
CVE-2026-41940
CVE-2026-41940
authentication-authorizationcommand-and-controlexploitation+5

CVE-2026-41940

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

Exploit for CVE-2024-10793: stored XSS in WP Activity Log plugin. Includes a detection script and a shell-based exploit for unauthenticated attackers.

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated