Sploitus Multiple CVEs Disclosed for WordPress Plugins with Active Exploitation Risks
Article Content
- •CVE-2026-77770 allows unauthenticated option deletion in miniOrange 2FA plugin.
- •CVE-2026-15667 enables authenticated local file inclusion in Eventin plugin.
- •Both vulnerabilities pose significant risks to WordPress sites and require immediate attention.
Two critical vulnerabilities affecting WordPress plugins have been disclosed. CVE-2026-77770 affects the miniOrange 2FA plugin, allowing unauthenticated arbitrary option deletion, while CVE-2026-15667 impacts the Eventin plugin, enabling authenticated local file inclusion. Both vulnerabilities pose significant risks to WordPress sites running the affected plugin versions. The miniOrange 2FA vulnerability was published on September 10, 2026, and the Eventin vulnerability on September 9, 2026, with a proof-of-concept (PoC) for the latter released on September 12, 2026. Security professionals are advised to assess their systems and apply necessary mitigations. The exploit for miniOrange requires Python for execution, while Eventin's exploit also necessitates authentication. Both vulnerabilities are critical for WordPress administrators to address immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-15667 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…