Security Digest: June 20, 2026 - 6 Critical Vulnerabilities
Today’s alerts are dominated by WordPress plugin flaws that can lead to account takeover, arbitrary file deletion, and file modification, plus two Capgo issues that can expose organization data or let attackers mint more powerful API keys. If you run any affected plugin or Capgo version, patch or disable exposed functionality immediately and review for signs of compromise.
· 8 min read
Security Digest: June 20, 2026 - 6 Critical Vulnerabilities
Executive Summary
Today’s alerts are dominated by WordPress plugin flaws that can lead to account takeover, arbitrary file deletion, and file modification, plus two Capgo issues that can expose organization data or let attackers mint more powerful API keys. If you run any affected plugin or Capgo version, patch or disable exposed functionality immediately and review for signs of compromise.
The most urgent risks are unauthenticated attacks against WordPress sites and scope escalation in Capgo. Treat any public-facing instance as potentially at risk until you confirm it is updated and no malicious activity has occurred.
Critical Vulnerabilities
CVE-2026-11551: Branda plugin password reset flaw enables account takeover
- Impact: Unauthenticated attackers can change arbitrary user passwords, including administrator accounts, and take over the site.
- Affected Systems: Branda plugin for WordPress, all versions up to and including
3.4.29. - Immediate Action: Disable or remove Branda now if you cannot patch immediately. Force password resets for all privileged accounts and review recent account changes.
- Mitigation: Update to a fixed release as soon as the vendor provides one. Until then, restrict admin access, rotate credentials, and check logs for unexpected password-reset activity.
CVE-2026-56216: Capgo API key scope escalation can create unrestricted keys
- Impact: Attackers with a compromised app-limited API key can mint an unrestricted key and gain org-wide access to protected resources.
- Affected Systems: Capgo versions before
12.128.2. - Immediate Action: Rotate all Capgo API keys now, especially app-limited keys, and review key creation activity for anomalies.
- Mitigation: Upgrade to
12.128.2or later. Revoke any suspicious keys, audit access to app listings and other protected endpoints, and limit exposure of API credentials.
CVE-2026-9843: Database for Contact Form 7 / WPforms / Elementor forms can delete arbitrary files
- Impact: Unauthenticated attackers can trigger deletion of arbitrary files; deleting
wp-config.phpor similar files can lead to remote code execution. - Affected Systems: Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress, all versions up to and including
1.5.1. - Immediate Action: Remove or disable the plugin on exposed sites until patched. Inspect admin activity for poisoned form entries and delete suspicious submissions.
- Mitigation: Update to a fixed version when available. Review file-integrity alerts, back up the site, and verify that no critical files were deleted or altered.
CVE-2026-56214: Capgo information disclosure reveals organizations and billing status
- Impact: Unauthenticated attackers can enumerate organizations and learn whether they are paying customers, enabling targeted profiling and follow-on attacks.
- Affected Systems: Capgo versions before
12.128.2. - Immediate Action: Assume public metadata exposure if your Capgo instance is reachable. Reduce unnecessary public access and review API usage for enumeration patterns.
- Mitigation: Upgrade to
12.128.2or later. Restrict access to Supabase/PostgREST endpoints where possible and monitor for repeated calls to trial or billing-status methods.
CVE-2026-11911: Simple File List arbitrary file deletion can lead to site compromise
- Impact: Unauthenticated attackers can delete arbitrary files on the server, potentially causing remote code execution if a critical file is removed.
- Affected Systems: Simple File List plugin for WordPress, all versions up to and including
6.3.7. - Immediate Action: Update or disable the plugin immediately. Check whether the
simplefilelist_edit_jobAJAX endpoint is exposed and review admin-ajax activity. - Mitigation: Patch to a fixed release, verify file integrity, and restore from clean backups if any core files were deleted. Watch for suspicious requests to
admin-ajax.php.
CVE-2026-11912: Simple File List arbitrary file modification bypasses authorization
- Impact: Unauthenticated attackers can delete or modify files on the server, creating a path to defacement, persistence, or code execution.
- Affected Systems: Simple File List plugin for WordPress, all versions up to and including
6.3.7. - Immediate Action: Treat this as active compromise risk on any internet-facing WordPress site using the plugin. Disable the plugin and inspect file changes immediately.
- Mitigation: Update as soon as a fix is available. Do not rely on the
AllowFrontManagesetting for protection; confirm file permissions, restore tampered files, and review logs for unauthorized file operations.
What to Do Now
- Patch or disable affected software today. Prioritize Branda and Simple File List on WordPress sites, then Capgo instances before
12.128.2. - Rotate credentials and revoke keys. Reset WordPress admin passwords, rotate Capgo API keys, and invalidate any tokens that may have been exposed.
- Check for compromise. Review file integrity, recent admin logins, password changes, API key creation, and unexpected deletions or modifications.
- Restore from known-good backups if needed. If core files or configuration files were touched, rebuild from clean backups rather than trying to repair in place.
- Limit exposure. Restrict admin panels, API endpoints, and
admin-ajax.phpaccess where possible until fixes are confirmed.
Verification steps: confirm plugin versions against the affected ranges, check vendor changelogs for fixed releases, and validate that no unauthorized accounts, keys, or file changes remain. For WordPress, inspect wp-config.php, recent uploads, and plugin directories for tampering.
Monitoring recommendations: alert on password resets, new API keys, repeated calls to Capgo RPC endpoints, requests to admin-ajax.php, and file deletions or modifications in web roots. Keep an eye out for logins from unusual IPs after any suspected account takeover.
Related Resources
- Internal: Related internal blog posts on WordPress plugin risk management and Capgo API security are recommended for follow-up, but have not been published yet.
- Official vendor advisories: Monitor vendor security advisories for Branda, Capgo, Database for Contact Form 7 / WPforms / Elementor forms, and Simple File List for fixed versions and remediation guidance.