CVE-2026-11563

cvss 9.6

A basic WordPress plugin flaw lets any logged-in user delete critical server files and hijack the entire website.

Patch now

why it matters — synthesized by an LLM from the sources below

signal timeline

Nothing is referencing this right now. Feeds are snapshots of the present, so a quiet timeline means quiet today — not that nothing ever happened.

first seen 16d ago · last seen 16d ago

intelyard daily

One short email each weekday: what mattered in tech, written from source data and checked by a human. No account needed, one-click unsubscribe, and we never sell or share the address.