Daily briefing · July 13, 2026
WordPress Plugin Wave: Ten Critical CVEs Published, No Active Exploitation Detected
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 13, 2026 brought a calm but notable disclosure day, with 336 new CVEs published — 42 of them rated critical — yet none confirmed in active exploitation or flagged as weaponized. The day's standout theme is a concentrated wave of critical-severity vulnerabilities in WordPress plugins and themes, ranging from remote code injection to deserialization flaws, demanding patch prioritization even in the absence of known exploits in the wild.
Today’s brief
- 10 critical WordPress plugin/theme CVEs published in a single day, including two CVSS 10.0 remote code injection flaws
- No active exploitation (KEV), no weaponized exploits, no VulnCheck early signals — day classified as CALM
- SAP NetWeaver ABAP memory corruption flaw (CVE-2026-44747) is the only enterprise-grade critical outside the WordPress ecosystem
- Brazil faces heavy ransomware pressure: LockBit5 and Deadlock claimed multiple victims across public sector, manufacturing, and business services
Critical highlights
1
A CVSS 10.0 code injection flaw in the Realtyna Organic IDX plugin (≤5.2.0) allows unauthenticated remote code inclusion, giving an attacker full server-side code execution. Any WordPress site running this plugin should treat patching as immediately urgent.
2
Unrestricted file upload in Aimogen Pro (≤2.8.3) permits attackers to upload and execute malicious files on the server, rated CVSS 10.0. This class of vulnerability is historically trivial to exploit once a PoC exists, making immediate remediation critical.
3
A path traversal vulnerability in SureDash (≤1.8.0) by Brainstorm Force carries a CVSS 9.9 and could allow attackers to read or write files outside the intended directory, potentially leading to configuration exposure or code execution.
4
WoowBot Pro Max (≤14.1.7) suffers from unrestricted dangerous file upload (CVSS 9.9), enabling upload of malicious files that can be leveraged for remote code execution on the hosting environment.
5
SAP NetWeaver Application Server ABAP contains a memory corruption flaw exploitable by authenticated attackers, with high impact on confidentiality, integrity, and availability. In SAP environments, even authenticated-only paths are serious given credential exposure risks and the sensitivity of business data hosted on ABAP systems.
6
Deserialization of untrusted data in Directorist (≤8.8.2) enables PHP object injection, which can chain into remote code execution depending on available gadget chains in the environment. WordPress directory-listing sites using this plugin are at elevated risk.
7
The Grand Photography theme (≤5.7.8) by ThemeGoods is vulnerable to object injection via unsafe deserialization (CVSS 9.8), a class of flaw that can escalate to full compromise when exploitable gadget chains are present in the loaded codebase.
8
RT-Theme 18 Extensions (≤2.5) carries a deserialization/object injection vulnerability rated CVSS 9.8; sites relying on this theme extension should update immediately, as object injection is a well-understood exploitation primitive in the PHP ecosystem.
9
The 777 theme by axiomthemes (≤1.13.0) is affected by an untrusted deserialization flaw allowing object injection (CVSS 9.8). Theme-level vulnerabilities often go unpatched longer than plugin flaws, increasing the window of exposure.
10
Kirki by Themeum (≤6.0.12) — a widely used WordPress customizer framework — is vulnerable to object injection via deserialization (CVSS 9.8). Its broad install base across many themes makes this a particularly high-impact disclosure worth prioritizing.
Ransomware today
LockBit5 and Deadlock emerged as the most active groups in the recent disclosure window, with LockBit5 claiming victims including santoinacio-rio.com.br, lbreng.com.br, and saude.mt.gov.br (the Mato Grosso state health secretariat), while Deadlock targeted Werken Química Brasil S.A., Bombas Ideal, and Direção Estacionamentos S.A. Over the past 30 days, lockbit3 leads with 39 tracked victims, followed by ransomhub (35), lockbit5 (29), thegentlemen (20), 8base (20), and arcusmedia (19), painting a picture of sustained, high-volume ransomware pressure.
santoinacio-rio.com.br BRlockbit5 · Business Services
lbreng.com.br BRlockbit5 · Business Services
saude.mt.gov.br BRlockbit5 · Public Sector
Werken Química Brasil S.A. BRDeadlock · Manufacturing
Bombas Ideal BRDeadlock · Manufacturing
Direção Estacionamentos S.A. BRDeadlock · Consumer Services
lockbit3 39ransomhub 35lockbit5 29thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups have been flagged as active or updated in intelligence feeds, including Iran-linked blackshadow and CopyKittens, as well as apt73, coinbasecartel, dragonforce, and againstthewest. While no confirmed victims are currently attributed to these groups in this cycle, their presence in active tracking indicates ongoing reconnaissance or campaign preparation that defenders should monitor.
Brazil focus
Brazil continues to face one of the most intense ransomware environments globally, with multiple organizations hit recently across critical sectors: the public sector (saude.mt.gov.br by LockBit5), manufacturing (Werken Química Brasil S.A. and Bombas Ideal by Deadlock), business services (santoinacio-rio.com.br and lbreng.com.br by LockBit5), consumer services (Direção Estacionamentos S.A. by Deadlock), and technology (tecnocurva.com.br by incransom). The diversity of targeted sectors and active groups — including qilin claiming S.J. Louis — underscores that no vertical is exempt from risk in the Brazilian threat landscape.
santoinacio-rio.com.brlockbit5 · Business Services
saude.mt.gov.brlockbit5 · Public Sector
lbreng.com.brlockbit5 · Business Services
Direção Estacionamentos S.A.Deadlock · Consumer Services
Bombas IdealDeadlock · Manufacturing
Werken Química Brasil S.A.Deadlock · Manufacturing
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Today’s recommendation: WordPress administrators should audit installed plugins and themes against today's CVE list and apply available updates immediately, prioritizing the two CVSS 10.0 flaws (CVE-2026-57811 and CVE-2026-57719) and the SAP NetWeaver patch (CVE-2026-44747) for enterprise environments. Organizations without a patching SLA should treat any CVSS 9.8+ disclosure as requiring remediation within 24–72 hours, regardless of confirmed exploitation status.
Even on a calm disclosure day, the breadth of critical findings across popular WordPress components is a reminder that understanding your actual attack surface — not just your known assets — is what separates proactive defense from reactive firefighting.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →