CVE-2026-49774: RD Station WordPress Plugin Remote Code Injection (CVSS 9.9)
ID: 25b275fe-b4cb-5e4a-a316-f3e70453fdb0
STIX ID: report--25b275fe-b4cb-5e4a-a316-f3e70453fdb0
Feed Name: CosmicBytez Labs
Threat Score
**Executive Summary:** CVE-2026-49774 is a critical Remote File Inclusion / code injection vulnerability in the RD Station WordPress plugin (affecting versions through 5.6.0) that allows unauthenticated remote code execution (CVSS 9.9) on compromised hosts; the report provides technical details, attack flow, detection queries, impact assessment, and remediation guidance including patching, PHP hardening, and WAF rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
