TopVuln

High-risk vulnerability digests

CVE-2026-27065

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-03-19 09:16:17
Affected versions
BuilderPress <= 2.0.1
Summary
This is a critical PHP local file inclusion vulnerability in ThimPress BuilderPress. It allows unauthenticated attackers to include and execute arbitrary local files on vulnerable systems. The vulnerability holds a 9.8 CVSS v3 score, making it extremely high risk for exposed installations.
Remediation
Upgrade BuilderPress to a version newer than 2.0.1 immediately to remediate this flaw. Restrict access to the plugin's functionality to only authorized users until patching is complete. Scan web server directories for any unexpected or malicious files that may indicate exploitation.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.