| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102394 | WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripting (XSS) vulnerability | WPDeveloper | Essential Addons for Elementor | Medium | 6.5 | 2026-10-01 12:35:40 | Deep Dive |
| CVE-2026-103339 | WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability | Wpmet | Metform | Medium | 6.5 | 2026-10-01 12:34:57 | Deep Dive |
| CVE-2026-102379 | WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection vulnerability | VillaTheme | BuildKit – Product Builder for WooCommerce – Custom PC Builder | High | 8.5 | 2026-10-01 12:34:15 | Deep Dive |
| CVE-2026-103063 | WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability | Wpmet | ElementsKit Elementor addons Lite | Medium | 6.5 | 2026-10-01 12:33:44 | Deep Dive |
| CVE-2026-103345 | WordPress Pie Register plugin <= 3.8.4.13 - Sensitive Data Exposure vulnerability | Shamim Rajani | Pie Register | Medium | 5.3 | 2026-10-01 12:33:16 | Deep Dive |
| CVE-2026-103064 | WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability | Wpmet | ElementsKit Elementor addons Lite | Medium | 6.5 | 2026-10-01 12:32:30 | Deep Dive |
| CVE-2026-102390 | WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control vulnerability | VillaTheme | AFFI – Affiliate Marketing for WooCommerce | Medium | 5.3 | 2026-10-01 12:31:33 | Deep Dive |
| CVE-2026-102382 | WordPress Majestic Support plugin <= 1.2.0 - Insecure Direct Object References (IDOR) vulnerability | Ahmad | Majestic Support | Medium | 4.3 | 2026-10-01 12:31:11 | Deep Dive |
| CVE-2026-102381 | WordPress Majestic Support plugin <= 1.2.0 - Broken Access Control vulnerability | Ahmad | Majestic Support | Medium | 5.3 | 2026-10-01 12:28:06 | Deep Dive |
| CVE-2026-103343 | WordPress FluentForm plugin <= 6.2.14 - Cross Site Scripting (XSS) vulnerability | WP ManageNinja LLC | FluentForm | Medium | 6.5 | 2026-10-01 12:27:41 | Deep Dive |
| CVE-2026-103341 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Broken Access Control vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Medium | 5.3 | 2026-10-01 12:26:43 | Deep Dive |
| CVE-2026-103340 | WordPress Site Reviews plugin <= 8.3.2 - Broken Access Control vulnerability | Gemini Labs | Site Reviews | Medium | 5.3 | 2026-10-01 12:26:12 | Deep Dive |
| CVE-2026-103338 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | High | 8.5 | 2026-10-01 12:24:11 | Deep Dive |
| CVE-2026-103067 | WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability | Memberful | Memberful - Membership Plugin | High | 8.0 | 2026-10-01 12:18:21 | Deep Dive |
| CVE-2026-103754 | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory | Red Hat | Red Hat Ansible Automation Platform 2 | Medium | 5.9 | 2026-10-01 11:57:08 | Deep Dive |
| CVE-2026-103336 | WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability | Smackcoders Inc. | WP Ultimate CSV Importer | Medium | 5.3 | 2026-10-01 11:43:57 | Deep Dive |
| CVE-2026-103680 | Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation | - | - | Low | 3.1 | 2026-10-01 11:34:52 | Deep Dive |
| CVE-2026-103679 | Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction | - | - | Medium | 6.5 | 2026-10-01 11:34:50 | Deep Dive |
| CVE-2026-103678 | Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value | - | - | Medium | 5.4 | 2026-10-01 11:34:49 | Deep Dive |
| CVE-2026-103858 | MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions | MISP | MISP | Medium | 5.3 | 2026-10-01 11:31:33 | Deep Dive |