OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqGeneral
High severity alert on CVE‑2026‑2001, which lets subscriber users install plugins in WowRevenue WordPress (≤2.1.3) leading to RCE; recommends restricting permissions and monitoring installs.
CVE@CVEnewDisclosure
The WowRevenue WordPress plugin has a missing capability check in 'Notice::install_activate_plugin', enabling unauthorized plugin installation; no exploit, patch, or active exploitation is reported.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
This is a disclosure of CVE‑2026‑2001 affecting the WordPress WowRevenue plugin, which permits unauthorized plugin installation.
The Hacker Wire@TheHackerWireDisclosure
The WowRevenue WordPress plugin is vulnerable to unauthorized plugin installation because of a missing capability check, with the CVE disclosed but no PoC, exploit, or patch details provided.
CVEFind.com@CveFindComDisclosure
The post announces CVE‑2026‑2001, a WordPress WowRevenue plugin flaw that allows authenticated attackers to install arbitrary plugins and potentially execute remote code due to missing validation checks.