| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-96347 | WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vulnerability | Bookly | Bookly | Medium | 6.5 | 2026-09-30 12:27:23 | Deep Dive |
| CVE-2026-96345 | WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability | Estatik | Estatik | High | 7.6 | 2026-09-30 12:27:22 | Deep Dive |
| CVE-2026-96344 | WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vulnerability | impleCode | eCommerce Product Catalog | High | 7.2 | 2026-09-30 12:27:20 | Deep Dive |
| CVE-2026-96343 | WordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerability | weDevs | WP ERP | High | 7.2 | 2026-09-30 12:27:19 | Deep Dive |
| CVE-2026-96338 | WordPress Profile Builder plugin <= 4.0.2 - Cross Site Scripting (XSS) vulnerability | Cozmoslabs | Profile Builder | Medium | 6.5 | 2026-09-30 12:27:18 | Deep Dive |
| CVE-2026-95587 | WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability | Hostinger | Hostinger Migrator | High | 7.5 | 2026-09-30 12:27:17 | Deep Dive |
| CVE-2026-94683 | WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability | Justin Nealey | DesignSetGo | High | 8.8 | 2026-09-30 12:27:16 | Deep Dive |
| CVE-2026-95531 | WordPress Conversational Forms for ChatBot plugin <= 1.5.0 - PHP Object Injection vulnerability | QuantumCloud | Conversational Forms for ChatBot | High | 8.8 | 2026-09-30 12:27:16 | Deep Dive |
| CVE-2026-94681 | WordPress WP Store Locator plugin < 3.0.0 - Denial of Service Attack vulnerability | Tijmen Smit | WP Store Locator | Medium | 5.9 | 2026-09-30 12:27:15 | Deep Dive |
| CVE-2026-94678 | WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerability | Mat Lipe | Go Live Update Urls | High | 8.8 | 2026-09-30 12:27:14 | Deep Dive |
| CVE-2026-94677 | WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object Injection vulnerability | Nexcess | Kadence WooCommerce Email Designer | High | 7.2 | 2026-09-30 12:27:13 | Deep Dive |
| CVE-2026-94674 | WordPress Pixel Manager for WooCommerce plugin <= 1.69.0 - Cross Site Scripting (XSS) vulnerability | SweetCode | Pixel Manager for WooCommerce | Medium | 6.5 | 2026-09-30 12:27:12 | Deep Dive |
| CVE-2026-94673 | WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability | NSquared | Simply Schedule Appointments | Medium | 5.3 | 2026-09-30 12:27:11 | Deep Dive |
| CVE-2026-94672 | WordPress Safe SVG plugin <= 2.5.0 - Insecure Direct Object References (IDOR) vulnerability | 10up | Safe SVG | Medium | 4.3 | 2026-09-30 12:27:11 | Deep Dive |
| CVE-2026-94499 | WordPress FormGent plugin <= 1.12.2 - Broken Access Control vulnerability | wpWax | FormGent | High | 7.1 | 2026-09-30 12:27:10 | Deep Dive |
| CVE-2026-94389 🧪 | WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | Critical | 9.0 | 2026-09-30 12:27:09 | Deep Dive |
| CVE-2026-94178 | WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability | Javier Carazo | Import and export users and customers | High | 7.5 | 2026-09-30 12:27:08 | Deep Dive |
| CVE-2026-94177 | WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability | Ruben Garcia | GamiPress | High | 8.5 | 2026-09-30 12:27:07 | Deep Dive |
| CVE-2026-94173 | WordPress Business Directory plugin <= 6.4.27 - Insecure Direct Object References (IDOR) vulnerability | Strategy11 Team | Business Directory | Medium | 5.4 | 2026-09-30 12:27:06 | Deep Dive |
| CVE-2026-94123 | WordPress NextGEN Gallery plugin <= 4.5.0 - Arbitrary File Download vulnerability | Syed Balkhi | NextGEN Gallery | High | 7.5 | 2026-09-30 12:27:05 | Deep Dive |