Nxploited[verified]@NxploitedExploit
The tweet announces CVE‑2026‑2631 and shares a PoC/exploit script on GitHub, confirming vulnerability details but no evidence of active exploitation or patch status.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
CVE-2026-2631 enables unauthenticated attackers to take over WordPress sites by altering site options and default roles; immediate update is recommended to mitigate the risk.
dbugs[verified]@ptdbugsPoC
The post discloses a critical privilege escalation flaw in Datalogics Ecommerce Delivery <2.6.60, provides technical details and a CVSS score, and shares a proof‑of‑concept exploit on GitHub, but does not mention active exploitation or patch information.
Brinztech@Brinztech_comPoC
A public proof‑of‑concept for CVE-2026-2631 affecting Datalogics Ecommerce Delivery has been released, with a link to the shared PoC.
CVE@CVEnewDisclosure
The Datalogics Ecommerce Delivery WordPress plugin prior to 2.6.60 is vulnerable to unauthenticated REST endpoint exploitation that permits remote modification of plugin options.
The Hacker Wire@TheHackerWireDisclosure
The text announces a critical vulnerability (CVE-2026-2631) in the Datalogics Ecommerce Delivery WordPress plugin, detailing an unauthenticated REST endpoint that permits remote modification of the `datalogics_token` option.