Wordfence's Argus team found two CVSS-9.8 chains in The Events Calendar. An anonymous comment plus a moderation-hash preview URL reaches OS command execution, and version 6.17.4 closes only one of them.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence62
One HTTP request runs Python on an exposed Langflow server, and Sysdig's honeypots logged exploit attempts inside a day of the March 17 advisory, before any public proof-of-concept existed. The traffic identified itself as nuclei.
Reality
- Evidence58
- Adoption34
- Hype gap+30
- Incentives78
- Confidence52
CVE-2026-82222 lets an unauthenticated visitor register on any GiveWP site running 4.16.7.1 or earlier, park a serialized gadget in a profile field, and let donation processing deserialize it into OS command execution. The fix is 4.16.7.2.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence45
Wordfence says CVE-2026-18431 lets an unauthenticated attacker run PHP on sites running both a vulnerable Avada theme and Fusion Builder. Updating either component breaks the chain.
Reality
- Evidence52
- Adoption28
- Hype gap+18
- Incentives66
- Confidence54
CVE-2026-58231 chains a default auth client with missing input validation in SAP's Data Hub Adapter. The fix needs a rebuild and redeploy; the attackers needed 72 hours.
Reality
- Evidence42
- Adoption28
- Hype gap+12
- Incentives38
- Confidence44