{"id":7036472,"date":"2026-08-10T09:53:27","date_gmt":"2026-08-10T09:53:27","guid":{"rendered":"https:\/\/peraltafinancing.com\/business\/internet-business\/weekly-cybersecurity-summary-31-july-to-6-august-2026\/"},"modified":"2026-08-10T09:53:27","modified_gmt":"2026-08-10T09:53:27","slug":"weekly-cybersecurity-summary-31-july-to-6-august-2026","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=7036472","title":{"rendered":"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"fws_6a799f96f2ec8\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row top-level\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-top: 3%;margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f97012be\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering five issues: two critical privilege escalations affecting cPanel &amp; WHM (including its bundled Exim mail server and the ConfigServer firewall it now distributes), two WordPress plugin vulnerabilities that could lead to full site takeover, and a pair of Linux kernel local-root flaws affecting shared and VPS hosting platforms.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97015cd\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f97016fd\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[Critical] cPanel &amp; WHM August Security Release (CVE-2026-58048, CVE-2026-58047, GCVE-25-2026-07-45-3)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>cPanel &amp; WebPros published a coordinated security release on 4 August 2026 covering three separate issues found in cPanel &amp; WHM and its bundled Exim mail transfer agent. The most serious, CVE-2026-58048, is a privilege escalation in the database management system: when a database is renamed, cPanel does not preserve the connection&#8217;s SQL mode, which allows SQL statements to execute in a root database context instead of the account holder&#8217;s own. Anyone with a cPanel account and access to the MySQL or MariaDB feature could use this to run database commands with full administrative privileges. The same release fixes CVE-2026-58047, an HTTP request-smuggling flaw in cpsrvd that, under limited conditions, can leak the credentials of other account holders on a shared server, and a separate local privilege escalation in Exim&#8217;s .forward pipe-transport handling that lets a Team User sub-account escalate to the primary cPanel account.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9701f99\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>All supported versions of cPanel &amp; WHM prior to the August 2026 builds, and WP Squared. The Exim issue affects sites using cPanel&#8217;s default mail stack with pipe-transport forwarding enabled.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>WHM 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32; WP Squared 138.1.6; Exim 4.99.5.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>9.4 (CVE-2026-58048, database privilege escalation); 5.6 (CVE-2026-58047, request smuggling); not yet scored (Exim local privilege escalation).<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97027f3\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What this means for you:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>On shared hosting, this is patched at the platform level, so most website owners don&#8217;t need to take any action themselves. On a self-managed VPS or dedicated server running cPanel &amp; WHM, the update needs applying directly, and administrators should check whether cpsrvd_keepalives_disabled=1 is set as an interim workaround for the request-smuggling issue if an immediate update isn&#8217;t possible.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97029c3\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Update WHM to the builds listed above as soon as possible; verify Exim is running 4.99.5 or later on any self-managed server.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9702d10\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f9702e6b\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[Critical] cPanel CSF (ConfigServer Security &amp; Firewall) Root Access Vulnerabilities<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>cPanel published a further advisory on 5 August 2026, separate from the release above, covering multiple vulnerabilities in ConfigServer Security &amp; Firewall (CSF), the firewall and login\/intrusion detection package installed on the large majority of cPanel &amp; WHM servers. CSF is now maintained as cPanel&#8217;s own fork following the original developer&#8217;s shutdown in 2025, so this falls under the same cPanel security channel as the database and Exim issues above. cPanel&#8217;s advisory is brief: it states only that the flaws &#8220;could allow an attacker to gain root access,&#8221; without publishing a CVE identifier, a CVSS score, or detail on whether exploitation requires local access or can be triggered remotely. Because CSF runs with root privileges to manage firewall rules and monitor logs, any flaw that lets attacker-influenced input reach it is significant regardless of the missing detail.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f970309e\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>CSF 16.20-1 and earlier, on any cPanel &amp; WHM server running the ConfigServer firewall.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>CSF 16.30-1. Update by running dnf clean metadata followed by \/scripts\/update-packages.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>Not yet assigned. No CVE identifier had been published at the time of writing; this is a single-source advisory pending further technical detail.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9703503\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>On shared hosting, this is a platform-level fix applied by us rather than something website owners need to act on. On a self-managed VPS or dedicated server running cPanel &amp; WHM with CSF installed, treat this as a priority update given the stated root-access impact, even though the exploitation path hasn&#8217;t been detailed publicly yet.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f970370d\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Update CSF to 16.30-1 or later on all cPanel &amp; WHM servers as soon as possible; there is no alternative mitigation published.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9703a59\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f9703b7f\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[High] WordPress Plugin: POUCO Import Users Unauthenticated Admin Takeover (CVE-2026-16256)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Researchers disclosed on 2 August 2026 that the POUCO Import Users plugin for WordPress performs no capability or nonce checks on the AJAX actions it exposes for creating and updating WordPress accounts. Because the plugin also trusts a role value supplied directly by the requester, an unauthenticated attacker can call the account-creation endpoint and simply specify &#8220;administrator&#8221; as the role, creating a fully privileged account without ever logging in. One vulnerability tracker classified this as an &#8220;Info&#8221; severity issue with a CVSS score of 0, which understates the real-world risk considerably: in practice this is a straightforward path to complete site takeover.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9703dbe\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>POUCO Import Users plugin, all versions up to and including 1.0.0.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>No patched release had been published at the time of writing; sites running the plugin should deactivate it until a fix is confirmed available.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>Logged as 0 (Info) by one tracker; real-world impact is consistent with a critical, unauthenticated full site takeover.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f970422d\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>On shared hosting, check whether any of your sites have this plugin active and deactivate it as a precaution. On a VPS or dedicated server where you manage WordPress yourself, the same applies, and it&#8217;s worth checking the WordPress admin user list for any accounts you don&#8217;t recognise.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97043e4\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Deactivate and remove the POUCO Import Users plugin until an official fix is released; audit administrator accounts for unfamiliar entries.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f970473c\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f970484b\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[High] WordPress Plugin: NEX-Forms Ultimate Form Builder Lite Arbitrary File Deletion (CVE-2026-15450)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Disclosed on 2 August 2026, this vulnerability sits in the NEX-Forms \u2013 Ultimate Form Builder Lite plugin&#8217;s delete_file() AJAX handler, which reads a file path from the database and passes it straight to PHP&#8217;s unlink() function without validating it against the real site path, a safe filename check, or an allow-list. A separate handler, insert_record(), lets an authenticated user store an arbitrary value in the database column the delete handler later trusts. Combined, this lets an attacker with admin-level access delete arbitrary files on the server, including wp-config.php, which can be used to force the site into a broken or reinstallable state.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9704aa3\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>NEX-Forms \u2013 Ultimate Form Builder Lite, versions up to and including 9.2.3.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>A patched release beyond 9.2.3 is available; update via the WordPress plugin repository.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>8.1 (High), authenticated, admin-level access required.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9704f00\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Exploitation requires an admin-level account already, so this is primarily a risk where an attacker has already compromised a lower-privilege account or is an insider. Shared hosting website owners should update the plugin at the next opportunity; VPS and dedicated server administrators managing multiple WordPress installs should check all of them for the plugin.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97050b5\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Update NEX-Forms to the latest version beyond 9.2.3 on all affected sites.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97053e7\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f9705525\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[High] Linux Kernel Local-Root Vulnerabilities: OVSwrap and net\/sched Use-After-Free (CVE-2026-64531, CVE-2026-53264)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Two unrelated Linux kernel local privilege escalation bugs came to wider attention this week. OVSwrap (CVE-2026-64531), disclosed on 28 July 2026 by researcher Asim Viladi Oglu Manizada, is a length-field wraparound in how the Open vSwitch kernel datapath converts userspace flow actions into internal Netlink attributes; an unprivileged local user who can create a user and network namespace can corrupt kernel memory and gain root, with no administrator interaction required. Separately, CVE-2026-53264 is a use-after-free race in the kernel&#8217;s network traffic-control code (net\/sched\/act_api.c), where an action can be looked up and its reference count raised under RCU read protection while a concurrent delete path frees the same object without waiting for the RCU grace period. This bug was patched upstream back in June, but gained fresh urgency on 28 July 2026 when STAR Labs published a working, AI-assisted root exploit against CentOS Stream 9.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9705770\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>OVSwrap affects default configurations of AlmaLinux, CentOS Stream, Debian 12\/13, Rocky Linux, and Ubuntu 22.04\/24.04. The net\/sched flaw affects the same kernel family and is present on any unpatched build with unprivileged user namespaces enabled.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>OVSwrap: kernel 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40 or 7.1.5 and later. net\/sched: kernel 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13 and later (fixed upstream since 1 June 2026).<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>7.8 (High) for both \u2014 local attack vector, low complexity, low privileges required, no user interaction.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9705bd6\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Both flaws require local access, so the direct risk to website owners on well-isolated shared hosting is limited. The more significant exposure is on VPS and dedicated servers, particularly where multiple untrusted users or containers share a kernel: an attacker who gains any foothold, even a low-privilege one, can use either bug to reach root. For the net\/sched bug specifically, check you&#8217;re already on a patched kernel rather than treating it as a brand-new vulnerability, since the underlying fix has been available since June; what&#8217;s new is a working public exploit.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9705dd1\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Apply the latest kernel update for your distribution and reboot; where immediate patching isn&#8217;t possible, disable unprivileged user namespaces as an interim mitigation and verify KernelCare or equivalent live-patching is current.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f970612e\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f9706230\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>How to Check If Your Site Has Been Compromised<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Because two of this week&#8217;s issues (the POUCO Import Users takeover and the NEX-Forms file deletion flaw) can leave visible signs on a website, it&#8217;s worth running through the following checks:<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9706406\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-ul\" data-list-icon=\"icon-salient-thin-line\" data-animation=\"false\" data-animation-delay=\"0\" data-color=\"accent-color\" data-spacing=\"default\" data-alignment=\"left\">\n<ul>\n<li>Review the WordPress admin user list for any accounts you don&#8217;t recognise, especially ones created recently.<\/li>\n<li>Check whether wp-config.php or other core files are missing or have been recently modified or recreated.<\/li>\n<li>Look through your site&#8217;s file manager or FTP logs for unexpected file deletions around early August 2026.<\/li>\n<li>Check installed plugins for POUCO Import Users or NEX-Forms \u2013 Ultimate Form Builder Lite, and confirm their versions.<\/li>\n<li>Review recent database user or MySQL\/MariaDB privilege changes if you manage your own cPanel account with database access.<\/li>\n<li>If anything looks unfamiliar, change your WordPress and hosting account passwords and get in touch with support.<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9706655\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f9706759\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Frequently Asked Questions<\/h3>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f97068be\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>Do I need to do anything if I&#8217;m on shared hosting?<\/h4>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> In most cases the underlying platform-level issues (the cPanel and kernel items) are handled for you. The WordPress plugin issues depend on what you&#8217;ve installed on your own site, so it&#8217;s worth checking whether you use either affected plugin. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9706a33\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>I run a VPS or dedicated server. What should I prioritise?<\/h4>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> Patch the cPanel &amp; WHM builds and the kernel update first, since both affect the underlying platform rather than an individual website. Then work through any WordPress installs you manage for the two plugin issues. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9706b89\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>Are any of these being actively exploited right now?<\/h4>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> There&#8217;s no confirmed evidence of active exploitation for the cPanel or WordPress plugin issues at the time of writing. The net\/sched kernel bug has a working public proof-of-concept exploit, which increases the urgency of confirming you&#8217;re on a patched kernel even though the underlying flaw was fixed back in June. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9706d19\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>Why does the POUCO Import Users bug show a CVSS score of 0?<\/h4>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> Some vulnerability trackers score based on strict technical criteria that don&#8217;t always capture real-world impact well, particularly for plugins with a small install base. In this case the scoring undersells the risk: the practical outcome is a full, unauthenticated site takeover, which we treat as high priority regardless of the numeric score. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9706e88\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>The CSF firewall issue has no CVE number. Is it real?<\/h4>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> Yes. It&#8217;s published directly on cPanel&#8217;s own security advisory pages, which is the same channel used for the other cPanel items in this summary. Some advisories are published before a CVE identifier or CVSS score has been assigned, particularly when they&#8217;re only hours old. We treat the advisory as genuine and act on it rather than waiting for a CVE number, and we&#8217;ll add the technical detail here once the vendor publishes it. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9707018\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>Does any of this affect email specifically?<\/h4>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> Yes, indirectly. The Exim local privilege escalation fixed alongside the cPanel release affects sites using cPanel&#8217;s default mail stack with pipe-transport forwarding configured, so mail administrators on self-managed servers should confirm Exim has been updated to 4.99.5 or later. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6a799f9707335\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div style=\"margin-bottom: 3%\" class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6a799f9707447\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h4>Need Help? Get in Touch<\/h4>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>If you have questions about any of the issues covered this week, or you&#8217;re not sure whether your website or server is affected, our support team is here to help.<\/p>\n<\/p><\/div>\n<\/div>\n<div class=\"nectar-fancy-ul\" data-list-icon=\"icon-salient-thin-line\" data-animation=\"false\" data-animation-delay=\"0\" data-color=\"accent-color\" data-spacing=\"default\" data-alignment=\"left\">\n<ul>\n<li>Raise a support ticket via the Customer Area at heartinternet.uk<\/li>\n<li>Speak to us on live chat, Monday to Friday, 09:30\u201316:00<\/li>\n<li>Browse our knowledge base at heartinternet.uk\/support<\/li>\n<\/ul><\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>We&#8217;re always happy to talk through anything that&#8217;s unclear, so don&#8217;t hesitate to get in touch.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<p>The post <a href=\"https:\/\/www.heartinternet.uk\/blog\/weekly-cybersecurity-summary-31-july-to-6-august-2026\/\">Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026<\/a> appeared first on <a href=\"https:\/\/www.heartinternet.uk\/blog\">Heart Internet<\/a>.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering five issues: two critical privilege escalations affecting cPanel &amp; WHM (including its bundled Exim mail [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":362843,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[95],"tags":[5427,15439,5762,4028,6039],"dealstore":[],"offerexpiration":[],"class_list":["post-7036472","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet-business","tag-august","tag-cybersecurity","tag-july","tag-summary","tag-weekly"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026 - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=7036472\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026 - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering five issues: two critical privilege escalations affecting cPanel &amp; WHM (including its bundled Exim mail [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=7036472\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T09:53:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=7036472#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=7036472\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026\",\"datePublished\":\"2026-08-10T09:53:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7036472\"},\"wordCount\":2118,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=7036472#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp\",\"keywords\":[\"August\",\"Cybersecurity\",\"July\",\"Summary\",\"Weekly\"],\"articleSection\":[\"Internet Business\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=7036472#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=7036472\",\"url\":\"https:\/\/fivemor.com\/?p=7036472\",\"name\":\"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026 - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7036472#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=7036472#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp\",\"datePublished\":\"2026-08-10T09:53:27+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=7036472#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=7036472\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=7036472#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp\",\"width\":1000,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=7036472#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026 - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=7036472","og_locale":"en_US","og_type":"article","og_title":"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026 - Som2ny Network","og_description":"The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering five issues: two critical privilege escalations affecting cPanel &amp; WHM (including its bundled Exim mail [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=7036472","og_site_name":"Som2ny Network","article_published_time":"2026-08-10T09:53:27+00:00","og_image":[{"width":1000,"height":1000,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp","type":"image\/webp"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=7036472#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=7036472"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026","datePublished":"2026-08-10T09:53:27+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=7036472"},"wordCount":2118,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=7036472#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp","keywords":["August","Cybersecurity","July","Summary","Weekly"],"articleSection":["Internet Business"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=7036472#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=7036472","url":"https:\/\/fivemor.com\/?p=7036472","name":"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026 - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=7036472#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=7036472#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp","datePublished":"2026-08-10T09:53:27+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=7036472#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=7036472"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=7036472#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/08\/placeholder.webp.webp","width":1000,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=7036472#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Weekly Cybersecurity Summary \u2014 31 July to 6 August 2026"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7036472","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7036472"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7036472\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/362843"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7036472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7036472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7036472"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=7036472"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=7036472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}