| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-97637 | JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response | parorrey | JSON API Auth | Critical | 9.8 | 2026-10-02 07:39:29 | Deep Dive |
| CVE-2026-97338 | Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name | codename065 | Download Manager | Medium | 6.4 | 2026-10-02 07:39:29 | Deep Dive |
| CVE-2026-95670 | No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect | mihdan | No External Links | High | 7.2 | 2026-10-02 07:39:28 | Deep Dive |
| CVE-2026-96647 | Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter | webilia | Listdom: AI-powered Business Directory with Classifieds Ads Listings | Medium | 6.4 | 2026-10-02 07:39:28 | Deep Dive |
| CVE-2026-97634 | Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter | stellarwp | Event Tickets and Registration | Medium | 6.5 | 2026-10-02 07:39:28 | Deep Dive |
| CVE-2026-100107 | Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) | extendthemes | Kubio AI Page Builder | High | 7.2 | 2026-10-02 07:39:27 | Deep Dive |
| CVE-2026-93756 | Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview | smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | High | 7.2 | 2026-10-02 07:39:27 | Deep Dive |
| CVE-2026-96871 | Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter | kitae-park | Mang Board | High | 7.2 | 2026-10-02 07:39:27 | Deep Dive |
| CVE-2026-97342 | JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | High | 7.2 | 2026-10-02 07:39:26 | Deep Dive |
| CVE-2026-103426 | Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter | Relevanssi | Relevanssi Premium | High | 7.2 | 2026-10-02 07:39:25 | Deep Dive |
| CVE-2026-96566 | Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter | satollo | Newsletter – Send awesome emails from WordPress | High | 7.2 | 2026-10-02 07:39:25 | Deep Dive |
| CVE-2026-102002 | Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Low | 3.1 | 2026-10-02 07:39:24 | Deep Dive |
| CVE-2026-12951 | MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | Medium | 6.5 | 2026-10-02 07:39:24 | Deep Dive |
| CVE-2026-100182 | Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor | wpchill | Download Monitor | High | 7.2 | 2026-10-02 07:39:24 | Deep Dive |
| CVE-2026-102772 | CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field | jtsternberg | CMB2 | High | 7.2 | 2026-10-02 07:39:23 | Deep Dive |
| CVE-2026-97641 | Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content | comesio | Relevanssi – A Better Search | High | 7.2 | 2026-10-02 07:39:23 | Deep Dive |
| CVE-2026-95817 | DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content | apasionados | DoFollow Case by Case | High | 7.2 | 2026-10-02 07:39:22 | Deep Dive |
| CVE-2026-93880 | Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder | wpsoul | Greenshift – animation and page builder blocks | Medium | 6.1 | 2026-10-02 07:39:22 | Deep Dive |
| CVE-2026-97336 | CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type | jtsternberg | CMB2 | High | 7.2 | 2026-10-02 07:39:22 | Deep Dive |
| CVE-2026-96567 | MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta) | websoudan | MW WP Form | High | 7.2 | 2026-10-02 07:39:21 | Deep Dive |