Ciberseguridadlatam Critical WordPress Plugin Vulnerabilities Expose Sites to Severe Attacks
Article Content
- •CVE-2026-82845 allows code execution for basic users in Masteriyo LMS.
- •CVE-2026-14563 enables admin account takeover without passwords.
- •CVE-2026-77006 permits file deletion by any authenticated user.
Three critical vulnerabilities have been identified in popular WordPress plugins, affecting educational and backup systems. CVE-2026-82845 in Masteriyo LMS allows users with basic accounts to execute arbitrary code, while CVE-2026-14563 in 'advanced-customized-prompts' enables attackers to take control of admin accounts without passwords. Additionally, CVE-2026-77006 in WebTotem Backups permits authenticated users to delete arbitrary files on the server. All vulnerabilities have been classified as critical by the National Vulnerability Database. The issues stem from poor authentication and validation practices, making exploitation straightforward for attackers. Users of affected plugins are urged to update immediately to mitigate risks. The vulnerabilities were disclosed between September 11 and September 12, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-14563 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…