CYBERHAWK / CVE / CVE-2026-2554

CVE-2026-2554

WCFM WordPress Plugin

HIGH CVSS 8.1 vibe

The flaw

Insecure direct object reference allows arbitrary user deletion.

What to do

Update to version 6.7.26 or later

▸ Scan my repo for CVE-2026-2554

References

First seen 2026-05-08 · Tracked by PickBits CyberHawk · Weekly CVE digest