High severity7.2NVD Advisory· Published May 14, 2026· Updated May 14, 2026
CVE-2026-3718
CVE-2026-3718
Description
The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator visits the plugin's connection management page with debug parameters.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
35- Russian hackers turn Kazuar backdoor into modular P2P botnetBleepingComputer · May 16, 2026
- PoC Code Published for Critical NGINX VulnerabilitySecurityWeek · May 16, 2026
- Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent AccessThe Hacker News · May 15, 2026
- Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid EvolutionBleepingComputer · May 15, 2026
- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- 18-year-old NGINX vulnerability allows DoS, potential RCEBleepingComputer · May 14, 2026
- 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCEThe Hacker News · May 14, 2026
- Browser Run: now running on Cloudflare Containers, it’s faster and more scalableCloudflare Blog · May 13, 2026
- State-sponsored actors, better known as the friends you don’t wantCisco Talos Intelligence · May 12, 2026
- The Good, the Bad and the Ugly in Cybersecurity – Week 19SentinelOne Labs · May 8, 2026
- Helping North Korean IT remote workers is becoming a fast track to prisonHelp Net Security · May 8, 2026
- Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State HackingSecurityWeek · May 7, 2026
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News · May 7, 2026
- Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code ExecutionUnit 42 · May 7, 2026
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCEThe Hacker News · May 5, 2026
- The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1)Unit 42 · May 2, 2026
- Introducing Dynamic Workflows: durable execution that follows the tenantCloudflare Blog · May 1, 2026
- That AI Extension Helping You Write Emails? It’s Reading Them FirstUnit 42 · Apr 30, 2026
- New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATsThe Hacker News · Apr 29, 2026
- VECT: Ransomware by design, Wiper by accidentCheck Point Research · Apr 28, 2026
- Parsing Agentic Offensive Security's Existential ThreatDark Reading · Apr 27, 2026
- Crime crew impersonates help desk, abuses Microsoft Teams to steal your dataThe Register Security · Apr 25, 2026
- Tropic Trooper APT Takes Aim at Home Routers, Japanese TargetsDark Reading · Apr 24, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)Wordfence Blog · Apr 23, 2026
- Making Rust Workers reliable: panic and abort recovery in wasm‑bindgenCloudflare Blog · Apr 22, 2026
- Orchestrating AI Code Review at scaleCloudflare Blog · Apr 20, 2026
- The AI engineering stack we built internally — on the platform we shipCloudflare Blog · Apr 20, 2026
- Shared Dictionaries: compression that keeps up with the agentic webCloudflare Blog · Apr 17, 2026
- The Good, the Bad and the Ugly in Cybersecurity – Week 16SentinelOne Labs · Apr 17, 2026
- Introducing Flagship: feature flags built for the age of AICloudflare Blog · Apr 17, 2026
- Agents that remember: introducing Agent MemoryCloudflare Blog · Apr 17, 2026
- US Nationals Jailed for Operating Fake Remote Worker Laptop Farms for North KoreaInfosecurity Magazine · Apr 16, 2026
- Artifacts: versioned storage that speaks GitCloudflare Blog · Apr 16, 2026
- How AI Assistants are Moving the Security GoalpostsKrebs on Security · Mar 8, 2026
- Siemens SIMATICCISA Alerts