Daily briefing · August 13, 2026
Supply Chain Backdoors and Active Exploitation Target WordPress Ecosystem and Brazilian Organizations
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention6 seen before CISA
August 13, 2026 demands heightened attention: six vulnerabilities are already under active exploitation, six were detected by VulnCheck before any CISA confirmation, and the day's most alarming entries involve tampered plugin builds creating persistent backdoors across WordPress sites worldwide. With 605 new CVEs published — 67 critical — and a string of Brazilian organizations hit by ransomware, defenders face a broad and immediate threat surface.
Today’s brief
- Fluent Forms Pro and Ninja Tables Pro shipped trojaned builds via a compromised update server, planting persistent backdoors with unauthenticated REST API access — patch and audit immediately.
- Six CVEs already actively exploited per VulnCheck intelligence, all published today, before CISA could officially confirm them.
- Four additional CVEs carry a perfect CVSS 10.0 score, including unauthenticated RCE in WP BASE Booking and QA Analytics.
- Brazil faces a multi-front ransomware wave: Chat Jurídico, Intranet Gov Brasil, universities, and tech firms among recent victims across eight distinct threat groups.
Critical highlights
1
Fluent Forms Pro 6.2.7 was backdoored via a tampered update delivered through a decommissioned server, installing a rogue PHP file that opens a persistent REST API backdoor and plants files in mu-plugins — meaning the malicious code survives plugin removal. Any site that auto-updated to this build should be treated as fully compromised.
2
Ninja Tables Pro 5.2.11 suffered the same supply chain attack vector as CVE-2026-73532: a trojanized build dropped a data sync PHP file that establishes a backdoor endpoint, installs a passwordless admin account, and persists in mu-plugins and uploads directories. Sites running this version must assume unauthorized admin-level access is already in place.
3
ASP-CMS exposes an unauthenticated SQL injection in the commentList.asp endpoint, where attackers bypass keyword blocklists by interleaving SQL terms — a classic evasion technique that makes WAF rules unreliable. VulnCheck observed exploitation before CISA, and a proof of concept is available, elevating the urgency for any organization still running this legacy CMS.
4
Hongjing e-HR's getSdutyTree servlet can be reached unauthenticated via a path traversal bypass of the oauthservlet filter, after which UNION-based SQL injection allows full database extraction. VulnCheck flagged active exploitation ahead of CISA confirmation, making this a high-priority patch for HR system operators.
5
REST API Log plugin versions up to 1.7.1 expose sensitive data to unauthenticated users, potentially leaking API keys, authentication tokens, and internal request metadata logged by the plugin. VulnCheck observed exploitation before CISA, and any WordPress deployment using this plugin for API monitoring should disable or update it immediately.
6
MultiVendorX up to version 5.0.10 contains a broken access control flaw reachable without authentication, which could allow attackers to perform privileged marketplace actions — including vendor and order manipulation — on affected WooCommerce-based storefronts. Already flagged by VulnCheck as actively exploited.
7
CVE-2026-59500CVSS 10affects Portal Generator addon to Priority ERP (developed by Soft Solutions) The Portal Generator addon for Priority ERP (by Soft Solutions) scores a perfect CVSS 10.0 due to improper authentication, meaning attackers may completely bypass access controls on ERP-connected portal interfaces. Though EPSS is currently 0%, the severity and ERP exposure profile make this a critical patch priority for enterprise environments.
8
The 'Link Factory' WordPress plugin is classified as a backdoor: it exposes operator-controlled REST API endpoints authenticated by a hardcoded public key, effectively handing remote command capability to whoever controls the corresponding private key. Any site with this plugin installed should treat it as a confirmed compromise vector and remove it without delay.
9
WP BASE Booking plugin versions up to 6.3.0 allow unauthenticated arbitrary code execution, a CVSS 10.0 flaw that requires no credentials to trigger. Booking and reservation platforms running this plugin are exposed to complete server takeover and should prioritize patching or temporary disablement.
10
QA Analytics up to version 5.2.0.0 carries unauthenticated remote code execution at CVSS 10.0 — no authentication, no interaction required. Analytics plugins are often deprioritized in patch cycles, making this a likely target of opportunity for threat actors scanning for overlooked WordPress components.
Ransomware today
The direwolf group recently claimed Chat Jurídico, a Brazilian legal services firm, as its latest victim — a reminder that professional services handling sensitive client data remain prime ransomware targets. Among the most active groups over the past 30 days, lockbit5 leads with 21 victims (all in Brazil), followed by Section9 with 6 Brazilian victims, and Global Secret Group with 4, underscoring a sustained and concentrated campaign against Brazilian organizations across multiple sectors.
Chat Jurídico BRdirewolf · Professional Services
lockbit5 21Section9 6Global Secret Group 4thegentlemen 3L Group 2ransomhouse 2
Active groups & APTs
Several threat actors are currently being tracked with heightened attention, including Darkhotel (attributed to North Korea), Equation, karakurt, linkc, LeakBazaar, and apt73. While no new victims have been attributed to these groups in the current reporting window, their active monitoring status reflects intelligence indicators suggesting ongoing reconnaissance or infrastructure activity — defenders in targeted sectors should treat this as a warning posture, not an all-clear.
Brazil focus
Brazil is experiencing a broad ransomware wave across multiple sectors: recent victims include Intranet Gov Brasil (Government & Defense, claimed by thegentlemen), Alya Construtora (Manufacturing, ransomhouse), brdigital.net.br and eSysTech (Technology, by L Group and Orova respectively), uva.edu.br and cesmac.edu.br (Education, by L Group and krybit), and PontoBR Sistemas (Technology, by spacebears). The diversity of groups and sectors confirms that Brazilian organizations of all sizes and verticals are being systematically targeted.
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
brdigital.net.brL Group · Technology
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
Today’s recommendation: Immediately audit all WordPress installations for the presence of Fluent Forms Pro 6.2.7, Ninja Tables Pro 5.2.11, and the Link Factory plugin, treating any match as a potential compromise; scan mu-plugins and uploads directories for unexpected PHP files. Simultaneously, prioritize patching CVE-2026-61962 and CVE-2026-27544 in any environment running WP BASE Booking or QA Analytics, as unauthenticated RCE at CVSS 10.0 with no known mitigating factors demands immediate action.
With backdoored plugins, unauthenticated RCE, and six vulnerabilities already exploited before official confirmation, today's landscape makes clear that the most dangerous question is not whether threats exist — but whether your own attack surface has already been quietly compromised without your knowledge.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →