|
CVE-2026-89424
|
Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter
|
inisev
|
Duplicate Post
|
Medium
|
6.4
|
2026-10-01 08:28:45 |
Deep Dive
|
|
CVE-2026-96813
|
Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields
|
10web
|
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
|
High
|
7.2
|
2026-10-01 08:28:45 |
Deep Dive
|
|
CVE-2026-95687
|
WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint
|
wpclever
|
WPC Shop as a Customer for WooCommerce
|
High
|
8.8
|
2026-10-01 08:28:44 |
Deep Dive
|
|
CVE-2026-100184
|
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value
|
codepeople
|
Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
|
Medium
|
4.7
|
2026-10-01 08:28:44 |
Deep Dive
|
|
CVE-2026-96268
|
Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action
|
awesomesupport
|
Awesome Support – WordPress HelpDesk & Support Plugin
|
Medium
|
6.4
|
2026-10-01 08:28:44 |
Deep Dive
|
|
CVE-2026-101925
|
bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name
|
robin-w
|
bbp style pack
|
Medium
|
6.4
|
2026-10-01 08:28:43 |
Deep Dive
|
|
CVE-2026-96573
|
Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer
|
codepeople
|
Appointment Hour Booking – Booking Calendar
|
High
|
7.2
|
2026-10-01 08:28:43 |
Deep Dive
|
|
CVE-2026-85235
|
Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
|
wpmudev
|
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
|
High
|
7.2
|
2026-10-01 08:28:42 |
Deep Dive
|
|
CVE-2026-92244
|
PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields
|
wpovernight
|
PDF Invoices & Packing Slips for WooCommerce
|
High
|
7.2
|
2026-10-01 08:28:42 |
Deep Dive
|
|
CVE-2026-15983
|
Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter
|
WebRehab
|
Super Forms – Drag & Drop Form Builder
|
High
|
8.1
|
2026-10-01 08:28:42 |
Deep Dive
|
|
CVE-2026-100179
|
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()
|
codepeople
|
Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
|
Medium
|
6.1
|
2026-10-01 08:28:41 |
Deep Dive
|
|
CVE-2026-90992
|
Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field
|
davidanderson
|
Redux Framework
|
Medium
|
6.4
|
2026-10-01 08:28:41 |
Deep Dive
|
|
CVE-2026-14995
|
Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path
|
optimizingmatters
|
Autoptimize
|
High
|
7.2
|
2026-10-01 08:28:40 |
Deep Dive
|
|
CVE-2026-103655
|
MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period
|
MISP
|
MISP
|
Critical
|
9.3
|
2026-10-01 08:08:55 |
Deep Dive
|
|
CVE-2026-78249
|
理光多功能设备1.1.3及更早版本路径遍历漏洞
|
Fujifilm Business Innovation Corp.
|
Apeos 3060 / 2560 / 1860 Japan model
|
Medium
|
6.8
|
2026-10-01 07:56:26 |
Deep Dive
|
|
CVE-2026-75957
|
Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter
|
superdav42
|
Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform
|
Critical
|
9.8
|
2026-10-01 07:40:24 |
Deep Dive
|
|
CVE-2026-19807
|
ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
|
bytecorestack
|
ByteCoreStack – MCP Connector for AI Tools
|
High
|
8.8
|
2026-10-01 07:40:24 |
Deep Dive
|
|
CVE-2026-15989
|
Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
|
WebRehab
|
Super Forms – Drag & Drop Form Builder
|
Critical
|
9.8
|
2026-10-01 07:40:24 |
Deep Dive
|
|
CVE-2026-19902
|
Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
|
spacetime
|
Ad Inserter – Ad Manager & AdSense Ads
|
Medium
|
6.1
|
2026-10-01 07:40:23 |
Deep Dive
|
|
CVE-2026-93882
|
LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
|
thimpress
|
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
|
High
|
7.5
|
2026-10-01 07:40:23 |
Deep Dive
|