Skip to main content
Back to Blog
24 June 2026, byZebrabyte Breaches and incidents

Security Warning: Critical vulnerabilities inWordPressplugins (CVE-2026-11551, CVE-2026-12416, CVE-2026-12417)

Security Warning: Critical vulnerabilities inWordPressplugins (CVE-2026-11551, CVE-2026-12416, CVE-2026-12417)

You need to urgently update theWordPressplugins to prevent account takeover attacks and escalating privileges Critical vulnerabilities in ZBTKEEP plugins1

Critical Vulnerabilities inWordPressPlugins

Recently, three critical vulnerabilities have been released in theWordPressplugins, which can be exploited by attackers to take over accounts and escalate privileges. These vulnerabilities are identified by CVE-2026-11551, CVE-2026-12416 and CVE-2026-12417.

CVE-2026-11551: Escalating Privileges by Accountability

The CVE-2026-11551 vulnerability affects the Branda plugin and allows attackers to change any user’s password, including administrators, without being logged in. This is due to the lack of validation of the user’s identity before updating the password.

CVE-2026-12416: Acceptance of account by reseting password

The CVE-2026-12416 vulnerability affects the Invoice Generator plugin and allows attackers to take over accounts by resetting the password. This is due to the lack of nonce verification and authorization in the function pravel_invoice_change_password().

CVE-2026-12417: Acceptance by password reset and poor authentication

The CVE-2026-12417 vulnerability affects the SignUp & SignIn plugin and allows attackers to take over accounts by resetting passwords and weak authentication. This is due to the lack of nonce verification and authorization in the function pravel_change_password().

Impactul asupra afacerilor

These vulnerabilities can have a significant impact on as they allow attackers to take over accounts and escalate privileges, which can lead to loss of sensitive data and compromise site security.

Recommendations for remediation

To prevent attacks, it is recommended to urgently update the affected plugins to the newer versions. It is also recommended to regularly check the site’s security and implement additional security measures such as two-factor authentication and monitoring user activity.

What can you do today

  • UpdatesWordPressplugins to the newer versions

  • Regularly check the security of the site

  • Implement two-factor authentication

  • Monitor the activity of users

  • Contact a security specialist to evaluate and improve site security

Monitoring and protecting yourWordPresswebsite is essential to preventing attacks andining data security.Zebrabyteprovides security and monitoring solutions forWordPresssites. Contact us to find out more about how we can help you.


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert