Security Digest: June 30, 2026 - 6 Critical Vulnerabilities

Today’s alert is dominated by active-risk flaws in WordPress plugins, LinuxCNC, NLTK, and libarchive. The most urgent issues include unauthenticated SQL injection in a widely used event calendar plugin, a local root escalation in LinuxCNC, and a plugin flaw that can lead to arbitrary file deletion and possible site takeover.

· 7 min read

Executive Summary

Today’s alert is dominated by active-risk flaws in WordPress plugins, LinuxCNC, NLTK, and libarchive. The most urgent issues include unauthenticated SQL injection in a widely used event calendar plugin, a local root escalation in LinuxCNC, and a plugin flaw that can lead to arbitrary file deletion and possible site takeover.

Act now: patch exposed systems immediately, disable vulnerable features where possible, and review logs for suspicious search queries, file operations, and unexpected script activity.

Critical Vulnerabilities

CVE-2026-9711: EventON WordPress plugin SQL injection

  • Impact: Unauthenticated attackers may inject SQL and extract sensitive database data, including user and event information.
  • Affected Systems: EventON - WordPress Virtual Event Calendar Plugin versions up to and including 5.0.11, when “Enable additional search queries” is enabled and at least one published event exists.
  • Immediate Action: Update or disable the plugin immediately on any public WordPress site. If you cannot patch at once, disable the additional search queries setting and restrict access to the site.
  • Mitigation: Apply the vendor fix as soon as available, then rotate any credentials or secrets that may have been exposed through the database.

CVE-2026-58302: LinuxCNC rtapi_app local privilege escalation

  • Impact: A local attacker can escalate to root by abusing unsafe shared-library loading in a SUID-root binary.
  • Affected Systems: LinuxCNC before 2.9.9 on systems with linuxcnc-uspace installed.
  • Immediate Action: Upgrade LinuxCNC immediately. If patching is delayed, remove or restrict access to the SUID binary and limit local shell access to trusted users only.
  • Mitigation: Deploy version 2.9.9 or later and audit for unexpected library loading behavior or privilege abuse.

CVE-2026-12240: Export User Data plugin arbitrary file deletion

  • Impact: Authenticated attackers with subscriber-level access can delete arbitrary files; deleting wp-config.php can lead to site compromise and possible remote code execution.
  • Affected Systems: Export User Data plugin versions up to and including 2.2.6.
  • Immediate Action: Update the plugin now. Until patched, remove the plugin or disable user-triggered exports on production sites.
  • Mitigation: Patch to the fixed release, review recent export activity, and inspect for malicious display-name payloads or unusual file deletions.

CVE-2026-14164: libarchive RAR5 double free

  • Impact: Crafted RAR5 archives can crash applications using libarchive, causing denial of service.
  • Affected Systems: Applications linked against vulnerable libarchive versions with RAR5 support enabled.
  • Immediate Action: Update libarchive in servers, desktop tools, and any software that processes archives from untrusted sources. Block suspicious RAR uploads where possible.
  • Mitigation: Apply the upstream fix, then test archive-handling workflows and monitor for repeated crashes tied to RAR5 parsing.

CVE-2026-12243: NLTK path traversal in resource loading

  • Impact: Attackers may read arbitrary files accessible to the Python process by bypassing path checks with encoded traversal sequences.
  • Affected Systems: NLTK 3.9.4 and applications using nltk.data.load() or nltk.data.find().
  • Immediate Action: Upgrade NLTK immediately. If you cannot patch, stop accepting untrusted resource names and review any app paths that expose NLTK loading to users.
  • Mitigation: Move to the fixed release, validate all resource-name inputs, and treat any file-read exposure as a potential data leak.

CVE-2026-8141: Ajax Load More - Filters stored XSS

  • Impact: Unauthenticated attackers can inject scripts that execute in visitors’ browsers, enabling session theft, defacement, or malicious redirects.
  • Affected Systems: Ajax Load More - Filters plugin versions up to and including 3.4.1.
  • Immediate Action: Update the plugin now. If immediate patching is not possible, disable the affected filter functionality or remove the plugin from exposed sites.
  • Mitigation: Patch to the fixed version and inspect pages using the plugin for injected content or unexpected client-side behavior.

Previously Alerted

What to Do Now

  1. Patch public-facing WordPress plugins first, especially EventON, Export User Data, and Ajax Load More - Filters.
  2. Upgrade LinuxCNC to 2.9.9 or later on any host where local users are not fully trusted.
  3. Update NLTK and libarchive across servers, developer machines, notebooks, and application images.
  4. Temporarily disable risky features such as additional search queries, user exports, and untrusted archive processing.
  5. Review logs and file changes for SQL errors, unexpected exports, deleted files, browser-side script injection, and archive-related crashes.

Verification steps: confirm installed plugin/package versions, check whether vulnerable features are enabled, and validate that patches were applied to every environment, including containers and staging systems.

Monitoring recommendations: watch for abnormal database queries, new admin accounts, file deletion events, suspicious RAR uploads, repeated application crashes, and browser reports of injected scripts.

Related Resources

  • Internal: Related June 2026 response guidance and patch validation checklist (to be published).
  • Official advisories: Vendor and project security advisories for WordPress plugins, LinuxCNC, NLTK, and libarchive.

Keep reading