CVE@CVEnewDisclosure
The tweet announces the discovery of a stored cross‑site scripting vulnerability in the Envira Gallery WordPress plugin, specifying the affected parameter but providing no PoC, exploit, patch, or evidence of active exploitation.
takenaka hiroya@Joe_Biden_jaPatch
A new RCE vulnerability (CVE-2026-1236) affecting the latest WordPress release has been confirmed with a CVSS score of 7.5, and immediate patching is advised.
CVEarity@CVEarityGeneral
The tweet announces CVE‑2026‑1236 with basic severity information and links to the NVD entry, but offers no detailed technical, exploit, or mitigation details.
Infoflowcloud@infoflowcloudDisclosure
The post simply announces CVE‑2026‑1236, noting a stored XSS in Envira Gallery’s 'justified_gallery_theme' parameter, without providing PoC, exploit code, or mitigation information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A stored XSS vulnerability (CVE-2026-1236) was disclosed in the Envira Gallery WordPress plugin via the Gallery Theme parameter.