Security Digest: June 30, 2026 - 6 Critical Vulnerabilities
Today’s alert is dominated by active-risk flaws in WordPress plugins, LinuxCNC, NLTK, and libarchive. The most urgent issues include unauthenticated SQL injection in a widely used event calendar plugin, a local root escalation in LinuxCNC, and a plugin flaw that can lead to arbitrary file deletion and possible site takeover.
· 7 min read
Executive Summary
Today’s alert is dominated by active-risk flaws in WordPress plugins, LinuxCNC, NLTK, and libarchive. The most urgent issues include unauthenticated SQL injection in a widely used event calendar plugin, a local root escalation in LinuxCNC, and a plugin flaw that can lead to arbitrary file deletion and possible site takeover.
Act now: patch exposed systems immediately, disable vulnerable features where possible, and review logs for suspicious search queries, file operations, and unexpected script activity.
Critical Vulnerabilities
CVE-2026-9711: EventON WordPress plugin SQL injection
- Impact: Unauthenticated attackers may inject SQL and extract sensitive database data, including user and event information.
- Affected Systems: EventON - WordPress Virtual Event Calendar Plugin versions up to and including
5.0.11, when “Enable additional search queries” is enabled and at least one published event exists. - Immediate Action: Update or disable the plugin immediately on any public WordPress site. If you cannot patch at once, disable the additional search queries setting and restrict access to the site.
- Mitigation: Apply the vendor fix as soon as available, then rotate any credentials or secrets that may have been exposed through the database.
CVE-2026-58302: LinuxCNC rtapi_app local privilege escalation
- Impact: A local attacker can escalate to root by abusing unsafe shared-library loading in a SUID-root binary.
- Affected Systems: LinuxCNC before 2.9.9 on systems with
linuxcnc-uspaceinstalled. - Immediate Action: Upgrade LinuxCNC immediately. If patching is delayed, remove or restrict access to the SUID binary and limit local shell access to trusted users only.
- Mitigation: Deploy version
2.9.9or later and audit for unexpected library loading behavior or privilege abuse.
CVE-2026-12240: Export User Data plugin arbitrary file deletion
- Impact: Authenticated attackers with subscriber-level access can delete arbitrary files; deleting
wp-config.phpcan lead to site compromise and possible remote code execution. - Affected Systems: Export User Data plugin versions up to and including
2.2.6. - Immediate Action: Update the plugin now. Until patched, remove the plugin or disable user-triggered exports on production sites.
- Mitigation: Patch to the fixed release, review recent export activity, and inspect for malicious display-name payloads or unusual file deletions.
CVE-2026-14164: libarchive RAR5 double free
- Impact: Crafted RAR5 archives can crash applications using libarchive, causing denial of service.
- Affected Systems: Applications linked against vulnerable libarchive versions with RAR5 support enabled.
- Immediate Action: Update libarchive in servers, desktop tools, and any software that processes archives from untrusted sources. Block suspicious RAR uploads where possible.
- Mitigation: Apply the upstream fix, then test archive-handling workflows and monitor for repeated crashes tied to RAR5 parsing.
CVE-2026-12243: NLTK path traversal in resource loading
- Impact: Attackers may read arbitrary files accessible to the Python process by bypassing path checks with encoded traversal sequences.
- Affected Systems: NLTK
3.9.4and applications usingnltk.data.load()ornltk.data.find(). - Immediate Action: Upgrade NLTK immediately. If you cannot patch, stop accepting untrusted resource names and review any app paths that expose NLTK loading to users.
- Mitigation: Move to the fixed release, validate all resource-name inputs, and treat any file-read exposure as a potential data leak.
CVE-2026-8141: Ajax Load More - Filters stored XSS
- Impact: Unauthenticated attackers can inject scripts that execute in visitors’ browsers, enabling session theft, defacement, or malicious redirects.
- Affected Systems: Ajax Load More - Filters plugin versions up to and including
3.4.1. - Immediate Action: Update the plugin now. If immediate patching is not possible, disable the affected filter functionality or remove the plugin from exposed sites.
- Mitigation: Patch to the fixed version and inspect pages using the plugin for injected content or unexpected client-side behavior.
Previously Alerted
- CVE-2026-12073: CVE-2026-12073 Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch public-facing WordPress plugins first, especially EventON, Export User Data, and Ajax Load More - Filters.
- Upgrade LinuxCNC to 2.9.9 or later on any host where local users are not fully trusted.
- Update NLTK and libarchive across servers, developer machines, notebooks, and application images.
- Temporarily disable risky features such as additional search queries, user exports, and untrusted archive processing.
- Review logs and file changes for SQL errors, unexpected exports, deleted files, browser-side script injection, and archive-related crashes.
Verification steps: confirm installed plugin/package versions, check whether vulnerable features are enabled, and validate that patches were applied to every environment, including containers and staging systems.
Monitoring recommendations: watch for abnormal database queries, new admin accounts, file deletion events, suspicious RAR uploads, repeated application crashes, and browser reports of injected scripts.
Related Resources
- Internal: Related June 2026 response guidance and patch validation checklist (to be published).
- Official advisories: Vendor and project security advisories for WordPress plugins, LinuxCNC, NLTK, and libarchive.