## Summary CVE-2026-9227 is a high-severity (CVSS 8.8) arbitrary file upload vulnerability in the GutenBee – Gutenberg Blocks WordPress plugin affecting all versions up to and including 2.20.1. The flaw resides in the `gutenbee_file_and_ext_json` function, which uses an insufficient `strpos()` check that merely verifies the filename contains '.json' anywhere in the string rather than ensuring the file end [truncated]
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist track data without performing any authe [truncated]