AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-22390

CRITICAL · CVSS 9.9 EPSS 0.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-03-05 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.9. It affects WordPress.

CVE
CVE-2026-22390
Severity
CRITICAL
CVSS
9.9
EPSS
0.47%
WordPress

Original NVD Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1.