CVE-2026-19225 PUBLISHED

Defender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Multisite

Assigner: WPScan
Reserved: 07.08.2026 Published: 27.08.2026 Updated: 27.08.2026

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

Product Status

Vendor Unknown
Product Defender Security
Versions Default: unaffected
  • affected from 5.0.0 to 6.2.0 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE