Security Digest: July 9, 2026 - 18 Critical Vulnerabilities
Today’s alert is broad and urgent: we have multiple critical bugs that can lead to administrator takeover, remote code execution, SQL injection, stored XSS, and authentication bypass across WordPress plugins, business apps, and platform components. The biggest immediate risks are the WordPress plugin flaws that allow unauthenticated account takeover or arbitrary file upload, plus the public SQL injection issues that are already being targeted.
· 13 min read
Executive Summary
Today’s alert is broad and urgent: we have multiple critical bugs that can lead to administrator takeover, remote code execution, SQL injection, stored XSS, and authentication bypass across WordPress plugins, business apps, and platform components. The biggest immediate risks are the WordPress plugin flaws that allow unauthenticated account takeover or arbitrary file upload, plus the public SQL injection issues that are already being targeted.
Act now: patch exposed systems first, disable vulnerable features where needed, and watch for suspicious admin changes, new plugins, unexpected password resets, and webshell-style uploads.
Critical Vulnerabilities
CVE-2026-14245: miniOrange OTP Login authentication bypass in WordPress
- Impact: Unauthenticated attackers can generate a password-reset URL for any WordPress user, including administrators, and take over the account.
- Affected Systems: miniOrange OTP Login, Verification and SMS Notifications for WordPress up to and including
5.5.1; requires Ultimate Member Password Reset Form integration and non-phone-only reset configuration. - Immediate Action: Disable the Ultimate Member password reset integration if you use it, restrict public reset flows, and update or remove the plugin immediately.
- Mitigation: Apply the vendor fix as soon as available; if no patch is available, disable the plugin and review admin accounts and recent password resets.
CVE-2026-15158: Blocksy Companion arbitrary file upload
- Impact: Attackers may upload executable files and potentially achieve remote code execution.
- Affected Systems:
blocksy-companion-prowith both WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active; versions up to and including2.1.46. - Immediate Action: Remove or disable the premium plugin and the affected extensions until patched.
- Mitigation: Upgrade to a fixed release; audit uploads for suspicious
.phpand double-extension files such asshell.woff2.php.
CVE-2026-5955: BiEticaret SQL injection
- Impact: Remote attackers can inject SQL, exposing or altering database data and possibly taking over the application.
- Affected Systems: Inrove Software and Internet Services BiEticaret before
v3.3.57. - Immediate Action: Patch to
v3.3.57or later and restrict public access if you cannot update immediately. - Mitigation: Validate logs for unusual database errors and suspicious query patterns.
CVE-2026-47646: Dynamics 365 Customer Voice XSS
- Impact: Unauthorized attackers can inject scripts to spoof content or manipulate users.
- Affected Systems: Dynamics 365 Customer Voice.
- Immediate Action: Review exposed forms and responses, and apply Microsoft guidance as soon as it is published.
- Mitigation: Treat untrusted inputs as hostile; monitor for malicious payloads in survey fields and links.
CVE-2026-2342: ValeApp stored XSS
- Impact: Stored script injection can persist and execute for other users.
- Affected Systems: OceanicSoft ValeApp through
09072026. - Immediate Action: Isolate the app if public-facing and sanitize user-generated content.
- Mitigation: Apply vendor remediation; review for defacement, stolen sessions, and admin actions triggered from malicious content.
CVE-2026-47830: bosh-windows-stemcell-builder permission flaw
- Impact: Low-privilege users can overwrite system binaries and gain
SYSTEMon reboot. - Affected Systems: bosh-windows-stemcell-builder prior to
v2019.98. - Immediate Action: Upgrade immediately and check for tampering in
C:\bosh\service_wrapper.exeandC:\bosh\bosh-agent.exe. - Mitigation: Restrict local access and validate file integrity on affected hosts.
CVE-2026-5523: Divi Form Builder missing authorization
- Impact: Authenticated users with low privileges can change any account’s email and password, including administrators.
- Affected Systems: Divi Form Builder up to and including
5.1.8. - Immediate Action: Disable the plugin or remove user-editing forms until patched.
- Mitigation: Update promptly and review all admin and editor accounts for unauthorized changes.
CVE-2026-31985: Remote Collector TLS verification disabled
- Impact: Attackers can intercept sync traffic, steal tokens, and inject false data.
- Affected Systems: Remote Collector configurations generated via
n2os-tuiwhen upstream Guardian or CMC is used. - Immediate Action: Stop using the affected generated config and rotate any exposed sync tokens.
- Mitigation: Reconfigure with certificate verification enabled or move to a fixed configuration workflow.
CVE-2026-31984: Audit log resource exhaustion
- Impact: Unauthenticated attackers can fill disk space and disrupt service.
- Affected Systems: Audit logging functionality with no input size limit.
- Immediate Action: Rate-limit public endpoints and watch disk usage closely.
- Mitigation: Apply vendor limits or hotfixes; add upstream request size controls.
CVE-2026-1989: PAVO Pay trusted identifier bypass
- Impact: Attackers may bypass authorization by manipulating user-controlled keys.
- Affected Systems: PAVO Pay through
09072026. - Immediate Action: Restrict access to trusted identifier flows and review authorization logic.
- Mitigation: Patch as soon as available and audit for unauthorized account activity.
CVE-2026-47831: Weak password generation in bosh-windows-stemcell-builder
- Impact: Remote attackers may brute-force SSH logins due to weak randomness.
- Affected Systems: bosh-windows-stemcell-builder prior to
v2019.98. - Immediate Action: Rotate SSH credentials and upgrade immediately.
- Mitigation: Enforce stronger key-based access and monitor SSH failures.
CVE-2026-47840: UAA LDAP StartTLS certificate validation flaw
- Impact: A network attacker can steal LDAP credentials and forge group membership to gain admin scopes.
- Affected Systems: UAA prior to
v78.13.0; Cf-deployment prior tov56.2.0. - Immediate Action: Patch immediately and review LDAP transport settings.
- Mitigation: Ensure strict certificate validation is enforced across LDAP connections.
CVE-2026-15134: Simple Online Leave Management SQL injection
- Impact: Remote SQL injection may expose or alter leave-management data.
- Affected Systems: CodeAstro Simple Online Leave Management System 1.0,
/SimpleOnlineLeave/index.php. - Immediate Action: Remove public exposure and patch or replace the application.
- Mitigation: Sanitize input, review database logs, and hunt for exploitation attempts.
CVE-2026-15135: Online Food Order System SQL injection
- Impact: Attackers can inject SQL through food item update functions.
- Affected Systems: code-projects Online Food Order System 1.0,
/edit_food_items.php. - Immediate Action: Patch immediately and restrict access to admin functions.
- Mitigation: Validate server-side input and inspect for suspicious item changes.
CVE-2026-15137: Interview Management System SQL injection
- Impact: Remote attackers can manipulate database queries through the
IDparameter. - Affected Systems: code-projects Interview Management System 1.0,
\inc\classes\View.php. - Immediate Action: Take the system offline if exposed and apply fixes before re-enabling access.
- Mitigation: Review for data leakage and unauthorized record changes.
CVE-2026-8848: Popup Maker plugin authorization bypass
- Impact: Authenticated editors can install attacker-controlled plugins, leading to remote code execution.
- Affected Systems: Popup Maker up to and including
1.22.0; requires active Popup Maker Pro license and no existing Pro install. - Immediate Action: Disable plugin installation for non-admin users and update immediately.
- Mitigation: Review installed plugins for unknown additions and revoke suspicious tokens.
CVE-2026-15000: Connect Contact Form 7 and Mailchimp stored XSS
- Impact: Malicious scripts can execute when an administrator looks up a submitted email address.
- Affected Systems: Connect Contact Form 7 and Mailchimp up to and including
0.9.78.06. - Immediate Action: Patch immediately and warn admins not to inspect untrusted submissions until fixed.
- Mitigation: Clean stored form data and monitor admin sessions for suspicious activity.
CVE-2026-31982: SAML open redirect and redirect poisoning
- Impact: Attackers can redirect users to phishing pages and disrupt SAML sign-in flows.
- Affected Systems: SAML Single Sign-On functionality with insufficient redirect validation.
- Immediate Action: Disable or restrict SAML login entry points if you cannot patch quickly.
- Mitigation: Validate redirect targets strictly and clear cached SAML state after fixes.
What to Do Now
- Patch or disable exposed systems first: WordPress plugins, internet-facing apps, and any LDAP/SAML authentication components.
- Remove risky features temporarily: file uploads, public reset flows, plugin installation, and admin lookup tools.
- Rotate secrets: admin passwords, sync tokens, LDAP bind credentials, SSH credentials, and any session-bearing tokens.
- Search for compromise: unexpected admin accounts, new plugins, webshell-like uploads, altered emails, and suspicious redirects.
- Contain vulnerable hosts: isolate systems that cannot be patched today.
Verification steps: confirm versions against vendor release notes, validate that patches actually removed the vulnerable code paths, and test whether public endpoints are still reachable. Check logs for repeated password resets, unusual file uploads, SQL errors, and SAML redirect anomalies.
Monitoring recommendations: alert on new admin creation, plugin installs, outbound connections from web servers, changes to authentication settings, and unexpected disk growth from audit logs. For WordPress, watch for sudden password-reset activity and account email changes.
Related Resources
- Internal: Add your incident response note and patch tracker for July 9, 2026.
- Internal: Add a follow-up post on WordPress plugin exposure and SAML hardening.
- Official vendor advisories: miniOrange, Blocksy, Inrove Software, Microsoft, OceanicSoft, BOSH-Ecosystem, Divi Form Builder, UAA/Cf-deployment, CodeAstro, code-projects, Popup Maker, and the Connect Contact Form 7 and Mailchimp vendor notices.