Daily briefing · August 13, 2026

Supply Chain Backdoors and Active Exploitation Target WordPress Ecosystem and Brazilian Organizations

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention6 seen before CISA

August 13, 2026 demands heightened attention: six vulnerabilities are already under active exploitation, six were detected by VulnCheck before any CISA confirmation, and the day's most alarming entries involve tampered plugin builds creating persistent backdoors across WordPress sites worldwide. With 605 new CVEs published — 67 critical — and a string of Brazilian organizations hit by ransomware, defenders face a broad and immediate threat surface.

Today’s brief
  • Fluent Forms Pro and Ninja Tables Pro shipped trojaned builds via a compromised update server, planting persistent backdoors with unauthenticated REST API access — patch and audit immediately.
  • Six CVEs already actively exploited per VulnCheck intelligence, all published today, before CISA could officially confirm them.
  • Four additional CVEs carry a perfect CVSS 10.0 score, including unauthenticated RCE in WP BASE Booking and QA Analytics.
  • Brazil faces a multi-front ransomware wave: Chat Jurídico, Intranet Gov Brasil, universities, and tech firms among recent victims across eight distinct threat groups.
67
critical
6
Actively exploited
6
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-73532◆ VulnCheckCVSS 9.3affects Fluent Forms Pro
Fluent Forms Pro 6.2.7 was backdoored via a tampered update delivered through a decommissioned server, installing a rogue PHP file that opens a persistent REST API backdoor and plants files in mu-plugins — meaning the malicious code survives plugin removal. Any site that auto-updated to this build should be treated as fully compromised.
2
CVE-2026-73533◆ VulnCheckCVSS 9.3affects Ninja Tables Pro
Ninja Tables Pro 5.2.11 suffered the same supply chain attack vector as CVE-2026-73532: a trojanized build dropped a data sync PHP file that establishes a backdoor endpoint, installs a passwordless admin account, and persists in mu-plugins and uploads directories. Sites running this version must assume unauthorized admin-level access is already in place.
3
CVE-2019-25765◆ VulnCheckHIGH 8.7PoCaffects ASP-CMS
ASP-CMS exposes an unauthenticated SQL injection in the commentList.asp endpoint, where attackers bypass keyword blocklists by interleaving SQL terms — a classic evasion technique that makes WAF rules unreliable. VulnCheck observed exploitation before CISA, and a proof of concept is available, elevating the urgency for any organization still running this legacy CMS.
4
CVE-2024-58374◆ VulnCheckHIGH 8.7PoCaffects e-HR
Hongjing e-HR's getSdutyTree servlet can be reached unauthenticated via a path traversal bypass of the oauthservlet filter, after which UNION-based SQL injection allows full database extraction. VulnCheck flagged active exploitation ahead of CISA confirmation, making this a high-priority patch for HR system operators.
5
CVE-2026-66443◆ VulnCheckHIGH 7.5affects REST API Log
REST API Log plugin versions up to 1.7.1 expose sensitive data to unauthenticated users, potentially leaking API keys, authentication tokens, and internal request metadata logged by the plugin. VulnCheck observed exploitation before CISA, and any WordPress deployment using this plugin for API monitoring should disable or update it immediately.
6
CVE-2026-66441◆ VulnCheckHIGH 7.5affects MultiVendorX
MultiVendorX up to version 5.0.10 contains a broken access control flaw reachable without authentication, which could allow attackers to perform privileged marketplace actions — including vendor and order manipulation — on affected WooCommerce-based storefronts. Already flagged by VulnCheck as actively exploited.
7
CVE-2026-59500CVSS 10affects Portal Generator addon to Priority ERP (developed by Soft Solutions)
The Portal Generator addon for Priority ERP (by Soft Solutions) scores a perfect CVSS 10.0 due to improper authentication, meaning attackers may completely bypass access controls on ERP-connected portal interfaces. Though EPSS is currently 0%, the severity and ERP exposure profile make this a critical patch priority for enterprise environments.
8
CVE-2026-15413CVSS 10PoCaffects Link Factory
The 'Link Factory' WordPress plugin is classified as a backdoor: it exposes operator-controlled REST API endpoints authenticated by a hardcoded public key, effectively handing remote command capability to whoever controls the corresponding private key. Any site with this plugin installed should treat it as a confirmed compromise vector and remove it without delay.
9
CVE-2026-61962CVSS 10affects WP BASE Booking
WP BASE Booking plugin versions up to 6.3.0 allow unauthenticated arbitrary code execution, a CVSS 10.0 flaw that requires no credentials to trigger. Booking and reservation platforms running this plugin are exposed to complete server takeover and should prioritize patching or temporary disablement.
10
CVE-2026-27544CVSS 10affects QA Analytics
QA Analytics up to version 5.2.0.0 carries unauthenticated remote code execution at CVSS 10.0 — no authentication, no interaction required. Analytics plugins are often deprioritized in patch cycles, making this a likely target of opportunity for threat actors scanning for overlooked WordPress components.
Ransomware today

The direwolf group recently claimed Chat Jurídico, a Brazilian legal services firm, as its latest victim — a reminder that professional services handling sensitive client data remain prime ransomware targets. Among the most active groups over the past 30 days, lockbit5 leads with 21 victims (all in Brazil), followed by Section9 with 6 Brazilian victims, and Global Secret Group with 4, underscoring a sustained and concentrated campaign against Brazilian organizations across multiple sectors.

Chat Jurídico BRdirewolf · Professional Services
lockbit5 21Section9 6Global Secret Group 4thegentlemen 3L Group 2ransomhouse 2
Active groups & APTs

Several threat actors are currently being tracked with heightened attention, including Darkhotel (attributed to North Korea), Equation, karakurt, linkc, LeakBazaar, and apt73. While no new victims have been attributed to these groups in the current reporting window, their active monitoring status reflects intelligence indicators suggesting ongoing reconnaissance or infrastructure activity — defenders in targeted sectors should treat this as a warning posture, not an all-clear.

Brazil focus

Brazil is experiencing a broad ransomware wave across multiple sectors: recent victims include Intranet Gov Brasil (Government & Defense, claimed by thegentlemen), Alya Construtora (Manufacturing, ransomhouse), brdigital.net.br and eSysTech (Technology, by L Group and Orova respectively), uva.edu.br and cesmac.edu.br (Education, by L Group and krybit), and PontoBR Sistemas (Technology, by spacebears). The diversity of groups and sectors confirms that Brazilian organizations of all sizes and verticals are being systematically targeted.

Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
brdigital.net.brL Group · Technology
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
Today’s recommendation: Immediately audit all WordPress installations for the presence of Fluent Forms Pro 6.2.7, Ninja Tables Pro 5.2.11, and the Link Factory plugin, treating any match as a potential compromise; scan mu-plugins and uploads directories for unexpected PHP files. Simultaneously, prioritize patching CVE-2026-61962 and CVE-2026-27544 in any environment running WP BASE Booking or QA Analytics, as unauthenticated RCE at CVSS 10.0 with no known mitigating factors demands immediate action.
With backdoored plugins, unauthenticated RCE, and six vulnerabilities already exploited before official confirmation, today's landscape makes clear that the most dangerous question is not whether threats exist — but whether your own attack surface has already been quietly compromised without your knowledge.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share