| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-93697 | WHM Mass Modify Accounts存储型XSS漏洞 | Webpros | cPanel | - | - | 2026-10-02 06:20:44 | Deep Dive |
| CVE-2026-93698 | Multilang adminbin验证不足致任意命令执行 | Webpros | cPanel | - | - | 2026-10-02 06:20:34 | Deep Dive |
| CVE-2026-97317 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page | Unknown | Giveaways and Contests by RafflePress | - | - | 2026-10-02 06:00:27 | Deep Dive |
| CVE-2026-97318 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter | Unknown | Giveaways and Contests by RafflePress | - | - | 2026-10-02 06:00:27 | Deep Dive |
| CVE-2026-94298 | BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter | Unknown | BuildKit | - | - | 2026-10-02 06:00:26 | Deep Dive |
| CVE-2026-91023 | Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured | Unknown | Motors | - | - | 2026-10-02 06:00:26 | Deep Dive |
| CVE-2026-91022 | Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color | Unknown | Motors | - | - | 2026-10-02 06:00:26 | Deep Dive |
| CVE-2026-13718 | Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content | Unknown | Tabs Responsive | - | - | 2026-10-02 06:00:25 | Deep Dive |
| CVE-2026-85016 | Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter | Unknown | Unlimited Elements for Elementor | - | - | 2026-10-02 06:00:25 | Deep Dive |
| CVE-2026-90988 | Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum | Unknown | Request a Quote | - | - | 2026-10-02 06:00:25 | Deep Dive |
| CVE-2026-91828 | OMGF < 6.3.11 - Unauthenticated DoS via do_optimize | Unknown | OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. | - | - | 2026-10-02 06:00:25 | Deep Dive |
| CVE-2026-85004 | Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect | Unknown | Popup Maker | - | - | 2026-10-02 06:00:24 | Deep Dive |
| CVE-2026-81740 | Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback | Unknown | Paytm Payment Gateway | - | - | 2026-10-02 06:00:24 | Deep Dive |
| CVE-2026-15896 | Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter | WebRehab | Super Forms – Drag & Drop Form Builder | Critical | 9.1 | 2026-10-02 05:30:19 | Deep Dive |
| CVE-2026-92174 | SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter | gpriday | SiteOrigin Widgets Bundle | High | 7.5 | 2026-10-02 05:30:18 | Deep Dive |
| CVE-2026-90438 | Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission | kstover | Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder | High | 7.2 | 2026-10-02 05:30:18 | Deep Dive |
| CVE-2026-78471 | Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name | optimizingmatters | Autoptimize | Medium | 5.4 | 2026-10-02 05:30:18 | Deep Dive |
| CVE-2026-15897 | Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login | WebRehab | Super Forms – Drag & Drop Form Builder | High | 8.8 | 2026-10-02 05:30:17 | Deep Dive |
| CVE-2026-92820 | Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload | SaturdayDrive | Ninja Forms - File Uploads | High | 8.1 | 2026-10-02 05:30:16 | Deep Dive |
| CVE-2026-84925 | Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter | ThemeFusion | Avada | Website Builder For WordPress & WooCommerce | Medium | 6.1 | 2026-10-02 05:30:15 | Deep Dive |