Daily briefing · August 15, 2026

Calm CVE Day Belies Real Threat: WordPress Plugins and SiYuan Hit with Critical Flaws

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 15, 2026 registered no actively exploited vulnerabilities and no weaponized exploits, marking a calm day by the metrics — yet the disclosure queue delivered 17 critical CVEs among 925 new entries, with several carrying maximum or near-maximum CVSS scores. The day's highlight is a cluster of five stored XSS and RCE flaws in SiYuan's desktop client, where Electron's Node integration turns browser-grade bugs into full host compromise. On the WordPress front, three plugins — User Profile Builder, TrueBooker, and Pods — expose authentication bypass, account takeover, and privilege escalation at CVSS 9.8.

Today’s brief
  • No active exploitation or weaponized exploits recorded today — monitoring posture applies.
  • Five SiYuan (before v3.7.4) vulnerabilities allow stored XSS to reach arbitrary code execution via Electron Node integration.
  • Three WordPress plugins carry critical authentication bypass, account takeover, and privilege escalation flaws up to CVSS 9.8.
  • Brazil is under sustained ransomware pressure: TOTVS, government infrastructure, and multiple tech firms hit in recent days.
17
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-74764CVSS 10affects pandora
A path traversal flaw in Pandora's TAR extraction passes archive member names directly to Python's tarfile without filtering, letting an attacker write arbitrary files to the host — classic zip-slip class bug with direct path to code execution or persistence.
2
CVE-2026-15826CVSS 9.8affects User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
A type confusion in User Profile Builder (≤3.16.4) allows authentication bypass: absint() coerces a WP_Error to zero before the error check, which WordPress may treat as a valid user ID, enabling unauthenticated login under specific username-length conditions.
3
CVE-2026-16142CVSS 9.8affects TrueBooker – Appointment Booking and Scheduler System
TrueBooker (≤1.2.6) exposes an unauthenticated AJAX handler that accepts an arbitrary user ID and passes it directly to wp_update_user(), allowing any visitor to take over any account on the site without credentials.
4
CVE-2026-19598CVSS 9.8affects Pods – Custom Content Types and Fields
The Pods plugin (≤3.3.9) routes all admin AJAX access checks through pods_error(), which under JSON mode swallows errors and bypasses capability gates entirely — enabling unauthenticated users to escalate to administrator-level privileges.
5
CVE-2026-73053CVSS 9.4affects siyuan
SiYuan before v3.7.4 fails to sanitize hex-encoded markup in unicode2Emoji, allowing a crafted document icon to execute arbitrary JavaScript in the Electron renderer with full Node.js access — effectively remote code execution on the desktop host.
6
CVE-2026-73052CVSS 9.4affects siyuan
Unescaped attribute-view field names in SiYuan are interpolated via innerHTML into sort menus; renaming a database field to contain HTML markup triggers script execution with Node integration enabled whenever the sort menu is opened.
7
CVE-2026-73050CVSS 9.4affects siyuan
SiYuan's select-option color field is stored without HTML escaping and rendered in eight locations, letting attackers embed event-handler attributes that fire arbitrary JavaScript — and via Electron's Node integration, reach the underlying OS — when any user views the database.
8
CVE-2026-73044CVSS 9.4affects siyuan
Table column width values in SiYuan are injected unsanitized into style attributes, allowing payload breakout into event handlers on every table cell; the setAttrViewColWidth API is the attack vector, culminating in code execution through Node integration.
9
CVE-2026-73043CVSS 9.4affects siyuan
SiYuan's Template calculation operator renders user-authored Go templates and stores output verbatim, enabling injection of HTML and JavaScript that executes in the desktop renderer with Node integration — delivering arbitrary code execution when the template is evaluated.
10
CVE-2026-73042CVSS 9.4affects siyuan
Database menu metadata in SiYuan is interpolated into HTML without escaping; attackers can rename fields or descriptions to inject markup that closes containing elements and fires event handlers, reaching Node built-ins due to the client's insecure Electron configuration.
Ransomware today

Ransomware activity targeting Brazil remains notably intense in the current period. Among recently confirmed victims are TOTVS — a major Brazilian ERP and technology provider — claimed by direwolf, alongside Vector Two Technology and Megalaser Industria Metalurgica LTDA attributed to thegentlemen, and tecnoabi.com claimed by m3rx. The law firm VR Advogados was listed by Barracuda, underscoring that no vertical is being spared. Over the past 30 days, lockbit5 leads activity with 20 Brazilian victims, followed by Section9 (6), thegentlemen (5), and Global Secret Group (4).

TOTVS BRdirewolf · Technology
VR Advogados BRBarracuda · Professional Services
tecnoabi.com BRm3rx · Technology
Vector Two Technology BRthegentlemen · Technology
Megalaser Industria Metalurgica LTDA BRthegentlemen · Manufacturing
lockbit5 20Section9 6thegentlemen 5Global Secret Group 4L Group 2direwolf 2
Active groups & APTs

Several threat actors are flagged as active or updated in the current tracking window, including linkc, Equation, the North Korean-linked Darkhotel, karakurt, LeakBazaar, and apt73. No confirmed new victims are attributed to these groups in the current dataset, but their presence in active tracking suggests ongoing reconnaissance or operational preparation that defenders should monitor closely.

Brazil focus

Brazil is experiencing one of its more concentrated ransomware waves in recent memory, with victims spanning government infrastructure (Intranet Gov Brasil, claimed by thegentlemen), legal services (VR Advogados by Barracuda, Chat Jurídico by direwolf), construction (Alya Construtora by ransomhouse), and manufacturing (Megalaser Industria Metalurgica LTDA by thegentlemen). The breadth of targeted sectors and the dominance of lockbit5 with 20 Brazilian victims over 30 days signal a sustained, coordinated campaign rather than opportunistic incidents.

TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
Vector Two Technologythegentlemen · Technology
tecnoabi.comm3rx · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
Today’s recommendation: Defenders should prioritize patching SiYuan desktop clients to v3.7.4 or later immediately, as the five Electron-based XSS-to-RCE chains require only user interaction with attacker-controlled content. WordPress administrators running User Profile Builder (≤3.16.4), TrueBooker (≤1.2.6), or Pods (≤3.3.9) should apply available updates without delay, given the unauthenticated nature of all three exploitable conditions.
Even on a calm disclosure day, the combination of critical unauthenticated flaws and active ransomware campaigns is a strong prompt to validate whether any of these vulnerable components exist in your environment before attackers confirm it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share