Security Digest: June 18, 2026 - 10 Critical Vulnerabilities
Today’s threat picture is urgent: multiple high-impact flaws affect WordPress plugins, Cotonti, TypeBot, and cifs-utils, with paths to privilege escalation, stored XSS, SSRF, and remote code execution. Act now: patch exposed systems, disable vulnerable features where possible, and review admin and upload-capable accounts immediately.
· 9 min read
Executive Summary
Today’s threat picture is urgent: multiple high-impact flaws affect WordPress plugins, Cotonti, TypeBot, and cifs-utils, with paths to privilege escalation, stored XSS, SSRF, and remote code execution. The most dangerous issues allow attackers to take over admin accounts, write to wp-config.php, or reach internal services from public-facing apps.
Act now: patch exposed systems, disable vulnerable features where possible, and review admin and upload-capable accounts immediately. If you run any affected product, treat it as a same-day remediation item.
Critical Vulnerabilities
CVE-2026-55742: Cotonti admin rights CSRF leads to privilege escalation
- Impact: An attacker can trick an authenticated admin into granting elevated permissions to an attacker-controlled group, potentially leading to full site takeover and further code execution.
- Affected Systems: Cotonti 1.0.0 master branch, commit
f43f1fc3. - Immediate Action: Restrict admin access, review group rights changes, and patch or backport the CSRF fix immediately.
- Mitigation: Ensure the rights update handler validates anti-CSRF tokens with
cot_check_xg(); monitor for unexpected group or template changes.
CVE-2026-48768: TypeBot unauthenticated file upload enables arbitrary content hosting
- Impact: Anonymous users can upload attacker-controlled HTML, SVG, or JS into public storage paths, enabling stored XSS and malicious content hosting.
- Affected Systems: TypeBot versions 3.16.1 and earlier.
- Immediate Action: Upgrade to 3.17.0 or later and disable public file-input bots until patched.
- Mitigation: Validate and sanitize file names, bind upload URLs to safe content types, and review public bot endpoints for abuse.
CVE-2026-12407: E2Pdf missing authorization allows WordPress option overwrite
- Impact: Authenticated users with certain granted roles can overwrite arbitrary WordPress options, including
default_role, and escalate to administrator. - Affected Systems: E2Pdf – Export Pdf Tool for WordPress up to and including 1.32.26.
- Immediate Action: Update the plugin now and audit any roles granted
e2pdf_templates. - Mitigation: Remove unnecessary custom capabilities, restrict plugin access, and verify no unauthorized option changes occurred.
CVE-2026-9860: Cloudflare Images plugin RCE via wp-config.php write
- Impact: Authenticated users with upload access can inject code into
wp-config.phpand execute commands on the server. - Affected Systems: Offload, AI & Optimize with Cloudflare Images up to and including 1.10.2.
- Immediate Action: Disable the plugin or remove upload-capable access until patched.
- Mitigation: Update immediately, verify
account-idand API key handling, and inspectwp-config.phpfor tampering.
CVE-2026-55741: Cotonti configuration CSRF can weaken security settings
- Impact: A forged request can change core, module, or plugin settings and open the door to further compromise.
- Affected Systems: Cotonti 1.0.0 master branch, commit
f43f1fc3. - Immediate Action: Patch immediately and review recent configuration changes.
- Mitigation: Require CSRF validation on configuration updates and lock down admin sessions.
CVE-2026-48764: TypeBot SSRF guard bypass via DNS rebinding
- Impact: Attackers can make the server connect to internal services or metadata endpoints, exposing sensitive data or enabling deeper compromise.
- Affected Systems: TypeBot versions prior to 3.17.2.
- Immediate Action: Upgrade to 3.17.2 or later and disable server-side fetch blocks for untrusted bots.
- Mitigation: Rework SSRF checks to pin the validated IP, and block outbound access to private ranges at the network layer.
CVE-2026-55744: Cotonti PFS upload CSRF
- Impact: Attackers can force authenticated users to upload arbitrary files into personal storage.
- Affected Systems: Cotonti 1.0.0 master branch, commit
f43f1fc3. - Immediate Action: Patch and review recent file uploads from privileged users.
- Mitigation: Enforce anti-CSRF checks on upload actions and restrict file types and destinations.
CVE-2026-12505: cifs-utils root helper can load attacker NSS modules
- Impact: A local attacker can gain root by forcing the helper to load malicious NSS code.
- Affected Systems: cifs-utils package installations using
cifs.upcall. - Immediate Action: Apply vendor updates and treat any untrusted local user as a potential root escalation risk.
- Mitigation: Ensure the helper drops privileges before environment-sensitive lookups and restrict local execution paths.
CVE-2026-55746: Cotonti PFS stored XSS in folder titles
- Impact: Attackers can store script in folder titles that executes when listings are viewed, including by other users.
- Affected Systems: Cotonti 1.0.0 master branch, commit
f43f1fc3. - Immediate Action: Patch now and inspect public folders for suspicious titles.
- Mitigation: Escape output in templates and remove any HTML-capable title input paths.
CVE-2026-11395: CF7 to Webhook SSRF via crafted webhook placeholders
- Impact: Unauthenticated attackers can trigger web requests to arbitrary locations and interact with internal services.
- Affected Systems: CF7 to Webhook plugin up to and including 5.0.0, when a public form and placeholder-based host are configured.
- Immediate Action: Disable the plugin or affected webhook configurations until patched.
- Mitigation: Remove field placeholders from the host portion of webhook URLs and validate outbound destinations.
Previously Alerted
- CVE-2026-55740: Security Alert
What to Do Now
- Patch exposed internet-facing systems first — especially WordPress sites, TypeBot instances, and any Cotonti deployment.
- Disable risky features temporarily — public file uploads, server-side fetch blocks, and vulnerable webhook configurations.
- Review privileged accounts and roles — look for unexpected admin grants, option changes, and recent plugin setting updates.
- Inspect for compromise — check
wp-config.php, upload directories, public storage buckets, and admin configuration history. - Restrict outbound and local trust paths — block access to private IP ranges and limit local shell access where possible.
Verification steps: confirm patched versions, compare current plugin and CMS versions against vendor advisories, and validate that CSRF protections are active on admin actions. Search logs for suspicious POST requests, unusual uploads, and outbound requests to internal networks.
Monitoring recommendations: alert on admin-rights changes, new uploads in public paths, unexpected WordPress option writes, and any server-side requests to RFC1918 or metadata addresses. Watch for script execution from storage origins and for local privilege escalation attempts on Linux hosts.
Related Resources
- Internal blog posts: pending publication on Cotonti CSRF, TypeBot SSRF, and WordPress plugin triage.
- Official vendor advisories: consult Cotonti, TypeBot, WordPress plugin, and cifs-utils release notes for fixed versions and mitigation details.