Remote Code Execution in Everest Forms
CVE-2026-3300 is a critical unauthenticated RCE in Everest Forms ≤1.9.12 — the Calculation Addon passes user input directly to eval(), giving attackers full server access.
26 June 2026
Read moreRemote Code Execution in RD Station Plugin
CVE-2026-49774: RD Station Plugin ≤5.6.0 lets contributor-level users execute arbitrary PHP by injecting a path traversal sequence into the OAuth refresh token, which is used unsanitised in a log file path.
21 June 2026
Read moreUnauthenticated RCE in File Uploader for WooCommerce
File Uploader for WooCommerce up to 1.0.3 exposes an unauthenticated REST endpoint that pulls an attacker-controlled file from Uploadcare into the uploads directory with any extension. Full pre-auth RCE (CVE-2025-13329, CVSS 9.8).
9 April 2026
Read more