CVE-2026-81294

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-19: 1Mentions · 2026-09-20: 109-1909-20
Referenced assets3 URLs
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 WordPress eklentilerindeki iki kritik güvenlik açığı için @abraxas_null adlı araştırmacı tarafından PoC yayınlandı: CVE-2026-81294 (CVSS: 9.8) — Authorizer ≤3.15.1 Kimlik doğrulaması gerektirmeyen açık, OAuth2 giriş akışında doğrulanmamış e-posta adresinin kontrol edilmemesi nedeniyle yetki yükseltmeye yol açıyor. CVE-2026-13447 (CVSS: 9.8) — MStore API ≤4.20.0 Firebase ID token'larının kriptografik imza doğrulamasının yapılmaması, saldırganların sahte JWT oluşturarak kimlik doğrulamasını atlatmasına olanak sağlıyor. PoC'ler: CVE-2026-81294: https://github.com/abraxas/CVE-2026-81294 CVE-2026-13447: https://github.com/abraxas/CVE-2026-13447 Authorizer 3.15.2+, MStore API 4.21.1+ sürümlerine güncellenmeli.

    03043669
    2.3K followersView on X
  • abraxas@abraxas_null

    it's wordpress devolution day... CVE-2026-81294 - WordPress Authorizer - Critical 9.8 - Unauthenticated Privilege Escalation exploit: https://github.com/abraxas/CVE-2026-81294 lab write-up (with infra): https://abraxaslabs.tech/research/cve-2026-81294

    0002059
    57 followersView on X

Explore more