| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-93927 | WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability | Axiomthemes | Veto | Critical | 9.8 | 2026-10-10 07:00:35 | Deep Dive |
| CVE-2026-93930 | WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability | ThemeREX Group | Tantra | Critical | 9.8 | 2026-10-10 07:00:35 | Deep Dive |
| CVE-2026-93929 | WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability | ThemeREX Group | Travesia | Critical | 9.8 | 2026-10-10 07:00:35 | Deep Dive |
| CVE-2026-93931 | WordPress Smash theme <= 1.12.0 - PHP Object Injection vulnerability | ThemeREX Group | Smash | Critical | 9.8 | 2026-10-10 07:00:35 | Deep Dive |
| CVE-2026-106606 | WordPress YITH WooCommerce Affiliates plugin <= 3.31.0 - PHP Object Injection vulnerability | YITH | YITH WooCommerce Affiliates | High | 7.2 | 2026-10-10 07:00:34 | Deep Dive |
| CVE-2026-93949 | WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability | Omegathemes | Grocery Shopping Store | High | 7.1 | 2026-10-10 07:00:34 | Deep Dive |
| CVE-2026-93950 | WordPress Motors theme <= 1.4.108 - Broken Access Control vulnerability | StylemixThemes | Motors | High | 7.5 | 2026-10-10 07:00:34 | Deep Dive |
| CVE-2026-108503 | Unauthorized information acquisition vulnerability in ZTE Z80 Ultra product | ZTE | Z80 Ultra | Low | 3.3 | 2026-10-10 06:52:59 | Deep Dive |
| CVE-2026-103427 | Simple Membership <= 4.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Country Field | wpinsider-1 | Simple Membership | Medium | 6.4 | 2026-10-10 06:40:17 | Deep Dive |
| CVE-2026-104006 | SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check | softaculous | SpeedyCache – Cache, Optimization, Performance | Low | 3.7 | 2026-10-10 06:40:16 | Deep Dive |
| CVE-2026-96572 | WP Meteor Website Speed Optimization Addon <= 3.4.18 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name | aguidrevitch | WP Meteor Website Speed Optimization Addon | High | 7.2 | 2026-10-10 06:40:16 | Deep Dive |
| CVE-2026-100196 | LazyLoad Plugin <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content | wp_media | LazyLoad Plugin – Lazy Load Images, Videos, and Iframes | High | 7.2 | 2026-10-10 06:40:15 | Deep Dive |
| CVE-2026-3717 | CV Builder – Professional Resume Builder SaaS <= 1.3.1 - Missing Authorization to Unauthenticated PNG File Upload | bestwpdeveloper | WP CV Builder | Medium | 5.3 | 2026-10-10 06:40:15 | Deep Dive |
| CVE-2026-107742 | 10Web Booster <= 2.34.8 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name | 10web | 10Web Booster – Website speed optimization, Cache & Page Speed optimizer | High | 7.2 | 2026-10-10 06:40:15 | Deep Dive |
| CVE-2026-102402 | Team <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ttp_filter_taxonomy' Post Meta via [tlpteam] Shortcode | techlabpro1 | Team – Team Members Showcase Plugin | Medium | 6.4 | 2026-10-10 06:40:14 | Deep Dive |
| CVE-2026-6243 | Frontend Admin by DynamiApps <= 3.28.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content | shabti | Frontend Admin by DynamiApps | Medium | 6.4 | 2026-10-10 06:40:14 | Deep Dive |
| CVE-2026-100161 | Photo Reviews for WooCommerce <= 1.2.30 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'wcpr_image_upload_id' Parameter | villatheme | Photo Reviews for WooCommerce | High | 7.2 | 2026-10-10 06:40:13 | Deep Dive |
| CVE-2026-5725 | Favicon Rotator <= 1.2.11 - Reflected Cross-Site Scripting via 'fvrt_' prefix | archetyped | Favicon Rotator | Medium | 6.1 | 2026-10-10 06:40:13 | Deep Dive |
| CVE-2026-107712 | WP Booking System <= 2.1.0.1 - Authenticated (Subscriber+) SQL Injection via 'current_month' Parameter | murgroland | WP Booking System – Booking Calendar | Medium | 6.5 | 2026-10-10 06:40:13 | Deep Dive |
| CVE-2026-94538 | WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion/Modification via 'task' Parameter to Multiple Functions | JoomUnited | WP File Download | High | 8.1 | 2026-10-10 06:40:12 | Deep Dive |