RCE

Remote Code Execution in Everest Forms

CVE-2026-3300 is a critical unauthenticated RCE in Everest Forms ≤1.9.12 — the Calculation Addon passes user input directly to eval(), giving attackers full server access.

26 June 2026

Read more

Remote Code Execution in RD Station Plugin

CVE-2026-49774: RD Station Plugin ≤5.6.0 lets contributor-level users execute arbitrary PHP by injecting a path traversal sequence into the OAuth refresh token, which is used unsanitised in a log file path.

21 June 2026

Read more

Unauthenticated RCE in File Uploader for WooCommerce

File Uploader for WooCommerce up to 1.0.3 exposes an unauthenticated REST endpoint that pulls an attacker-controlled file from Uploadcare into the uploads directory with any extension. Full pre-auth RCE (CVE-2025-13329, CVSS 9.8).

9 April 2026

Read more