Security Digest: June 27, 2026 - 5 Critical Vulnerabilities

Five high-priority vulnerabilities demand immediate attention today. The most urgent is CVE-2026-12415, a WordPress plugin flaw that can let unauthenticated attackers take over admin accounts.

· 8 min read

Executive Summary

Five high-priority vulnerabilities demand immediate attention today. The most urgent is CVE-2026-12415, a WordPress plugin flaw that can let unauthenticated attackers take over admin accounts. The remaining issues affect pnpm and gonic, with risks ranging from supply-chain code execution to unauthorized playlist access and file traversal.

Action now: patch exposed systems, disable or remove affected components where possible, and verify that no malicious account changes, package-manager switches, or unauthorized playlist activity have occurred.

Critical Vulnerabilities

  • CVE-2026-12415: WordPress Invoice Generator privilege escalation
    • Impact: Unauthenticated attackers can change any user’s email address, including administrators, then trigger password reset and take over the account.
    • Affected Systems: Invoice Generator plugin for WordPress versions up to and including 1.0.0.
    • Immediate Action: Disable or remove the plugin now if you cannot confirm a fixed release. Review user accounts for unexpected email changes and password reset activity.
    • Mitigation: Apply the vendor patch as soon as it is available; until then, restrict access to WordPress admin, rotate credentials for impacted accounts, and inspect logs for requests to wp_ajax_nopriv_pravel_invoice_edit_account.
  • CVE-2026-55698: pnpm env-lockfile package-manager trust bypass
    • Impact: A malicious repository can cause pnpm to install and execute attacker-selected package-manager code during automatic version switching.
    • Affected Systems: npm:pnpm and npm:@pnpm/installing.env-installer; direct pnpm execution with package-manager auto-switching and repository-controlled env lockfiles.
    • Immediate Action: Update pnpm immediately to a release containing the fix. Treat unexpected pnpm version switches in CI or developer environments as suspicious.
    • Mitigation: Pull the patched release that force-refreshes package-manager metadata through trusted registries before execution. If you cannot patch immediately, avoid running pnpm in untrusted repositories.
  • CVE-2026-55700: pnpm staged-tarball filename traversal
    • Impact: A crafted package manifest could write outside the intended download directory and overwrite reachable files.
    • Affected Systems: pnpm release/staging commands in affected versions before fix commit 65443f4bdf1f0db9c8c7dc58fee25252607e9234.
    • Immediate Action: Upgrade pnpm now. If staging workflows are exposed to untrusted package metadata, suspend them until patched.
    • Mitigation: Confirm you are on a build that validates package name/version and checks the final path before writing. Review any recent unexpected file changes in staging directories.
  • CVE-2026-49338: gonic playlist authorization bypass
    • Impact: Any authenticated user can delete another user’s playlist and read private playlist contents.
    • Affected Systems: gonic up to tagged release v0.20.1 and earlier; fixed in commit 6dd71e6a3c966867ef8c900d359a7df75789f410 but not yet in a tagged release.
    • Immediate Action: Restrict access to authenticated users only and plan an emergency upgrade when a tagged release lands. Watch for playlist deletion or unexpected playlist reads.
    • Mitigation: Backport the ownership-check fix or deploy the patched commit if you build from source. Audit playlist activity for cross-user access.
  • CVE-2026-49339: gonic playlist path traversal bypass
    • Impact: Authenticated attackers can bypass the new ownership check using crafted playlist IDs, then read or delete other users’ playlists and probe file paths.
    • Affected Systems: gonic versions containing commit 6dd71e6a3c966867ef8c900d359a7df75789f410 without a follow-up path containment fix.
    • Immediate Action: Do not assume the ownership fix is enough. Apply a containment patch that blocks playlist paths escaping the playlist directory.
    • Mitigation: Reject any playlist path that leaves the base directory after resolution. Until fixed, limit Subsonic access and monitor for unusual playlist IDs and file access errors.

What to Do Now

  1. Patch first: Prioritize CVE-2026-12415 and CVE-2026-55698 if they are internet-facing or used in CI/developer workflows. Then update pnpm and gonic deployments.
  2. Disable risky components: Remove or disable the vulnerable WordPress plugin; pause pnpm auto-switching in untrusted repos; restrict gonic Subsonic access if you cannot patch immediately.
  3. Verify exposure: Check WordPress logs for password-reset abuse, pnpm CI logs for unexpected version switching, and gonic logs for cross-user playlist reads/deletes.
  4. Confirm patch state: Verify versions against vendor advisories and commit references. Do not rely on partial fixes where a second bypass is documented.
  5. Hunt for abuse: Review recent admin email changes, unexpected package downloads, modified tarball/staging files, and playlist deletion events.

Verification Steps

  • Inventory all WordPress sites using Invoice Generator and confirm whether version 1.0.0 or earlier is present.
  • Check build pipelines and developer images for pnpm versions that predate the advisory fix.
  • Review gonic deployment tags and source commits; if you are on v0.20.1 or earlier, treat the service as vulnerable.
  • Validate that no repository-controlled lockfile or playlist ID is being trusted without path or ownership enforcement.

Monitoring Recommendations

  • Alert on WordPress admin email changes, password reset requests, and AJAX calls to unauthenticated account-edit actions.
  • Alert on pnpm switching package-manager versions during checkout or CI runs, especially from untrusted repositories.
  • Alert on unexpected file writes in staging/download directories and on path traversal indicators in package metadata.
  • Alert on gonic requests to /rest/getPlaylist.view and /rest/deletePlaylist.view that target unusual or repeated playlist IDs.

Related Resources

  • Internal blog posts: A short follow-up on emergency patch triage and supply-chain exposure will be published separately.
  • Official vendor advisories: Track the WordPress plugin release notes, the pnpm advisory GHSA-w466-c33r-3gjp, and the gonic fix commits referenced above.

Keep reading