SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19225

MEDIUM · CVSS 6.6 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Defender Security plugin for WordPress prior to version 6.2.0 is vulnerable as it fails to restrict a critical network-wide setting to only network administrators, enabling any site administrator within a multisite environment to execute arbitrary code across the entire network. This flaw poses a significant risk of unauthorized access and potential compromise of all sites within the network. WordPress multisite administrators and security teams should prioritize this vulnerability to safeguard their installations.

CVE
CVE-2026-19225
Severity
MEDIUM
CVSS
6.6
EPSS
0.29%
WordPress

Original NVD Description

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.