VYPR
AI Brief2026-08-24· generated Aug 24, 2026

WordPress Plugins, Linux Kernel, and Libraries Hit By Critical Flaws

Critical vulnerabilities disclosed in WordPress plugins, Linux kernel, justhtml library, Joomla extension, and Comfast router.

Multiple WordPress plugins are affected by critical vulnerabilities, including SmilePass Selfie Login (through 1.0.2), Social Login & Sharing buttons with Analytics By SoClever (through 1.2.0), and WP Social Media Login (through 1.0.6). These plugins fail to properly authenticate users, allowing unauthenticated attackers to log in as any user, including administrators. The Slider Hero with Video Background, Animation plugin (before 9.1.3) also suffers from similar authorization and nonce check flaws, alongside an unescaped stored setting that could lead to cross-site scripting. As Vypr Intelligence reported, these issues pose a significant risk to WordPress sites.

The Linux kernel has seen a flurry of critical vulnerabilities addressed, primarily focusing on network and storage subsystems. CVE-2026-74474, CVE-2026-72299, CVE-2026-72191, CVE-2026-72084, CVE-2026-72069, CVE-2026-72065, CVE-2026-72041, CVE-2026-68159, CVE-2026-68136, CVE-2025-39758, and CVE-2026-74476 all involve crucial validation, sanitization, or protection mechanisms within various kernel components like vxlan, tipc, ntfs3, scsi, RCU, mana, espintcp, libceph, net: gro, RDMA/siw, and veth. These fixes are essential for maintaining system stability and security against potential exploits targeting network packet handling and data integrity.

The justhtml library, specifically versions before 1.15.0, 1.12.0, and 1.16.0, contains several critical vulnerabilities related to URL sanitization and HTML serialization. CVE-2026-5388 and CVE-2026-8445 highlight issues in URL cleaning and Markdown conversion, potentially allowing for script injection. CVE-2026-7808 points to broader HTML sanitization bypasses that could lead to cross-site scripting by allowing dangerous content to persist. These flaws in a widely used HTML parsing and sanitization library are a significant concern for web application security.

A critical SQL injection vulnerability (CVE-2026-76571) has been discovered in the Joomla Fabrik extension, specifically in versions prior to 4.7.2. The issue lies in the list filter's condition parameter, which is directly concatenated into the WHERE clause of SQL queries without proper sanitization. This allows unauthenticated attackers to inject malicious SQL code, potentially leading to data breaches or complete database compromise.

The Comfast CF-N1-S router, running firmware version 2.6.0.1, is affected by a critical vulnerability (CVE-2026-78050) in its web management interface. A flaw in the sub_41AD7C function within the /cgi-bin/mbox-config endpoint allows for manipulation of the 'timestr' argument, potentially leading to command injection or other severe system compromises on the affected network devices.

Synthesized by Vypr AI
WordPress Plugins, Linux Kernel, and Libraries Hit By Critical Flaws · VYPR