← Back to Blog

Security News — 9 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 4 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 9 September 2026 · 9 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Recent CVEs09 Sep

CVE-2026-8615 — MEDIUM (CVSS 4.3)

CVSS 4.3 MEDIUM The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions…

Read at source →
CVEDatabase - Recent CVEs09 Sep

CVE-2026-85418

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the render…

Read at source →
CVEDatabase - Recent CVEs09 Sep

CVE-2026-85133

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to th…

Read at source →
CVEDatabase - Recent CVEs09 Sep

CVE-2026-85132

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule th…

Read at source →

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

← All blog posts