<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔥 HIGH severity: CVE-2026-6518 affects niteo CMP – Coming Soon &amp;amp; Maintenance Plugin (≤4.1.16).]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f525.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--fire" style="height:23px;width:auto;vertical-align:middle" title="🔥" alt="🔥" /> HIGH severity: CVE-2026-6518 affects niteo CMP – Coming Soon &amp; Maintenance Plugin (≤4.1.16). Authenticated Admins can trigger RCE via malicious ZIP uploads. No patch yet — restrict admin access &amp; monitor logs. More: <a href="https://radar.offseq.com/threat/cve-2026-6518-cwe-434-unrestricted-upload-of-file--f3d41796" rel="nofollow noopener"><span>https://</span><span>radar.offseq.com/threat/cve-20</span><span>26-6518-cwe-434-unrestricted-upload-of-file--f3d41796</span></a> <a href="https://infosec.exchange/tags/OffSeq" rel="tag">#<span>OffSeq</span></a> <a href="https://infosec.exchange/tags/WordPress" rel="tag">#<span>WordPress</span></a> <a href="https://infosec.exchange/tags/RCE" rel="tag">#<span>RCE</span></a> <a href="https://infosec.exchange/tags/Vuln" rel="tag">#<span>Vuln</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/428/428/963/482/077/original/7686d0e7fbbf17fb.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/eae6d40c-80c1-4712-b246-1d457f5c55f3/high-severity-cve-2026-6518-affects-niteo-cmp-coming-soon-amp-maintenance-plugin-4.1.16-.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:53:50 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/eae6d40c-80c1-4712-b246-1d457f5c55f3.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 19 Apr 2026 00:00:38 GMT</pubDate><ttl>60</ttl></channel></rss>