?:script|img|svg|iframe|object|embed|link|meta|style|a|body|input|form|video|audio|source|details|marquee)\\\\b|on(?:load|error|click|mouseover|focus|blur|toggle|animationend|animationstart|animationiteration|transitionend|pointerover|pointerdown|pointerup|pointermove|pointerenter|pointerleave|pointercancel|gotpointercapture|lostpointercapture|wheel|contextmenu|copy|cut|paste|drag|dragstart|dragend|dragenter|dragleave|dragover|drop|input|change|select|submit|reset|keydown|keyup|keypress|touchstart|touchend|touchmove|touchcancel|abort|beforeunload|hashchange|message|offline|online|pagehide|pageshow|popstate|resize|storage|unload)\\\\s*=|javascript\\\\s*:|data\\\\s*:\\\\s*text/html|srcdoc\\\\s*=|?0*(?:3c|60)\\\\s*;\\\\s*script)~i"}], "cve": "CVE-2026-6817", "description": "Quiz Maker by AYS <=6.7.1.29 unauthenticated stored XSS via rate_reason parameter in ays_rate_the_quiz AJAX action", "mode": "block", "severity": 5.8, "slug": "quiz-maker", "target": "plugin", "versions": "<=6.7.1.29"}, "RULE-CVE-2026-6817-02": {"ajax_action": "ays_load_more_reviews", "conditions": [{"name": "ARGS:start_from", "type": "regex", "value": "~(?:<\\\\s*(?:script|img|svg|iframe|object|embed|link|meta|style|a|body|input|form|video|audio|source|details|marquee)\\\\b|on(?:load|error|click|mouseover|focus|blur|toggle)\\\\s*=|javascript\\\\s*:|data\\\\s*:\\\\s*text/html|srcdoc\\\\s*=)~i"}], "cve": "CVE-2026-6817", "description": "Quiz Maker by AYS <=6.7.1.29 unauthenticated stored XSS render path via ays_load_more_reviews start_from parameter", "mode": "block", "severity": 5.8, "slug": "quiz-maker", "target": "plugin", "versions": "<=6.7.1.29"}, "RULE-CVE-2026-6828-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[fluentform\\\\s[^\\\\]]*permission_message\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+\\\\bonerror\\\\b|]*\\\\bon(?:load|error)\\\\b)~i"}, {"name": "", "type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-6828", "description": "Fluent Forms <=6.2.1 contributor+ stored XSS via permission_message shortcode attribute in post content (post.php)", "mode": "block", "severity": 6.4, "slug": "fluentform", "target": "plugin", "versions": "<=6.2.1"}, "RULE-CVE-2026-6828-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/(?:posts|pages)~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[fluentform\\\\s[^\\\\]]*permission_message\\\\s*=\\\\s*[\\"\'][^\\"\']*(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|]+\\\\bonerror\\\\b|]*\\\\bon(?:load|error)\\\\b)~i"}, {"name": "", "type": "missing_capability", "value": "unfiltered_html"}], "cve": "CVE-2026-6828", "description": "Fluent Forms <=6.2.1 contributor+ stored XSS via permission_message shortcode attribute in post content (REST API)", "mode": "block", "severity": 6.4, "slug": "fluentform", "target": "plugin", "versions": "<=6.2.1"}, "RULE-CVE-2026-6916-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~"}, {"name": "ARGS:action", "type": "equals", "value": "elementor_ajax"}, {"name": "ARGS:actions", "type": "regex", "value": "~sg_content_number_prefix[\\"\'\\\\\\\\]*\\\\s*:\\\\s*[\\"\'\\\\\\\\]*[^\\"\'}]*(?:[^\\"\'}]|\')*(?:<[a-zA-Z!/]|on(?:error|load|click|mouseover|focus|blur)\\\\s*=|javascript\\\\s*:|?[0-9a-f]+;?<|%3C(?:script|img|svg|iframe))~i"}], "cve": "CVE-2026-6916", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6916", "description": "Jeg Elementor Kit >=3.0.0 <=3.1.0 contributor+ stored XSS via Fun Fact widget sg_content_number_prefix setting", "mode": "block", "severity": 6.4, "slug": "jeg-elementor-kit", "tags": ["xss", "stored", "authenticated"], "target": "plugin", "versions": ">=3.0.0 <=3.1.0"}, "RULE-CVE-2026-6933-01": {"action": "admin_init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "create_plugin"}, {"name": "ARGS:premmerce_plugin_namespace", "type": "regex", "value": "~[;{}()$`]|\\\\b(?:system|exec|passthru|shell_exec|popen|proc_open|eval|assert|phpinfo|file_put_contents|file_get_contents|base64_decode|unlink)\\\\s*\\\\(~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6933", "description": "Premmerce Dev Tools <=2.0 authenticated RCE via unsanitized namespace injection in plugin generator", "mode": "block", "severity": 8.8, "slug": "premmerce-dev-tools", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2026-6933-02": {"action": "admin_init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "generate_data"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6933", "description": "Premmerce Dev Tools <=2.0 missing authorization on generate_data admin-post action", "mode": "block", "severity": 8.8, "slug": "premmerce-dev-tools", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2026-6933-03": {"action": "admin_init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "clean_up"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6933", "description": "Premmerce Dev Tools <=2.0 missing authorization on clean_up admin-post action", "mode": "block", "severity": 8.8, "slug": "premmerce-dev-tools", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2026-6963-01": {"ajax_action": "wmg_save_provider_config", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6963", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6963", "description": "WP Mail Gateway <=1.8 missing authorization on wmg_save_provider_config allows subscriber+ privilege escalation", "mode": "block", "severity": 9.8, "slug": "wp-mail-gateway", "tags": ["missing-authorization", "privilege-escalation"], "target": "plugin", "versions": "<=1.8"}, "RULE-CVE-2026-6963-02": {"ajax_action": "wmg_get_saved_configs", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6963", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6963", "description": "WP Mail Gateway <=1.8 missing authorization on wmg_get_saved_configs allows subscriber+ data disclosure", "mode": "block", "severity": 7.5, "slug": "wp-mail-gateway", "tags": ["missing-authorization", "information-disclosure"], "target": "plugin", "versions": "<=1.8"}, "RULE-CVE-2026-6963-03": {"ajax_action": "wmg_test_provider_config_send_mail", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-6963", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-6963", "description": "WP Mail Gateway <=1.8 missing authorization on wmg_test_provider_config_send_mail allows subscriber+ email sending", "mode": "block", "severity": 7.5, "slug": "wp-mail-gateway", "tags": ["missing-authorization", "email-abuse"], "target": "plugin", "versions": "<=1.8"}, "RULE-CVE-2026-7048-01": {"action": "init", "conditions": [{"name": "ARGS:content", "type": "regex", "value": "~Best_Wordpress_Gallery[^\\\\]]*order_by\\\\s*=\\\\s*[\\"\']?[^\\"\'\\\\]]*(?:SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:EXTRACT|UPDATE)XML\\\\s*\\\\(|\\\\(\\\\s*SELECT\\\\s|IF\\\\s*\\\\(|CASE\\\\s+WHEN|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|SELECT)\\\\s|UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s)~i"}], "cve": "CVE-2026-7048", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-7048", "description": "Photo Gallery by 10Web <=1.8.40 authenticated SQL injection via Best_Wordpress_Gallery shortcode order_by attribute in post content", "mode": "block", "severity": 6.5, "slug": "photo-gallery", "tags": ["sql-injection", "authenticated", "shortcode"], "target": "plugin", "versions": "<=1.8.40"}, "RULE-CVE-2026-7048-02": {"action": "init", "conditions": [{"name": "ARGS:post_content", "type": "regex", "value": "~Best_Wordpress_Gallery[^\\\\]]*order_by\\\\s*=\\\\s*[\\"\']?[^\\"\'\\\\]]*(?:SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:EXTRACT|UPDATE)XML\\\\s*\\\\(|\\\\(\\\\s*SELECT\\\\s|IF\\\\s*\\\\(|CASE\\\\s+WHEN|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|SELECT)\\\\s|UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s)~i"}], "cve": "CVE-2026-7048", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-7048", "description": "Photo Gallery by 10Web <=1.8.40 authenticated SQL injection via Best_Wordpress_Gallery shortcode order_by attribute in post_content parameter", "mode": "block", "severity": 6.5, "slug": "photo-gallery", "tags": ["sql-injection", "authenticated", "shortcode"], "target": "plugin", "versions": "<=1.8.40"}, "RULE-CVE-2026-7106-01": {"action": "personal_options_update", "conditions": [{"name": "ARGS:hscrm_user_roles", "type": "exists"}, {"type": "missing_capability", "value": "promote_users"}], "cve": "CVE-2026-7106", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-7106", "description": "Highland Software Custom Role Manager <=1.0.0 authenticated privilege escalation via hscrm_user_roles[] on personal_options_update", "method": "POST", "mode": "block", "severity": 8.8, "slug": "highland-software-custom-role-manager", "tags": ["missing-authorization", "privilege-escalation", "authenticated"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2026-7252-01": {"ajax_action": "updraft_smush_ajax", "conditions": [{"name": "ARGS:do", "type": "equals", "value": "unscheduled_original_file_deletion"}, {"name": "ARGS:attachment_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2026-7252", "mode": "block", "severity": 8.1, "slug": "wp-optimize", "target": "plugin", "versions": "<=4.5.2"}, "RULE-CVE-2026-73187-01": {"ajax_action": "scw_save_form_data", "conditions": [{"name": "ARGS_NAMES", "type": "regex", "value": "~scw_form_fields\\\\[[^\\\\]]*(?:[`\'\\";)(]|--|#|/\\\\*|UNION\\\\s+SELECT)~i"}], "cve": "CVE-2026-73187", "description": "Sticky Chat Widget <=1.4.2 unauthenticated SQL injection via attacker-controlled scw_form_fields array keys in scw_save_form_data AJAX handler", "mode": "block", "severity": 9.3, "slug": "sticky-chat-widget", "target": "plugin", "versions": "<=1.4.2"}, "RULE-CVE-2026-7330-01": {"ajax_action": "aal_stats_save", "conditions": [{"name": "ARGS:url", "type": "regex", "value": "~(?:]|on(?:error|load|click|mouseover|mouseout|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2026-7330", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-7330", "description": "WP Auto Affiliate Links <=6.8.8 unauthenticated stored XSS via url parameter", "mode": "block", "severity": 7.2, "slug": "wp-auto-affiliate-links", "tags": ["xss", "stored", "unauthenticated"], "target": "plugin", "versions": "<=6.8.8"}, "RULE-CVE-2026-73341-01": {"ajax_action": "rm_activate_user", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]+\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-73341", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73341", "description": "RegistrationMagic (Custom Registration Form Builder with Submission Manager) <=6.0.9.7 unauthenticated PHP object injection via rm_activate_user AJAX action", "mode": "block", "severity": 9.8, "slug": "custom-registration-form-builder-with-submission-manager", "tags": ["object-injection", "deserialization", "unauthenticated"], "target": "plugin", "versions": "<=6.0.9.7"}, "RULE-CVE-2026-73341-02": {"ajax_action": "rm_login_social_user", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?:O|C):[0-9]+:\\"[^\\"]+\\":[0-9]+:\\\\{~"}], "cve": "CVE-2026-73341", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73341", "description": "RegistrationMagic (Custom Registration Form Builder with Submission Manager) <=6.0.9.7 unauthenticated PHP object injection via rm_login_social_user AJAX action", "mode": "block", "severity": 9.8, "slug": "custom-registration-form-builder-with-submission-manager", "tags": ["object-injection", "deserialization", "unauthenticated"], "target": "plugin", "versions": "<=6.0.9.7"}, "RULE-CVE-2026-73343-01": {"ajax_action": "wpc_v2_lazy_patch_setting", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73343", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73343", "description": "WP Compress <7.20.01 unauthenticated settings write via wpc_v2_lazy_patch_setting AJAX action lacking any WordPress nonce or capability check", "mode": "block", "severity": 10.0, "slug": "wp-compress-image-optimizer", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<7.20.01"}, "RULE-CVE-2026-73343-02": {"ajax_action": "wpc_v2_lazy_opcache_invalidate", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73343", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73343", "description": "WP Compress <7.20.01 unauthenticated forced opcode cache invalidation via wpc_v2_lazy_opcache_invalidate AJAX action lacking any WordPress nonce or capability check", "mode": "block", "severity": 10.0, "slug": "wp-compress-image-optimizer", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<7.20.01"}, "RULE-CVE-2026-73343-03": {"ajax_action": "wpc_v2_lazy_test_purge_html", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73343", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73343", "description": "WP Compress <7.20.01 unauthenticated local file inclusion via image_id parameter in wpc_v2_lazy_test_purge_html AJAX action lacking any WordPress nonce or capability check", "mode": "block", "severity": 10.0, "slug": "wp-compress-image-optimizer", "tags": ["missing-authorization", "unauthenticated", "local-file-inclusion"], "target": "plugin", "versions": "<7.20.01"}, "RULE-CVE-2026-73343-04": {"ajax_action": "wpc_v2_provision_now", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73343", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73343", "description": "WP Compress <7.20.01 unauthenticated CDN/config provisioning via wpc_v2_provision_now AJAX action lacking any WordPress nonce or capability check", "mode": "block", "severity": 10.0, "slug": "wp-compress-image-optimizer", "tags": ["missing-authorization", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<7.20.01"}, "RULE-CVE-2026-73348-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "give-form-preview"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73348", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73348", "description": "GiveWP <4.16.6 missing capability check on onboarding form preview allows unauthorized access via page=give-form-preview", "mode": "block", "severity": 6.5, "slug": "give", "tags": ["missing-authorization", "broken-access-control"], "target": "plugin", "versions": "<4.16.6"}, "RULE-CVE-2026-73355-01": {"ajax_action": "wpam_ajax_activate_affiliate", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73355", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73355", "description": "Affiliates Manager <2.9.54 missing authorization on wpam_ajax_activate_affiliate AJAX handler", "mode": "block", "severity": 9.3, "slug": "affiliates-manager", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<2.9.54"}, "RULE-CVE-2026-73355-02": {"ajax_action": "wpam_ajax_deactivate_affiliate", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73355", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73355", "description": "Affiliates Manager <2.9.54 missing authorization on wpam_ajax_deactivate_affiliate AJAX handler", "mode": "block", "severity": 9.3, "slug": "affiliates-manager", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<2.9.54"}, "RULE-CVE-2026-73355-03": {"ajax_action": "wpam_ajax_add_transaction", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73355", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73355", "description": "Affiliates Manager <2.9.54 missing authorization on wpam_ajax_add_transaction AJAX handler", "mode": "block", "severity": 9.3, "slug": "affiliates-manager", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<2.9.54"}, "RULE-CVE-2026-73355-04": {"ajax_action": "wpam_ajax_delete_creative", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73355", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73355", "description": "Affiliates Manager <2.9.54 missing authorization on wpam_ajax_delete_creative AJAX handler", "mode": "block", "severity": 9.3, "slug": "affiliates-manager", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<2.9.54"}, "RULE-CVE-2026-73355-05": {"ajax_action": "wpam_ajax_set_creative_status", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-73355", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73355", "description": "Affiliates Manager <2.9.54 missing authorization on wpam_ajax_set_creative_status AJAX handler", "mode": "block", "severity": 9.3, "slug": "affiliates-manager", "tags": ["missing-authorization", "broken-access-control", "unauthenticated"], "target": "plugin", "versions": "<2.9.54"}, "RULE-CVE-2026-73356-01": {"action": "init", "conditions": [{"name": "REQUEST_COOKIES:/wcml_client_currency|aelia_cs_selected_currency/", "type": "regex", "value": "~^(?![A-Za-z]{3}$).+~"}], "cve": "CVE-2026-73356", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73356", "description": "Breeze <=2.5.12 unauthenticated cache-variation cookie value manipulation via wcml_client_currency/aelia_cs_selected_currency", "mode": "block", "severity": 8.2, "slug": "breeze", "tags": ["cache-poisoning", "header-injection", "unauthenticated"], "target": "plugin", "versions": "<=2.5.12"}, "RULE-CVE-2026-73381-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-admin/admin-ajax\\\\.php~i"}, {"name": "ARGS:action", "type": "regex", "value": "~::~"}], "cve": "CVE-2026-73381", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73381", "description": "Popup by Supsystic <=1.13.0 unauthenticated broken authentication via PHP Class::method callable-syntax injection in dynamic admin-ajax action parameter", "mode": "block", "severity": 9.1, "slug": "popup-by-supsystic", "tags": ["missing-authorization", "broken-authentication", "unauthenticated"], "target": "plugin", "versions": "<=1.13.0"}, "RULE-CVE-2026-73382-01": {"action": "init", "conditions": [{"name": "ARGS:_rendered", "type": "exists"}, {"type": "missing_capability", "value": "create_posts"}], "cve": "CVE-2026-73382", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73382", "description": "Site Reviews <=8.2.0 reported unauthenticated XSS; only grounded evidence is the REST review-creation _rendered field gated by create_posts capability (advisory-vs-code contradiction unresolved, no source-to-sink trace, REST route not statically literal, capability backstop only)", "mode": "block", "severity": 7.1, "slug": "site-reviews", "tags": ["xss", "rest-api", "authorization-contradiction"], "target": "plugin", "versions": "<=8.2.0"}, "RULE-CVE-2026-73992-01": {"ajax_action": "qw_form_ajax", "conditions": [{"name": "ARGS:form", "type": "equals", "value": "preview"}, {"type": "missing_capability", "value": "edit_others_posts"}], "cve": "CVE-2026-73992", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73992", "description": "Query Wrangler <=1.5.57 registers qw_form_ajax on wp_ajax_ only (no nopriv), so any logged-in user reaches it. The preview branch urldecode()s the options parameter and parse_str()s it into query options that reach three callable sinks gated only by function_exists(): includes/fields/callback_field.php:29 (custom_output_callback), includes/filters/post_id.php:56 (post_ids_callback) and includes/filters/callback.php:57 (callback). 1.5.58 fixes it by requiring edit_others_posts on the whole endpoint, which is what this rule enforces. Matching the sink names instead is not viable: admin/ajax.php:11 urldecode()s options a SECOND time after PHP already form-decoded it, while the engine reads $_POST, so any sink name survives one extra percent-encoding layer (custom_output_%2563allback) and the real wire format of the third sink is %5Bcallback%5D, which no literal [callback] pattern can match.", "method": "POST", "mode": "block", "severity": 9.9, "slug": "query-wrangler", "tags": ["remote-code-execution", "authenticated", "missing-capability"], "target": "plugin", "versions": "<=1.5.57"}, "RULE-CVE-2026-73994-01": {"ajax_action": "charitable_update_debug_window_ajax", "conditions": [{"type": "missing_capability", "value": "manage_charitable_settings"}], "cve": "CVE-2026-73994", "description": "Charitable <=1.8.11.3 unauthenticated access to debug window AJAX handler via missing authorization on charitable_update_debug_window_ajax", "mode": "block", "severity": 7.5, "slug": "charitable", "target": "plugin", "versions": "<=1.8.11.3"}, "RULE-CVE-2026-73996-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/masteriyo/pro/v1/certificate-pdf-email[\\\\\\\\/]*(?:[?&]|$)~i"}, {"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2026-73996", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73996", "description": "Masteriyo LMS <=2.3.2 unauthenticated arbitrary file upload via certificate-pdf-email REST endpoint", "mode": "block", "severity": 9.8, "slug": "learning-management-system", "tags": ["arbitrary-file-upload", "unauthenticated", "missing-authorization", "rest-api"], "target": "plugin", "versions": "<=2.3.2"}, "RULE-CVE-2026-73996-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/masteriyo/pro/v1/certificate-pdf-email[\\\\\\\\/]*$~i"}, {"type": "missing_capability", "value": "upload_files"}], "cve": "CVE-2026-73996", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73996", "description": "Masteriyo LMS <=2.3.2 unauthenticated arbitrary file upload via certificate-pdf-email REST endpoint", "mode": "block", "severity": 9.8, "slug": "learning-management-system", "tags": ["arbitrary-file-upload", "unauthenticated", "missing-authorization", "rest-api"], "target": "plugin", "versions": "<=2.3.2"}, "RULE-CVE-2026-73997-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/kadence-starter-library/v1/process_images[\\\\\\\\/]*(?:[?&]|$)~i"}, {"name": "ARGS:sizes[50]", "type": "exists"}], "cve": "CVE-2026-73997", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73997", "description": "Starter Templates by Kadence WP <=2.3.3 unauthenticated denial of service via unbounded image sizes array in process_images REST endpoint", "mode": "block", "severity": 7.5, "slug": "kadence-starter-templates", "tags": ["denial-of-service", "resource-exhaustion", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=2.3.3"}, "RULE-CVE-2026-73997-02": {"action": "rest_api_init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/kadence-starter-library/v1/process_images[\\\\\\\\/]*$~i"}, {"name": "ARGS:sizes[50]", "type": "exists"}], "cve": "CVE-2026-73997", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-73997", "description": "Starter Templates by Kadence WP <=2.3.3 unauthenticated denial of service via unbounded image sizes array in process_images REST endpoint", "mode": "block", "severity": 7.5, "slug": "kadence-starter-templates", "tags": ["denial-of-service", "resource-exhaustion", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=2.3.3"}, "RULE-CVE-2026-7465-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_content", "type": "regex", "value": "~wp:uagb/[a-zA-Z0-9_-]+\\\\s*\\\\{[^}]*render_callback~i"}], "cve": "CVE-2026-7465", "description": "Spectra Gutenberg Blocks <=2.19.25 authenticated (Contributor+) RCE via fake uagb/ block render_callback in post content (classic editor)", "mode": "block", "severity": 8.8, "slug": "ultimate-addons-for-gutenberg", "target": "plugin", "versions": "<=2.19.25"}, "RULE-CVE-2026-7465-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts(?:/[0-9]+)?(?:[/?]|$)~"}, {"name": "ARGS:content", "type": "regex", "value": "~wp:uagb/[a-zA-Z0-9_-]+\\\\s*\\\\{[^}]*render_callback~i"}], "cve": "CVE-2026-7465", "description": "Spectra Gutenberg Blocks <=2.19.25 authenticated (Contributor+) RCE via fake uagb/ block render_callback in post content (REST API)", "mode": "block", "severity": 8.8, "slug": "ultimate-addons-for-gutenberg", "target": "plugin", "versions": "<=2.19.25"}, "RULE-CVE-2026-74851-01": {"ajax_action": "pods_admin", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-74851", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-74851", "description": "Pods <3.3.9.1 unauthenticated access to pods_admin AJAX handler (wp_ajax_nopriv_pods_admin) removed in 3.3.9.1 hardening", "mode": "block", "severity": 7.2, "slug": "pods", "tags": ["missing-authorization", "unauthenticated", "admin-ajax"], "target": "plugin", "versions": "<3.3.9.1"}, "RULE-CVE-2026-74851-02": {"ajax_action": "pods_admin_components", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-74851", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-74851", "description": "Pods <3.3.9.1 unauthenticated access to pods_admin_components AJAX handler (wp_ajax_nopriv_pods_admin_components) removed in 3.3.9.1 hardening", "mode": "block", "severity": 7.2, "slug": "pods", "tags": ["missing-authorization", "unauthenticated", "admin-ajax"], "target": "plugin", "versions": "<3.3.9.1"}, "RULE-CVE-2026-74992-01": {"ajax_action": "kirki_post_apis", "conditions": [{"name": "ARGS:endpoint", "type": "regex", "value": "~(?:upload[_-]?font[_-]?zip|upload[_-]?fonts?)~i"}], "cve": "CVE-2026-74992", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-74992", "description": "Kirki <=6.2.2 authenticated (Editor+) unrestricted custom-font archive upload leading to stored XSS/RCE via kirki_post_apis AJAX endpoint dispatch", "mode": "block", "severity": 6.8, "slug": "kirki", "tags": ["unrestricted-file-upload", "stored-xss", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=6.2.2"}, "RULE-CVE-2026-74992-02": {"ajax_action": "kirki_wp_admin_post_apis", "conditions": [{"name": "ARGS:endpoint", "type": "regex", "value": "~(?:upload[_-]?font[_-]?zip|upload[_-]?fonts?)~i"}], "cve": "CVE-2026-74992", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-74992", "description": "Kirki <=6.2.2 authenticated (Editor+) unrestricted custom-font archive upload leading to stored XSS/RCE via kirki_wp_admin_post_apis AJAX endpoint dispatch", "mode": "block", "severity": 6.8, "slug": "kirki", "tags": ["unrestricted-file-upload", "stored-xss", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=6.2.2"}, "RULE-CVE-2026-75528-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "blc_local"}, {"name": "ARGS:filter_id", "type": "regex", "value": "~(?:]|<\\\\/script|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|[\'\\"]\\\\s*;?\\\\s*(?:alert|eval|prompt|confirm|document\\\\.[a-zA-Z]+)\\\\s*\\\\()~i"}], "cve": "CVE-2026-75528", "description": "Broken Link Checker <=2.4.13 reflected XSS via filter_id parameter on the Links admin page (blc_local), a secondary defect hardened in the same 2.4.13.1 patch that also fixed the primary stored XSS via comment author URL / link log", "mode": "block", "slug": "broken-link-checker", "target": "plugin", "versions": "<=2.4.13"}, "RULE-CVE-2026-75586-01": {"action": "wp", "conditions": [{"name": "ARGS:ucfrontajaxaction", "type": "equals", "value": "submitform"}, {"name": "ARGS:formData[/.*/]", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|=3.8.1 <4.0.1"}, "RULE-CVE-2026-76549-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "updraftplus"}, {"name": "ARGS:action", "type": "equals", "value": "updraft_restore"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-76549", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76549", "description": "UpdraftPlus <1.26.7 CSRF on direct backup-restore dispatch via admin.php?page=updraftplus&action=updraft_restore", "mode": "block", "severity": 5.9, "slug": "updraftplus", "tags": ["csrf", "missing-authorization", "backup-restore"], "target": "plugin", "versions": "<1.26.7"}, "RULE-CVE-2026-76549-02": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "updraftplus"}, {"name": "ARGS:action", "type": "equals", "value": "updraft_restore_continue"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-76549", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76549", "description": "UpdraftPlus <1.26.7 CSRF on direct backup-restore-continue dispatch via admin.php?page=updraftplus&action=updraft_restore_continue", "mode": "block", "severity": 5.9, "slug": "updraftplus", "tags": ["csrf", "missing-authorization", "backup-restore"], "target": "plugin", "versions": "<1.26.7"}, "RULE-CVE-2026-76550-01": {"ajax_action": "wpie_export_create_data", "conditions": [{"name": "ARGS:/fileName|fileDir|extra_copy_path/", "type": "regex", "value": "~(?:\\\\.\\\\.|\\\\x00|:)~"}], "cve": "CVE-2026-76550", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76550", "description": "WP Import Export Lite <=3.9.33 authenticated (export-capability holder) arbitrary file write via unvalidated fileName/fileDir/extra_copy_path in wpie_export_create_data", "mode": "block", "severity": 7.2, "slug": "wp-import-export-lite", "tags": ["path-traversal", "arbitrary-file-write", "authenticated"], "target": "plugin", "versions": "<=3.9.33"}, "RULE-CVE-2026-76550-02": {"ajax_action": "wpie_export_prepare_file", "conditions": [{"name": "ARGS:/fileName|fileDir|extra_copy_path/", "type": "regex", "value": "~(?:\\\\.\\\\.|\\\\x00|:)~"}], "cve": "CVE-2026-76550", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76550", "description": "WP Import Export Lite <=3.9.33 authenticated (export-capability holder) arbitrary file write via unvalidated fileName/fileDir/extra_copy_path in wpie_export_prepare_file", "mode": "block", "severity": 7.2, "slug": "wp-import-export-lite", "tags": ["path-traversal", "arbitrary-file-write", "authenticated"], "target": "plugin", "versions": "<=3.9.33"}, "RULE-CVE-2026-76551-01": {"ajax_action": "wpie_export_create_data", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\b(?:eval|assert|system|exec|shell_exec|passthru|popen|proc_open|pcntl_exec|create_function|call_user_func(?:_array)?)\\\\b~i"}], "cve": "CVE-2026-76551", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76551", "description": "WP Import Export Lite <=3.9.32 authenticated PHP code execution via unrestricted export field-value function selection in wpie_export_create_data", "mode": "block", "severity": 7.2, "slug": "wp-import-export-lite", "tags": ["code-injection", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=3.9.32"}, "RULE-CVE-2026-76551-02": {"ajax_action": "wpie_export_update_data", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\b(?:eval|assert|system|exec|shell_exec|passthru|popen|proc_open|pcntl_exec|create_function|call_user_func(?:_array)?)\\\\b~i"}], "cve": "CVE-2026-76551", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76551", "description": "WP Import Export Lite <=3.9.32 authenticated PHP code execution via unrestricted export field-value function selection in wpie_export_update_data", "mode": "block", "severity": 7.2, "slug": "wp-import-export-lite", "tags": ["code-injection", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=3.9.32"}, "RULE-CVE-2026-76551-03": {"ajax_action": "wpie_export_save_template", "conditions": [{"name": "ARGS", "type": "regex", "value": "~\\\\b(?:eval|assert|system|exec|shell_exec|passthru|popen|proc_open|pcntl_exec|create_function|call_user_func(?:_array)?)\\\\b~i"}], "cve": "CVE-2026-76551", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76551", "description": "WP Import Export Lite <=3.9.32 authenticated PHP code execution via unrestricted export field-value function selection in wpie_export_save_template", "mode": "block", "severity": 7.2, "slug": "wp-import-export-lite", "tags": ["code-injection", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=3.9.32"}, "RULE-CVE-2026-76554-01": {"ajax_action": "wpie_import_data", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-76554", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-76554", "description": "WP Import Export Lite <=3.9.34 improper privilege management allows delegated import users to create or modify administrator accounts via wpie_import_data AJAX action", "mode": "block", "severity": 7.2, "slug": "wp-import-export-lite", "tags": ["missing-authorization", "privilege-escalation", "broken-access-control"], "target": "plugin", "versions": "<=3.9.34"}, "RULE-CVE-2026-76585-01": {"ajax_action": "cr_submit_review", "conditions": [{"name": "ARGS:review", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur|mouseenter|mouseleave|change|submit)\\\\s*=|javascript\\\\s*:|]|]|]*onerror)~i"}], "cve": "CVE-2026-76585", "description": "Customer Reviews for WooCommerce <5.118.0 unauthenticated stored XSS via review parameter in cr_submit_review AJAX action", "mode": "block", "slug": "customer-reviews-woocommerce", "target": "plugin", "versions": "<5.118.0"}, "RULE-CVE-2026-7660-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "easy-updates-manager"}, {"name": "ARGS:paged", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|?(?:img|svg|iframe|object|embed|details|body|input|select|textarea|form|marquee|a)\\\\b[^>]*\\\\bon\\\\w+\\\\s*=)~i"}], "cve": "CVE-2026-7660", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-7660", "description": "Easy Updates Manager <=9.0.20 reflected XSS via paged parameter in pagination()", "method": "GET", "mode": "block", "severity": 6.1, "slug": "stops-core-theme-and-plugin-updates", "tags": ["xss", "reflected", "authenticated"], "target": "plugin", "versions": "<=9.0.20"}, "RULE-CVE-2026-77233-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-comments-post\\\\.php~i"}, {"name": "ARGS:comment", "type": "regex", "value": "~(?=.*google_ad_(?:client|slot|width|height)\\\\s*=)(?=.*pagead2\\\\.googlesyndication\\\\.com/pagead/show_ads\\\\.js)~is"}], "cve": "CVE-2026-77233", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-77233", "description": "iubenda Cookie Law Solution <=3.13.4 unauthenticated stored XSS via WordPress comment content triggering legacy AdSense regex rewrite in the Secondary parser engine", "mode": "block", "severity": 7.2, "slug": "iubenda-cookie-law-solution", "tags": ["xss", "stored", "unauthenticated", "comment-content"], "target": "plugin", "versions": "<=3.13.4"}, "RULE-CVE-2026-77752-01": {"ajax_action": "wtlwp_enable_one_click_login", "conditions": [{"name": "ARGS:user_id", "type": "exists"}, {"type": "missing_capability", "value": "manage_network"}], "cve": "CVE-2026-77752", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-77752", "description": "Temporary Login Without Password <1.9.9 network super-admin privilege escalation via wtlwp_enable_one_click_login AJAX handler\'s unguarded update_user() call", "mode": "block", "severity": 7.2, "slug": "temporary-login-without-password", "tags": ["privilege-escalation", "missing-authorization", "multisite"], "target": "plugin", "versions": "<1.9.9"}, "RULE-CVE-2026-77770-01": {"ajax_action": "mo_two_factor_ajax", "conditions": [{"name": "ARGS:option", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-77770", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-77770", "description": "miniOrange 2FA <6.3.1 unauthenticated arbitrary site-option deletion via mo_two_factor_ajax AJAX action missing authorization", "mode": "block", "severity": 10.0, "slug": "miniorange-2-factor-authentication", "tags": ["missing-authorization", "unauthenticated", "option-deletion"], "target": "plugin", "versions": "<6.3.1"}, "RULE-CVE-2026-77770-02": {"ajax_action": "mo_two_factor_ajax", "conditions": [{"name": "ARGS:option", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2026-77770", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-77770", "description": "miniOrange 2FA >=18.0 <19.3 unauthenticated arbitrary site-option deletion via mo_two_factor_ajax AJAX action missing authorization", "mode": "block", "severity": 10.0, "slug": "miniorange-2-factor-authentication", "tags": ["missing-authorization", "unauthenticated", "option-deletion"], "target": "plugin", "versions": ">=18.0 <19.3"}, "RULE-CVE-2026-77782-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/getHead(?:[/?]|$)~i"}, {"name": "ARGS:url", "type": "exists"}], "cve": "CVE-2026-77782", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-77782", "description": "Rank Math SEO <1.0.277.1 discloses password-protected post content via publicly generated SEO metadata reachable through the headless getHead REST endpoint; endpoint-scoping only, no exploit-specific payload signal is groundable from current evidence", "mode": "block", "severity": 5.3, "slug": "seo-by-rank-math", "tags": ["information-disclosure", "unauthenticated", "needs-human-review"], "target": "plugin", "versions": "<1.0.277.1"}, "RULE-CVE-2026-77830-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-comments-post\\\\.php~"}, {"name": "ARGS", "type": "regex", "value": "~[\\"\'][^\\"\'<>]{0,40}(?:on\\\\w+\\\\s*=|]|javascript\\\\s*:)~i"}], "cve": "CVE-2026-77830", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-77830", "description": "CleanTalk Spam Protection, Antispam, FireWall by CleanTalk <=6.86 stored XSS via comment-content attribute breakout of ContactsEncoder aria-label placeholder", "mode": "block", "severity": 7.2, "slug": "cleantalk-spam-protect", "tags": ["xss", "stored", "unauthenticated", "comment-content"], "target": "plugin", "versions": "<=6.86"}, "RULE-CVE-2026-7795-01": {"action": "save_post", "conditions": [{"name": "ARGS:post_content", "type": "regex", "value": "~\\\\[chat\\\\s[^\\\\]]*num\\\\s*=\\\\s*[\'\\"][^\'\\"]*[);][^\'\\"]*[\'\\"]~i"}], "cve": "CVE-2026-7795", "description": "Block stored XSS via [chat] shortcode num parameter injection through classic editor post.php", "mode": "block", "severity": 6.4, "slug": "click-to-chat-for-whatsapp", "target": "plugin", "versions": "<4.40"}, "RULE-CVE-2026-7795-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp/v2/posts~"}, {"name": "ARGS:content", "type": "regex", "value": "~\\\\[chat\\\\s[^\\\\]]*num\\\\s*=\\\\s*[\'\\"][^\'\\"]*[);][^\'\\"]*[\'\\"]~i"}], "cve": "CVE-2026-7795", "description": "Block stored XSS via [chat] shortcode num parameter injection through REST API post creation/update", "mode": "block", "severity": 6.4, "slug": "click-to-chat-for-whatsapp", "target": "plugin", "versions": "<4.40"}, "RULE-CVE-2026-78003-01": {"ajax_action": "add_list", "conditions": [{"name": "ARGS_NAMES", "type": "regex", "value": "~addresses\\\\[[^\\\\]]*(?:/|%2f|%2e%2e|\\\\.\\\\.)[^\\\\]]*\\\\]~i"}], "cve": "CVE-2026-78003", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-78003", "description": "Mailgun for WordPress <=2.2.0 unauthenticated SSRF via path traversal in addresses[] array key in add_list AJAX handler", "mode": "block", "severity": 9.8, "slug": "mailgun", "tags": ["ssrf", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=2.2.0"}, "RULE-CVE-2026-78006-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-comments-post\\\\.php~"}, {"name": "ARGS:comment", "type": "regex", "value": "~ Buscar Academia de Idiomas ABC Toggle navigation Inicio Cursos Cursos 2×1 2×1 Niños 2×1 Adultos y Adolescentes Cursos de Inglés Inglés de Niños Inglés de Adultos y Adolescentes Cursos de Francés Francés de Niños Francés de Adultos y Adolescentes Prueba tus conocimientos Blog ABC Acerca de Nosotros Contáctanos Inicio Cursos Cursos 2×1 2×1 Niños 2×1 Adultos y Adolescentes Cursos de Inglés Inglés de Niños Inglés de Adultos y Adolescentes Cursos de Francés Francés de Niños Francés de Adultos y Adolescentes Prueba tus conocimientos Blog ABC Acerca de Nosotros Contáctanos 404 La página que estás buscando no existe. REGRESAR A LA PÁGINA PRINCIPAL