🎯 CVE-2026-1051 🇪🇺 EUVD
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

CVE-2026-1051 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.

Klassifikation & Betroffenheit:
satollo Newsletter – Send awesome emails from WordPress 0 ≤9.1.0
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 🎯 High

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and …
Vollständige Definition bei MITRE ➔
🧩 Ähnliche Schwachstellen (Hersteller/Klasse/Score-Band):
📰 Eigene Berichterstattung: ➔ CVE-2026-105161 | invariant-systems-ai aiir up to 1.7.0 Policy Gate signature ve ➔ CVE-2026-105149 | mooSocial up to 3.2.4 /stores/all-products rating sql injectio ➔ CVE-2026-105186 | itsourcecode Online Admission System 1.0 /new.php schedid sql ➔ CVE-2026-105182 | SourceCodester Online Reviewer Management System 1.0 btn_funct ➔ CVE-2026-105178 | SourceCodester Drug Recommendation System 1.0 Symptom Creation
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 4.3
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Erforderlich
S · Scope Unverändert
C · Vertraulichkeit Keine
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Veröffentlicht:20.01.2026
Aktualisiert:17.06.2026 10:14
Assigner (CNA):Wordfence
EUVD-ID:EUVD-2026-3489
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🗨 Diskussion zu CVE-2026-1051 0 Beiträge
Antworten, Upvotes & Reaktionen — wie im Community-Feed. Markdown und ```Code``` unterstützt.

Noch keine Analyse zu CVE-2026-1051

Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.

↩️ Antworten auf:

Beitrag zu CVE-2026-1051 verfassen

Neu hier? Als Mitglied sammelst du Karma für Beiträge und Answers.
📧
Code-Formatierung: ```bash ... ``` oder `inline code` 0 / 2000
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

374k+ 🇪🇺 EUVD-Datenbank
1 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
5 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 257 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1511 2026-10: 289 9.588 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-242026-10-08
≥90 %484342
≥50 %14361061
≥10 %162
<10 %30562
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.993 Einträge):
Quelle:
🔍
2.3 LOW
EPSS
CVE-2026-105140 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
obot-platform

CVE-2026-105140 | Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-105139 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
obot-platform

CVE-2026-105139 | Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attacke

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
EPSS
CVE-2026-105138 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
obot-platform

CVE-2026-105138 | Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access cont

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS
CVE-2026-105192 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
LMCache

CVE-2026-105192 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes c

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
2.3 LOW
EPSS
CVE-2026-105111 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache Software Foundation

CVE-2026-105111 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports). This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, whic

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files,

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.3 MEDIUM
EPSS 0.1%
CVE-2026-1051 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
satollo

CVE-2026-1051 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_ac

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6 von ~6 Einträgen geladen Ende der Trefferliste — 6 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.