Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryopen-source-dependency-vulnerability

Multiple CMS Plugin Vulnerabilities: WordPress CVEs and Joomla Novarain/Tassos Framework Flaws

Updated 3mo agoFirst seen Feb 19, 20263 sources

Three newly described WordPress plugin vulnerabilities affect ShopLentor, Advanced AJAX Product Filters, and WP Maps. CVE-2026-1714 allows unauthenticated email relay abuse in ShopLentor (<= 3.3.2) via the woolentor_suggest_price_action AJAX endpoint due to missing validation of parameters such as send_to and product_title; the wlemail parameter can be abused for CRLF injection to control sender details, enabling spam/phishing relay through the victim site. CVE-2026-1426 is a PHP object injection issue in Advanced AJAX Product Filters (<= 3.1.9.6) reachable by authenticated users (Author+) through deserialization of untrusted input in shortcode_check within a Live Composer compatibility layer; impact depends on the presence of a usable POP chain in another installed plugin/theme and requires the Live Composer plugin to be installed and active. CVE-2025-12062 affects WP Maps (<= 4.8.6) and enables authenticated (Subscriber+) limited local file inclusion via fc_load_template, potentially leading to sensitive data exposure or code execution in scenarios where attacker-controlled .html content can be uploaded and then included.

Separately, Joomla sites using the Novarain/Tassos Framework (plg_system_nrframework) face critical issues enabling unauthenticated file read, file deletion, and SQL injection, which can be chained toward administrator takeover and potentially persistent RCE. The reported weaknesses stem from an AJAX handler that processes task=include without sufficient hardening, allowing attackers to reach internal classes implementing onAjax and abuse gadget-like behaviors (e.g., CSV loading for arbitrary file read, a remove action for path deletion, and attacker-influenced query construction for SQL injection). The risk propagates through multiple popular Tassos extensions that bundle the framework (including Convert Forms, EngageBox, Google Structured Data, Advanced Custom Fields, and Smile Pack), and remediation requires applying vendor updates for affected releases.

Share:
Multiple CMS Plugin Vulnerabilities: WordPress CVEs and Joomla Novarain/Tassos Framework Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 18, 20264mo ago

Advanced AJAX Product Filters object injection disclosed as CVE-2026-1426

A PHP object injection vulnerability affecting Advanced AJAX Product Filters versions through 3.1.9.6 was disclosed. Authenticated Author-level users or higher can exploit unsafe deserialization in the shortcode_check function, with possible file deletion, data access, or code execution if a usable POP chain exists and Live Composer is active.

ShopLentor email relay flaw disclosed as CVE-2026-1714

A vulnerability in ShopLentor versions through 3.3.2 was disclosed that allows unauthenticated attackers to abuse the woolentor_suggest_price_action AJAX endpoint to send arbitrary emails. The flaw can turn vulnerable sites into open email relays for spam or phishing, including sender-address manipulation via CRLF injection.

Feb 17, 20264mo ago

WP Maps LFI vulnerability disclosed as CVE-2025-12062

A local file inclusion vulnerability affecting WP Maps plugin versions through 4.8.6 was disclosed. Authenticated users with Subscriber-level access or higher can abuse the fc_load_template function to include arbitrary .html files, potentially leading to sensitive data access or code execution.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Affected products
3 linked
WordpressElementorWoocommerce
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.