|
CVE-2026-108505
|
Information disclosure vulnerability in ZTE Z80 Ultra product
|
ZTE
|
Z80 Ultra
|
Low
|
3.3
|
2026-10-10 08:50:06 |
Deep Dive
|
|
CVE-2026-4791
|
PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Attribute
|
peprodev
|
PeproDev Ultimate Profile Solutions
|
Medium
|
6.4
|
2026-10-10 08:26:40 |
Deep Dive
|
|
CVE-2026-107657
|
HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribute Value via Registration Form
|
hivepress
|
HivePress – Business Directory, Listings & Classified Ads Plugin
|
High
|
7.2
|
2026-10-10 08:26:40 |
Deep Dive
|
|
CVE-2026-104722
|
Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'ix[file]' Parameter
|
webilia
|
Listdom: AI-powered Business Directory with Classifieds Ads Listings
|
Medium
|
4.9
|
2026-10-10 08:26:39 |
Deep Dive
|
|
CVE-2026-91136
|
Divi Plus <= 2.4.0 - Unauthenticated Arbitrary File Read via 'svg_image' Parameter
|
Divi Essential
|
Divi Plus
|
High
|
7.5
|
2026-10-10 08:26:39 |
Deep Dive
|
|
CVE-2026-93951
|
WordPress Zeinet theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
|
Bracketweb
|
Zeinet
|
High
|
7.1
|
2026-10-10 08:00:09 |
Deep Dive
|
|
CVE-2026-103478
|
Premium Packages <= 7.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkout[billing][phone]' Parameter
|
codename065
|
Premium Packages – Sell Digital Products Securely
|
Medium
|
6.4
|
2026-10-10 07:41:49 |
Deep Dive
|
|
CVE-2026-93746
|
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 5.0.2 - Insecure Direct Object Reference to Unauthenticated Unauthorized Order Document Access via 'email' Parameter
|
webtoffee
|
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
|
High
|
7.5
|
2026-10-10 07:41:49 |
Deep Dive
|
|
CVE-2026-102291
|
Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'display_name'
|
themeum
|
Kirki – Freeform Page Builder, Website Builder & Customizer
|
Medium
|
5.4
|
2026-10-10 07:41:48 |
Deep Dive
|
|
CVE-2026-97340
|
Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'author_facebook' User Profile Field
|
ThemeFusion
|
Avada | Website Builder For WordPress & WooCommerce
|
Medium
|
6.4
|
2026-10-10 07:41:48 |
Deep Dive
|
|
CVE-2026-102774
|
SureDash <= 1.12.1 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content
|
brainstormforce
|
SureDash – Community, Courses & Member Dashboard
|
Medium
|
6.4
|
2026-10-10 07:41:47 |
Deep Dive
|
|
CVE-2026-104728
|
AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via wp_ajax_automatorwp_fluentform_get_forms AJAX Action
|
rubengc
|
AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI
|
Medium
|
4.3
|
2026-10-10 07:41:47 |
Deep Dive
|
|
CVE-2026-104759
|
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via OIDC Nonce Replay via id_token Nonce Verification
|
wpo365
|
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
|
High
|
8.1
|
2026-10-10 07:41:47 |
Deep Dive
|
|
CVE-2026-100178
|
WPAdverts <= 2.3.4 - Unauthenticated Stored Cross-Site Scripting via 'adverts_location' Parameter
|
gwin
|
WPAdverts – Classifieds Plugin
|
High
|
7.2
|
2026-10-10 07:41:46 |
Deep Dive
|
|
CVE-2026-96653
|
WP Directory Kit <= 1.5.9 - Authenticated (Subscriber+) SQL Injection via 'display_name' Profile Field (Second-Order)
|
wpdirectorykit
|
WP Directory Kit
|
Medium
|
6.5
|
2026-10-10 07:41:46 |
Deep Dive
|
|
CVE-2026-104803
|
WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback
|
whyun
|
WPCOM Member
|
Critical
|
9.8
|
2026-10-10 07:41:45 |
Deep Dive
|
|
CVE-2026-96765
|
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via 'id_token' Parameter (iss / unique_name JWT claims)
|
wpo365
|
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
|
High
|
7.2
|
2026-10-10 07:41:45 |
Deep Dive
|
|
CVE-2026-97396
|
Email Marketing for WordPress and WooCommerce <= 1.0.10 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter to /updateOptions REST Endpoint
|
retainful
|
Email Marketing for WordPress and WooCommerce – Retainful
|
Medium
|
6.4
|
2026-10-10 07:41:45 |
Deep Dive
|
|
CVE-2026-101920
|
Molongui Authorship <= 5.2.12 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Comment href Attribute
|
molongui
|
Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
|
High
|
7.2
|
2026-10-10 07:41:44 |
Deep Dive
|
|
CVE-2026-101921
|
WPForms <= 2.0.2.1 - Reflected Cross-Site Scripting via 'query_var' Smart Tag in iframe srcdoc Attribute
|
smub
|
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
|
Medium
|
4.7
|
2026-10-10 07:41:44 |
Deep Dive
|