
I've been busy. I have two new CVEs disclosed: CVE-2026-57339: Business Directory Plugin (<= 6.4.23). it allowed unauthenticated deletion of any listing on a website. Then there is CVE-2026-14306: Tutor LMS (< 3.9.14). which was some sort of payment bypass where you could view lessons not paid for. Write-ups and PoCs are on my github: http://github.com/johnumorujo/published-cves #infosec #bugbounty #WordPress
Post summary
The author announces two newly disclosed WordPress plugin CVEs, detailing the nature of the attacks and providing PoC links, but does not report active exploitation or patches.


