2 vulnerabilities across 2 products scored HIGH or above on June 20, 2026.
- ๐ HIGH: 2
๐ [HIGH] wpmudev/branda_โwhite_label&_branding,_free_login_page_customizer
1 CVE | CVSS 3.1: 9.8 | AAS 11.6
cpe:2.3:a:wpmudev:branda_white_label_branding_free_login_page_customizer:*:*:*:*:*:*:*:*(< 3.4.30)
WPMU DEV Branda โ White Label & Branding plugin for WordPress versions up to and including 3.4.29 contains a critical privilege escalation vulnerability (CVE-2026-11551, CVSS 9.8) that allows unauthenticated attackers to reset any user’s password, including administrator accounts, due to improper identity validation during password changes. A proof-of-concept exploit is publicly available, making active exploitation highly likely. WordPress administrators running Branda should update immediately to a patched version or disable the plugin until a fix is applied, and audit admin accounts for signs of unauthorized password changes or suspicious logins.
- ๐ CVE-2026-11551 (CVSS 3.1: 9.8)
๐ [HIGH] joomshaper.net/sp_lms_extension_for_joomla
1 CVE | CVSS 4.0: 9.5 | AAS 9.8
cpe:2.3:a:joomshaper.net:sp_lms_extension_for_joomla:*:*:*:*:*:*:*:*
JoomShaper SP LMS extension for Joomla versions 1.0.0 through 4.1.3 is affected by a critical insecure deserialization vulnerability (CVE-2026-48909, CVSS 9.5) that allows unauthenticated remote attackers to execute arbitrary code on the server by supplying crafted cookie data. This vulnerability is considered readily exploitable and poses an immediate risk to any Joomla site running the affected extension. Administrators should upgrade SP LMS to version 4.1.4 or later immediately, and review server logs for signs of compromise, particularly unexpected outbound connections or unauthorized file modifications.
- ๐ CVE-2026-48909 (CVSS 4.0: 9.5)