CRITICAL
9.8 CVE-2026-62928 Published 4 Sept 2026
WordPress XING CPTrans-ME-X OS Command Injection
Worried this affects your website?
WordPress plugin XING CPTrans-ME-X contains an OS Command Injection vulnerability (CWE-78).
An unauthenticated user can inject and execute operating system commands.
Reference: CVE-2026-62928 on NVD
← Back to Security News