NVD disclosure day

Published threat advisories for September 5, 2026

CVE advisoryCRITICAL

CVE-2026-83627

Hummingbird WordPress Plugin Remote Code Execution via Debug Log.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Hummingbird WordPress plugin could allow unauthenticated attackers to execute arbitrary PHP code. This occurs because a security check is bypassed, allowing malicious code to be written into a web-accessible log file if specific debug logging settings are enabled. This could lead to a full websit

CVE advisoryCRITICAL

CVE-2026-13447

Mstore Api WordPress Plugin JWT Forgery Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Mstore Api plugin for WordPress has a critical vulnerability where missing cryptographic signature verification allows unauthenticated attackers to forge authentication tokens. This enables them to impersonate any phone number, potentially leading to unauthorized access to existing accounts or the creation of new o

CVE advisoryCRITICAL

CVE-2026-52777

YesWiki PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated PHP object injection vulnerability exists in YesWiki prior to version 4.6.6, allowing attackers to inject objects via BazarImportAction. This could lead to unauthorized code execution and compromise of system and user data. Administrators should confirm if their YesWiki instances are affected and apply

CVE advisoryCRITICAL

CVE-2026-52766

YesWiki Unauthenticated Arbitrary Page Deletion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the YesWiki system allows any user with write access to permanently delete arbitrary wiki pages due to a missing authorization check in the comment erasure action. This could lead to the loss of critical information, including administrative and user-owned content. The issue has been addressed in ver