DFIR Lab[verified]@DFIR_LabDisclosure
The tweet announces the newly disclosed WordPress plugin vulnerability CVE-2026-12416, highlighting its critical severity and urging immediate patching or disabling of the plugin.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses a critical unauthenticated account takeover flaw in the Invoice Generator WordPress plugin, explaining how the missing nonce and loose equality checks allow password reset bypass, but notes that no patch is currently available.
Orizon[verified]@OrizonCyberPatch
The tweet announces a critical WordPress plugin vulnerability (CVE-2026-12416) with an available patch and provides key technical details.
ExploitGrid@exploitgridExploit
The post lists five CVEs from June 20–27, highlighting that they have publicly available exploits and directing readers to exploitgrid.net for details; CVE‑2026‑48908 is noted as already being exploited in the wild.
SecAlerts@SecAlertsCoDisclosure
The post announces a severe CVE (9.8) affecting the Pravel Invoice Generator plugin, highlighting an unauthenticated account takeover via weak reset_user_id validation.
Atomic Edge@atomicedgeWAFPoC
A proof‑of‑concept for CVE‑2026‑12416 in the Invoice Creator WordPress plugin is presented, noting its critical CVSS score, but no exploits, patches, or evidence of active exploitation are provided.
ThreatAft@ThreatAftGeneral
A critical vulnerability (CVE‑2026‑12416) in the WordPress Invoice Generator plugin is announced as a potential account takeover risk, but no exploitation details or patches are provided.