Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yasin

#25931de 53,633
9.8CVSS total
Vulnerabilidades · 1
PT-2026-46208
9.8
2026-06-04
Framework · Hybrid Composer · CVE-2019-25738
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc ajax save option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc ajax save option to enable user registration and set the default role to administrator, enabling account takeover.