SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-12685

HIGH · CVSS 7.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The EscortWP WordPress theme versions up to 3.6.2 contain a vendor-authored, obfuscated backdoor that allows unauthenticated attackers to permanently delete all site content using a hard-coded key. Additionally, this vulnerability facilitates the unauthorized transmission of sensitive site information, including the URL, administrator email, and license key, to an external server. WordPress site administrators using this theme should prioritize immediate updates or remediation to mitigate potential data loss and unauthorized access.

CVE
CVE-2026-12685
Severity
HIGH
CVSS
7.5
EPSS
0.22%
WordPress

Original NVD Description

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.