| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-96662 | Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_id]' Parameter | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | High | 7.5 | 2026-10-10 07:41:44 | Deep Dive |
| CVE-2026-100147 | FunnelKit <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Fields (shipping/billing) | teamfunnelkit | FunnelKit – Funnel Builder for WooCommerce Checkout | High | 7.2 | 2026-10-10 07:41:43 | Deep Dive |
| CVE-2026-96563 | Motors <= 1.4.123 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'stm_f_s' Parameter | stylemix | Motors – Car Dealership & Classified Listings Plugin | Medium | 6.4 | 2026-10-10 07:41:43 | Deep Dive |
| CVE-2026-96278 | WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Session History | opajaap | WP Photo Album Plus | High | 7.2 | 2026-10-10 07:41:42 | Deep Dive |
| CVE-2026-108504 | Unauthorized information retrieval vulnerability in ZTE Z80 Ultra product | ZTE | Z80 Ultra | Medium | 5.5 | 2026-10-10 07:19:21 | Deep Dive |
| CVE-2026-93945 | WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability | Axiomthemes | Balance | Critical | 9.8 | 2026-10-10 07:00:39 | Deep Dive |
| CVE-2026-62046 | WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability | ThemeREX Group | Gutentype | Critical | 9.8 | 2026-10-10 07:00:39 | Deep Dive |
| CVE-2026-62045 | WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability | ThemeREX Group | Booklovers | Critical | 9.8 | 2026-10-10 07:00:39 | Deep Dive |
| CVE-2026-93943 | WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability | ThemeREX Group | Convex | Critical | 9.8 | 2026-10-10 07:00:38 | Deep Dive |
| CVE-2026-93941 | WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability | ThemeREX Group | Edema | Critical | 9.8 | 2026-10-10 07:00:38 | Deep Dive |
| CVE-2026-93944 | WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability | ThemeREX Group | Camelia | Critical | 9.8 | 2026-10-10 07:00:38 | Deep Dive |
| CVE-2026-93940 | WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability | ThemeREX Group | Greeny | Critical | 9.8 | 2026-10-10 07:00:38 | Deep Dive |
| CVE-2026-93942 | WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability | ThemeREX Group | Dwell | Critical | 9.8 | 2026-10-10 07:00:38 | Deep Dive |
| CVE-2026-93937 | WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability | ThemeREX Group | Hygia | Critical | 9.8 | 2026-10-10 07:00:37 | Deep Dive |
| CVE-2026-93938 | WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability | ThemeREX Group | Hogwords | Critical | 9.8 | 2026-10-10 07:00:37 | Deep Dive |
| CVE-2026-93935 | WordPress Let's Play theme <= 1.1.15 - PHP Object Injection vulnerability | ThemeREX Group | Let's Play | Critical | 9.8 | 2026-10-10 07:00:37 | Deep Dive |
| CVE-2026-93936 | WordPress IPharm theme <= 1.2.4 - PHP Object Injection vulnerability | ThemeREX Group | IPharm | Critical | 9.8 | 2026-10-10 07:00:37 | Deep Dive |
| CVE-2026-93934 | WordPress Partiso theme <= 1.1.13 - PHP Object Injection vulnerability | ThemeREX Group | Partiso | Critical | 9.8 | 2026-10-10 07:00:36 | Deep Dive |
| CVE-2026-93933 | WordPress Rosalinda theme <= 1.2.4 - PHP Object Injection vulnerability | ThemeREX Group | Rosalinda | Critical | 9.8 | 2026-10-10 07:00:36 | Deep Dive |
| CVE-2026-93932 | WordPress Smart Casa theme <= 1.0.12 - PHP Object Injection vulnerability | ThemeREX Group | Smart Casa | Critical | 9.8 | 2026-10-10 07:00:36 | Deep Dive |