Skip to content
New Vulnerabilities Discovered in Kubernetes and WordPress

New Vulnerabilities Discovered in Kubernetes and WordPress

First seen 23 Sep 2026, 09:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 09:58 UTC

Two significant vulnerabilities have been reported: CVE-2024-10220 and CVE-2017-20192. CVE-2024-10220 affects gitRepo volumes in Kubernetes, allowing arbitrary command execution on Kubernetes nodes. This vulnerability was published on November 22, 2024, with a proof-of-concept (PoC) available since November 21, 2024. The testing repository is part of security research at the University of Central Oklahoma, but it contains a malicious Git hook and should not be used in production. CVE-2017-20192, related to Formidable Forms in WordPress, allows stored XSS attacks and was published on October 16, 2024. A PoC for this vulnerability is expected to be publicly available by December 24, 2025. Both vulnerabilities pose risks to their respective platforms, with CVE-2024-10220 being particularly critical due to its potential for remote command execution.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2024-10-16
CVE-2017-20192 published
The vulnerability affecting Formidable Forms in WordPress was officially published, allowing stored XSS.
Sploitus
2024-11-21
First public PoC for CVE-2024-10220
A proof-of-concept for the Kubernetes vulnerability was released, demonstrating its exploitability.
Sploitus
2024-11-22
CVE-2024-10220 published
The vulnerability affecting gitRepo volumes in Kubernetes was officially published, highlighting its severity.
Sploitus
2025-12-24
First public PoC for CVE-2017-20192 expected
A proof-of-concept for the WordPress vulnerability is anticipated to be released, increasing the risk of exploitation.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2017-20192 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed