Skip to content
Multiple CVEs Disclosed for WordPress Plugins with Active Exploitation Risks

Multiple CVEs Disclosed for WordPress Plugins with Active Exploitation Risks

First seen 13 Sep 2026, 05:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 05:56 UTC

Two critical vulnerabilities affecting WordPress plugins have been disclosed. CVE-2026-77770 affects the miniOrange 2FA plugin, allowing unauthenticated arbitrary option deletion, while CVE-2026-15667 impacts the Eventin plugin, enabling authenticated local file inclusion. Both vulnerabilities pose significant risks to WordPress sites running the affected plugin versions. The miniOrange 2FA vulnerability was published on September 10, 2026, and the Eventin vulnerability on September 9, 2026, with a proof-of-concept (PoC) for the latter released on September 12, 2026. Security professionals are advised to assess their systems and apply necessary mitigations. The exploit for miniOrange requires Python for execution, while Eventin's exploit also necessitates authentication. Both vulnerabilities are critical for WordPress administrators to address immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-09
CVE-2026-15667 published
Eventin plugin vulnerability disclosed, allowing authenticated local file inclusion.
Sploitus
2026-09-10
CVE-2026-77770 published
miniOrange 2FA plugin vulnerability disclosed, enabling unauthenticated option deletion.
Sploitus
2026-09-12
First public PoC for CVE-2026-15667
Proof-of-concept code for the Eventin plugin vulnerability made publicly available.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-15667 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed