SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57786

HIGH · CVSS 8.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A Cross-Site Request Forgery (CSRF) vulnerability in the WorkScout-Core plugin allows attackers to bypass authentication, potentially granting unauthorized access to sensitive functions. This high-severity flaw affects versions up to and including 1.7.08, making it critical for users of the WorkScout-Core plugin to prioritize immediate updates or mitigations to safeguard their systems. Organizations utilizing this plugin should assess their exposure and implement necessary security measures promptly.

CVE
CVE-2026-57786
Severity
HIGH
CVSS
8.8
EPSS
0.16%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.