Daily briefing · July 13, 2026

WordPress Plugin Wave: Ten Critical CVEs Published, No Active Exploitation Detected

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 13, 2026 brought a calm but notable disclosure day, with 336 new CVEs published — 42 of them rated critical — yet none confirmed in active exploitation or flagged as weaponized. The day's standout theme is a concentrated wave of critical-severity vulnerabilities in WordPress plugins and themes, ranging from remote code injection to deserialization flaws, demanding patch prioritization even in the absence of known exploits in the wild.

Today’s brief
  • 10 critical WordPress plugin/theme CVEs published in a single day, including two CVSS 10.0 remote code injection flaws
  • No active exploitation (KEV), no weaponized exploits, no VulnCheck early signals — day classified as CALM
  • SAP NetWeaver ABAP memory corruption flaw (CVE-2026-44747) is the only enterprise-grade critical outside the WordPress ecosystem
  • Brazil faces heavy ransomware pressure: LockBit5 and Deadlock claimed multiple victims across public sector, manufacturing, and business services
42
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-57811CVSS 10affects Realtyna Organic IDX plugin
A CVSS 10.0 code injection flaw in the Realtyna Organic IDX plugin (≤5.2.0) allows unauthenticated remote code inclusion, giving an attacker full server-side code execution. Any WordPress site running this plugin should treat patching as immediately urgent.
2
CVE-2026-57719CVSS 10affects Aimogen Pro
Unrestricted file upload in Aimogen Pro (≤2.8.3) permits attackers to upload and execute malicious files on the server, rated CVSS 10.0. This class of vulnerability is historically trivial to exploit once a PoC exists, making immediate remediation critical.
3
CVE-2026-57401CVSS 9.9affects SureDash
A path traversal vulnerability in SureDash (≤1.8.0) by Brainstorm Force carries a CVSS 9.9 and could allow attackers to read or write files outside the intended directory, potentially leading to configuration exposure or code execution.
4
CVE-2026-57710CVSS 9.9affects WoowBot Pro Max
WoowBot Pro Max (≤14.1.7) suffers from unrestricted dangerous file upload (CVSS 9.9), enabling upload of malicious files that can be leveraged for remote code execution on the hosting environment.
5
CVE-2026-44747CVSS 9.9affects SAP NetWeaver Application Server ABAP
SAP NetWeaver Application Server ABAP contains a memory corruption flaw exploitable by authenticated attackers, with high impact on confidentiality, integrity, and availability. In SAP environments, even authenticated-only paths are serious given credential exposure risks and the sensitivity of business data hosted on ABAP systems.
6
CVE-2026-59518CVSS 9.8affects Directorist
Deserialization of untrusted data in Directorist (≤8.8.2) enables PHP object injection, which can chain into remote code execution depending on available gadget chains in the environment. WordPress directory-listing sites using this plugin are at elevated risk.
7
CVE-2026-57770CVSS 9.8affects Grand Photography
The Grand Photography theme (≤5.7.8) by ThemeGoods is vulnerable to object injection via unsafe deserialization (CVSS 9.8), a class of flaw that can escalate to full compromise when exploitable gadget chains are present in the loaded codebase.
8
CVE-2026-57744CVSS 9.8affects RT-Theme 18 | Extensions
RT-Theme 18 Extensions (≤2.5) carries a deserialization/object injection vulnerability rated CVSS 9.8; sites relying on this theme extension should update immediately, as object injection is a well-understood exploitation primitive in the PHP ecosystem.
9
CVE-2026-57738CVSS 9.8affects 777
The 777 theme by axiomthemes (≤1.13.0) is affected by an untrusted deserialization flaw allowing object injection (CVSS 9.8). Theme-level vulnerabilities often go unpatched longer than plugin flaws, increasing the window of exposure.
10
CVE-2026-57724CVSS 9.8affects Kirki
Kirki by Themeum (≤6.0.12) — a widely used WordPress customizer framework — is vulnerable to object injection via deserialization (CVSS 9.8). Its broad install base across many themes makes this a particularly high-impact disclosure worth prioritizing.
Ransomware today

LockBit5 and Deadlock emerged as the most active groups in the recent disclosure window, with LockBit5 claiming victims including santoinacio-rio.com.br, lbreng.com.br, and saude.mt.gov.br (the Mato Grosso state health secretariat), while Deadlock targeted Werken Química Brasil S.A., Bombas Ideal, and Direção Estacionamentos S.A. Over the past 30 days, lockbit3 leads with 39 tracked victims, followed by ransomhub (35), lockbit5 (29), thegentlemen (20), 8base (20), and arcusmedia (19), painting a picture of sustained, high-volume ransomware pressure.

santoinacio-rio.com.br BRlockbit5 · Business Services
lbreng.com.br BRlockbit5 · Business Services
saude.mt.gov.br BRlockbit5 · Public Sector
Werken Química Brasil S.A. BRDeadlock · Manufacturing
Bombas Ideal BRDeadlock · Manufacturing
Direção Estacionamentos S.A. BRDeadlock · Consumer Services
lockbit3 39ransomhub 35lockbit5 29thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actor groups have been flagged as active or updated in intelligence feeds, including Iran-linked blackshadow and CopyKittens, as well as apt73, coinbasecartel, dragonforce, and againstthewest. While no confirmed victims are currently attributed to these groups in this cycle, their presence in active tracking indicates ongoing reconnaissance or campaign preparation that defenders should monitor.

Brazil focus

Brazil continues to face one of the most intense ransomware environments globally, with multiple organizations hit recently across critical sectors: the public sector (saude.mt.gov.br by LockBit5), manufacturing (Werken Química Brasil S.A. and Bombas Ideal by Deadlock), business services (santoinacio-rio.com.br and lbreng.com.br by LockBit5), consumer services (Direção Estacionamentos S.A. by Deadlock), and technology (tecnocurva.com.br by incransom). The diversity of targeted sectors and active groups — including qilin claiming S.J. Louis — underscores that no vertical is exempt from risk in the Brazilian threat landscape.

santoinacio-rio.com.brlockbit5 · Business Services
saude.mt.gov.brlockbit5 · Public Sector
lbreng.com.brlockbit5 · Business Services
Direção Estacionamentos S.A.Deadlock · Consumer Services
Bombas IdealDeadlock · Manufacturing
Werken Química Brasil S.A.Deadlock · Manufacturing
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Today’s recommendation: WordPress administrators should audit installed plugins and themes against today's CVE list and apply available updates immediately, prioritizing the two CVSS 10.0 flaws (CVE-2026-57811 and CVE-2026-57719) and the SAP NetWeaver patch (CVE-2026-44747) for enterprise environments. Organizations without a patching SLA should treat any CVSS 9.8+ disclosure as requiring remediation within 24–72 hours, regardless of confirmed exploitation status.
Even on a calm disclosure day, the breadth of critical findings across popular WordPress components is a reminder that understanding your actual attack surface — not just your known assets — is what separates proactive defense from reactive firefighting.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →