Lyrie.Ai Multiple Critical Vulnerabilities Disclosed Affecting Various Products
Article Content
- •Six critical vulnerabilities disclosed, all with CVSS scores of 9.8 or higher.
- •CVE-2026-25775 allows unauthorized firmware updates on SenseLive X3050 devices.
- •CVE-2026-8935 enables the creation of admin accounts in WP MAPS PRO without authentication.
A series of critical vulnerabilities (CVEs) have been disclosed affecting multiple products, all with a CVSS score of 9.8. CVE-2026-25775 allows unauthorized firmware operations on SenseLive X3050. CVE-2026-8935 enables unauthenticated admin account creation in WP MAPS PRO. CVE-2026-50890 features a SQL injection flaw in grocy v4.6.0, exposing sensitive data. CVE-2026-49105 involves unauthenticated PHP Object Injection in several WordPress plugins. CVE-2026-50886 presents incorrect access control in Project Firefly III. These vulnerabilities could lead to severe breaches if exploited. All vulnerabilities were validated by three independent sources before publication.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track CVE-2026-25775 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Over 100,000 WordPress Sites Vulnerable to Remote Code Execution A critical vulnerability affecting the Tutor LMS plugin allows for remote code execution on over 100,000 WordPress sites. The vulnerability stems from insecure handling of user input in the plugin's withdraw account management feature, which can be exploited via PHP Object Injection. Wordfence discovered and reported…