Remote Code Execution in RD Station Plugin
CVE-2026-49774: RD Station Plugin ≤5.6.0 lets contributor-level users execute arbitrary PHP by injecting a path traversal sequence into the OAuth refresh token, which is used unsanitised in a log file path.
21 June 2026
Read more