Jul 19, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • WordPress plugin RCE/exploit activity: 6 CVEs flagged today.
  • 8 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2012-10019 Scribu Front-end Editor RCE

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Scribu Front-end Editor RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2015-10135 Eoxia Wpshop 2 RCE

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Eoxia Wpshop 2 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2015-10138 Lynton Reed Work The Flow File Upload RCE

  • CVSS 9.8
  • Internet-facing CMS deployments affected

New critical Lynton Reed Work The Flow File Upload RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2012-10019 CVSS 9.8

The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php...

CVE-2015-10135 CVSS 9.8

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpl...

CVE-2015-10138 CVSS 9.8

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQu...

CVE-2016-15043 CVSS 9.8

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php fil...

CVE-2025-29757 CVSS 9.4

An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a val...

CVE-2025-53770 CVSS 9.8

Microsoft SharePoint Deserialization of Untrusted Data

CVE-2025-7696 CVSS 9.8

The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Inject...

CVE-2025-7697 CVSS 9.8

The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object In...

View critical disclosures

cvelogic Threat Intelligence