Skip to content
The Coolest Info

The Coolest Info

  • Cronos blockchain bridge suffers attack with over $12 million in crypto lossesJuly 31, 2026
  • SEC Sues Mining Automatic and Founder Over Alleged $22M Crypto Mining SchemeJuly 20, 2026
  • AI-Generated Fake nVidia Employee LinkedIn Profiles Surface in Hiring ScamsJuly 20, 2026
  • The Download: OpenAI unveils GPT-Red and heat pumps rise in the USJuly 19, 2026
  • The Download: perimenopause misinformation and China’s latest AI leapJuly 19, 2026
  • A bug in AWS has caused some customers’ bills to spike from a few cents to billions of dollarsJuly 19, 2026
  • There’s now an API for mainlining Trump’s Truth Social postsJuly 19, 2026
  • France doubles down on restricting access to PolymarketJuly 19, 2026
  • I replaced my space heater and ceiling fan with one Dyson applianceJuly 19, 2026
  • A 600-mile road trip (and data) proves EV charging doesn’t suck anymoreJuly 19, 2026
  • Kimi: Threat or menace?July 19, 2026
  • Troubling new details emerge on diabetes ouster controversyJuly 19, 2026
  • Will AI fix prior authorization—or make it worse?July 19, 2026
  • Surprise! Facial recognition smart locks are actually goodJuly 19, 2026
  • Google is open-sourcing its 3D emojiJuly 19, 2026
  • Google might not kneecap the Pixel 11a with an old processorJuly 19, 2026
  • The future of physical games is not looking greatJuly 19, 2026
  • US Marshals arrest the Tate brothers in MiamiJuly 19, 2026
  • UK Sentences Two Scattered Spider Hackers Over 29 Million Transport for London AttackJuly 18, 2026
  • Coca-Cola Halts Fairlife US Dairy Production After Ransomware AttackJuly 18, 2026
  • OpenSSL HollowByte Flaw Lets 11-Byte Payload Freeze Server MemoryJuly 18, 2026
  • 7-Zip 26.02 Fixes Critical RCE Flaw Exploitable With Malicious ArchivesJuly 18, 2026
  • WordPress Core wp2shell RCE Flaws Get Public Exploits, Patch NowJuly 18, 2026
  • Microsoft Patches Record 570 Security Flaws in July 2026 Patch TuesdayJuly 18, 2026
  • OkoBot Malware Framework Targets Crypto Wallet Seed Phrases From Trezor and Ledger UsersJuly 18, 2026
  • News
  • Crypto Predictions
The Coolest Info

The Coolest Info

  • News
  • Crypto Predictions
  • Home
  • 2026
  • June
  • 11
  • Security Advisory: Mirasvit Cache Warmer RCE and cPanel WP2 Auth Bypass Added to CISA KEV
  • Security Advisories

Security Advisory: Mirasvit Cache Warmer RCE and cPanel WP2 Auth Bypass Added to CISA KEV

The TeamJune 11, 2026June 12, 202602 mins

Critical WordPress Security Advisory – June 2026

Two WordPress-relevant vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog in recent weeks. Site administrators should review and take action immediately.

1. CVE-2026-45247 – Mirasvit Full Page Cache Warmer (Deserialization to Remote Code Execution)

  • Severity: Critical (CWE-502: Deserialization of Untrusted Data)
  • Added to KEV: June 3, 2026
  • Affected Product: Mirasvit Full Page Cache Warmer (WordPress plugin)
  • Attack Vector: Unauthenticated attacker supplies a crafted serialized PHP object via the CacheWarmer cookie
  • Impact: Full remote code execution on the WordPress server
  • Ransomware use: Not yet confirmed, but actively exploited in the wild

Recommended Action: If you use the Mirasvit Full Page Cache Warmer plugin, update to the latest patched version immediately. If a patch is not yet available, disable the plugin until one is released.

2. CVE-2026-41940 – cPanel/WHM and WP2 (WordPress Squared) Authentication Bypass

  • Severity: Critical (CWE-306: Missing Authentication for Critical Function)
  • Added to KEV: April 30, 2026 – Known ransomware campaign use confirmed
  • Affected Products: cPanel and WHM (WebHost Manager) and WP2 (WordPress Squared) by WebPros
  • Attack Vector: Unauthenticated remote attacker bypasses login flow to gain unauthorized control panel access
  • Impact: Full administrative access to hosting control panel and all managed WordPress sites
  • Ransomware use: CONFIRMED – Known ransomware campaigns are actively exploiting this

Recommended Action: If your hosting uses cPanel/WHM, ensure you are running the latest security update (April 28, 2026 or later). If you use WP2 (WordPress Squared), update to version 13.6.17 or later.

Additional Infrastructure CVEs to Monitor

While not directly WordPress-specific, the following high-severity CVEs in common web infrastructure components may affect your hosting environment:

  • CVE-2026-23631 – Redis Lua Scripting RCE (CVSS 8.8 HIGH)
  • CVE-2026-25243 – Redis RESTORE Memory Corruption RCE (CVSS 8.8 HIGH)
  • CVE-2026-33186 – gRPC-Go Authorization Bypass (CVSS 9.1 CRITICAL)
  • CVE-2026-33747 – BuildKit Arbitrary File Write and Code Execution (CVSS 8.2 HIGH)
  • CVE-2026-42578 through CVE-2026-42587 – Multiple Netty HTTP/DoS Vulnerabilities (CVSS 7.2 to 7.5 HIGH)

General Recommendations

  1. Audit all WordPress plugins – remove any unused or unmaintained plugins
  2. Ensure WordPress core, themes (including Newsup v5.4.3), and all plugins are up to date
  3. Verify your hosting provider has patched cPanel/WHM if applicable
  4. Review server-level software (Redis, Go runtime, OpenSSL) for pending updates
  5. Monitor the CISA KEV catalog for new additions

This advisory was generated by the Tyche automated security scanner. Data sources: CISA KEV (catalog version 2026.06.09), CIRCL CVE feed.

Tagged: Account Security advisory CVE-2026-11645 IKEv1 wordpress

Post navigation

Previous: OpenAI Bans Suspected Fake China-Linked Accounts Pushing Data Center Propaganda
Next: Security Advisory: Critical CVEs in WordPress Plugins, Themes, and Infrastructure — June 2026

Related News

Security Advisory: Critical CVEs in WordPress Plugins, Themes, and Infrastructure — June 2026

June 12, 2026June 12, 2026

Recent Posts

  • Cosmos Chain Vulnerability Yields Massive Losses for Nesa Token Holders Amidst Failed Exit Strategy
  • Fed Chair Kevin Warsh Kept Quiet for 3 Months. Jackson Hole Might Change That.
  • Connecticut sues Kalshi over sports event contracts in months-long legal feud
  • Tokenized deposits could raise US credit costs: Dallas Fed economists
  • Bitcoin ETF Inflows Decelerate to $232 Million Amid Sub-$80K Price Action

Recent Comments

No comments to show.

Archives

  • August 2026
  • July 2026
  • June 2026

Categories

  • Cross-Pillar
  • Cryptocurrency
  • Finance
  • Security
  • Security Advisories
  • Technology
  • Uncategorized
  • Crypto Predictions
Online Newspaper - News / Magazine WordPress Theme 2026.
Back To Top