Critical CVEs CVE-2025-12057: WavePlayer WordPress Plugin Vulnerability July 10, 2026 ♡Follow0 A vulnerability in the WavePlayer WordPress plugin exploited in a global CMS campaign for web shell deployment. Discovered from: iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days; CISA Adds to KEV Catalog CMSCVE-2025-12057WavePlayerweb shellWordPress