● Daily security briefing
Saturday, July 11, 2026
On July 11, 2026, there were no new advisories from CERT/PSIRT, but 78 CVEs were published, with several notable vulnerabilities emerging. Among the critical vulnerabilities, CVE-2026-61447 in PraisonAI allows for remote code execution, while CVE-2026-61445 and CVE-2026-60090 present significant risks with arbitrary file write and command execution issues. Additionally, several high-severity vulnerabilities affecting WordPress plugins were reported, including CVE-2026-13756, CVE-2026-2354, and CVE-2026-14262, all of which could lead to privilege escalation or arbitrary file uploads. Security teams should prioritize addressing these vulnerabilities to mitigate potential threats.
3 critical9 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-61447CVSS 10PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restric
- criticalCVE-2026-61445CVSS 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM
- criticalCVE-2026-60090CVSS 9.8PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keys
- highCVE-2026-13756CVSS 8.8The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key valida
- highCVE-2026-2354CVSS 8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all v
- highCVE-2026-14262CVSS 8.8The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and inclu
- highCVE-2025-6784CVSS 8.8The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin n
- highCVE-2026-13353CVSS 8.8The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.
- highCVE-2026-15155CVSS 8.8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all ve
- highCVE-2026-1359CVSS 8.8The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() functio
- highCVE-2026-61426CVSS 8.6PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET
- highCVE-2026-61429CVSS 8.5PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting