Daily briefing · July 13, 2026
WordPress Plugin Wave: Ten Critical CVEs Published, No Active Exploitation Detected
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 13, 2026 brought a calm but notable disclosure day, with 336 new CVEs published — 42 of them rated critical — yet none confirmed in active exploitation or flagged as weaponized. The day's standout theme is a concentrated wave of critical-severity vulnerabilities in WordPress plugins and themes, ranging from remote code injection to deserialization flaws, demanding patch prioritization even in the absence of known exploits in the wild.
Today’s brief
- 10 critical WordPress plugin/theme CVEs published in a single day, including two CVSS 10.0 remote code injection flaws
- No active exploitation (KEV), no weaponized exploits, no VulnCheck early signals — day classified as CALM
- SAP NetWeaver ABAP memory corruption flaw (CVE-2026-44747) is the only enterprise-grade critical outside the WordPress ecosystem
- Brazil faces heavy ransomware pressure: LockBit5 and Deadlock claimed multiple victims across public sector, manufacturing, and business services
Critical highlights
1
A CVSS 10.0 code injection flaw in the Realtyna Organic IDX plugin (≤5.2.0) allows unauthenticated remote code inclusion, giving an attacker full server-side code execution. Any WordPress site running this plugin should treat patching as immediately urgent.
2
Unrestricted file upload in Aimogen Pro (≤2.8.3) permits attackers to upload and execute malicious files on the server, rated CVSS 10.0. This class of vulnerability is historically trivial to exploit once a PoC exists, making immediate remediation critical.
3
A path traversal vulnerability in SureDash (≤1.8.0) by Brainstorm Force carries a CVSS 9.9 and could allow attackers to read or write files outside the intended directory, potentially leading to configuration exposure or code execution.
4
WoowBot Pro Max (≤14.1.7) suffers from unrestricted dangerous file upload (CVSS 9.9), enabling upload of malicious files that can be leveraged for remote code execution on the hosting environment.
5
SAP NetWeaver Application Server ABAP contains a memory corruption flaw exploitable by authenticated attackers, with high impact on confidentiality, integrity, and availability. In SAP environments, even authenticated-only paths are serious given credential exposure risks and the sensitivity of business data hosted on ABAP systems.
6
Deserialization of untrusted data in Directorist (≤8.8.2) enables PHP object injection, which can chain into remote code execution depending on available gadget chains in the environment. WordPress directory-listing sites using this plugin are at elevated risk.
7
The Grand Photography theme (≤5.7.8) by ThemeGoods is vulnerable to object injection via unsafe deserialization (CVSS 9.8), a class of flaw that can escalate to full compromise when exploitable gadget chains are present in the loaded codebase.
8
RT-Theme 18 Extensions (≤2.5) carries a deserialization/object injection vulnerability rated CVSS 9.8; sites relying on this theme extension should update immediately, as object injection is a well-understood exploitation primitive in the PHP ecosystem.
9
The 777 theme by axiomthemes (≤1.13.0) is affected by an untrusted deserialization flaw allowing object injection (CVSS 9.8). Theme-level vulnerabilities often go unpatched longer than plugin flaws, increasing the window of exposure.
10
Kirki by Themeum (≤6.0.12) — a widely used WordPress customizer framework — is vulnerable to object injection via deserialization (CVSS 9.8). Its broad install base across many themes makes this a particularly high-impact disclosure worth prioritizing.
Ransomware today
LockBit5 and Deadlock emerged as the most active groups in the recent disclosure window, with LockBit5 claiming victims including santoinacio-rio.com.br, lbreng.com.br, and saude.mt.gov.br (the Mato Grosso state health secretariat), while Deadlock targeted Werken Química Brasil S.A., Bombas Ideal, and Direção Estacionamentos S.A. Over the past 30 days, lockbit3 leads with 39 tracked victims, followed by ransomhub (35), lockbit5 (29), thegentlemen (20), 8base (20), and arcusmedia (19), painting a picture of sustained, high-volume ransomware pressure.
santoinacio-rio.com.br BRlockbit5 · Business Services
lbreng.com.br BRlockbit5 · Business Services
saude.mt.gov.br BRlockbit5 · Public Sector
Werken Química Brasil S.A. BRDeadlock · Manufacturing
Bombas Ideal BRDeadlock · Manufacturing
Direção Estacionamentos S.A. BRDeadlock · Consumer Services
lockbit3 39ransomhub 35lockbit5 29thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups have been flagged as active or updated in intelligence feeds, including Iran-linked blackshadow and CopyKittens, as well as apt73, coinbasecartel, dragonforce, and againstthewest. While no confirmed victims are currently attributed to these groups in this cycle, their presence in active tracking indicates ongoing reconnaissance or campaign preparation that defenders should monitor.
Brazil focus
Brazil continues to face one of the most intense ransomware environments globally, with multiple organizations hit recently across critical sectors: the public sector (saude.mt.gov.br by LockBit5), manufacturing (Werken Química Brasil S.A. and Bombas Ideal by Deadlock), business services (santoinacio-rio.com.br and lbreng.com.br by LockBit5), consumer services (Direção Estacionamentos S.A. by Deadlock), and technology (tecnocurva.com.br by incransom). The diversity of targeted sectors and active groups — including qilin claiming S.J. Louis — underscores that no vertical is exempt from risk in the Brazilian threat landscape.
santoinacio-rio.com.brlockbit5 · Business Services
saude.mt.gov.brlockbit5 · Public Sector
lbreng.com.brlockbit5 · Business Services
Direção Estacionamentos S.A.Deadlock · Consumer Services
Bombas IdealDeadlock · Manufacturing
Werken Química Brasil S.A.Deadlock · Manufacturing
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Today’s recommendation: WordPress administrators should audit installed plugins and themes against today's CVE list and apply available updates immediately, prioritizing the two CVSS 10.0 flaws (CVE-2026-57811 and CVE-2026-57719) and the SAP NetWeaver patch (CVE-2026-44747) for enterprise environments. Organizations without a patching SLA should treat any CVSS 9.8+ disclosure as requiring remediation within 24–72 hours, regardless of confirmed exploitation status.
Even on a calm disclosure day, the breadth of critical findings across popular WordPress components is a reminder that understanding your actual attack surface — not just your known assets — is what separates proactive defense from reactive firefighting.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →