
CVE-2026-19598
Custom Content Types and Fields plugin for WordPress
authentication-authorizationexploitationvulnerability-analysis+2
1

Custom Content Types and Fields plugin for WordPress

Self-hosted identity management platform providing WebAuthn passkeys, OAuth2/OIDC SSO, SSH key distribution, RADIUS and LDAP integration for modern…

Exploit for CVE-2026-29000, a JWT authentication bypass in pac4j-jwt via JWE-wrapped PlainJWT, allowing token forgery and privilege escalation.

CVE-2026-23760 - An authentication bypass via password reset API in SmarterMail.