Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-912'

View all threats tagged with 'cwe-912'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-912

Threats Tagged 'cwe-912'

Click on any threat for detailed analysis and mitigation recommendations

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated… (CVE-2026-17032)CVE-2026-17032
0

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

Join the discussion
CVE-2026-14812: CWE-912 Hidden Functionality in Premium SEOCVE-2026-14812
0

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

Join the discussion
CVE-2026-11976: CWE-912 Hidden Functionality in MonsterInsights ProCVE-2026-11976
0

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.

Join the discussion
CVE-2026-18191: CWE-912 Hidden Functionality in Vacron VIN-DS783E-E6CVE-2026-18191
0

Vacron VIN-DS783E-E6 contains a critical hidden functionality vulnerability (CWE-912) that allows unauthenticated remote attackers to access a concealed function and obtain administrator credentials. This vulnerability has a CVSS 4.0 score of 9.3, indicating high severity and ease of exploitation without user interaction or privileges. No patch or official remediation guidance is currently available from the vendor.

Join the discussion
CVE-2026-4769: CWE-912 Hidden Functionality in WAGO 0765-110x/0100-0000CVE-2026-4769
0

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.

Join the discussion
CVE-2026-12685: CWE-912 Hidden Functionality in escortwpCVE-2026-12685
0

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-912
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses