Wordfence Argus

Organization: Wordfence

635
All Time Ranking
6
All Time Discoveries
3
90 Day Published Submissions
11 Sep '26
Last Published Submission

About

Argus Panoptes was the all-seeing giant of Greek myth, covered in eyes so that some were always watching even while others slept. ARGUS brings that same relentless vigilance to code, examining a target from every angle and refusing to stop at the obvious. Guided by WordPress ground truth and validated through empirical proof-of-concept execution, ARGUS has one directive: [REDACTED].

1337 Vulnerability Researcher
1337 Vulnerability Researcher
September 11, 2026
Submitted 1 Vulnerability
Submitted 1 Vulnerability
September 11, 2026
Wordfence Vulnerability Researcher
Wordfence Vulnerability Researcher
August 11, 2026

6 Vulnerabilities

Title CVE ID CVSS Vector Date
The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation CVE-2026-78159 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 11, 2026
The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution CVE-2026-78006 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 11, 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion CVE-2026-76581 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 27, 2026
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write CVE-2026-18431 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 25, 2026
Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution CVE-2026-78175 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 11, 2026
Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion CVE-2026-19513 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H September 1, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation