| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-62065 | WordPress Cardea theme <= 2.3 - Local File Inclusion vulnerability | CocoBasic | Cardea | High | 8.1 | 2026-10-10 19:35:42 | Deep Dive |
| CVE-2026-62064 | WordPress Ambed theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | Bracketweb | Ambed | High | 7.1 | 2026-10-10 19:35:41 | Deep Dive |
| CVE-2026-62053 | WordPress Wine House theme <= 3.20 - PHP Object Injection vulnerability | ThemeREX | Wine House | Critical | 9.8 | 2026-10-10 19:35:40 | Deep Dive |
| CVE-2026-62054 | WordPress Yacht Rental theme <= 2.6 - PHP Object Injection vulnerability | ThemeREX | Yacht Rental | Critical | 9.8 | 2026-10-10 19:35:40 | Deep Dive |
| CVE-2026-62052 | WordPress Tipsy theme <= 1.6 - PHP Object Injection vulnerability | ThemeREX | Tipsy | Critical | 9.8 | 2026-10-10 19:35:39 | Deep Dive |
| CVE-2026-62051 | WordPress Stargaze theme <= 1.10 - PHP Object Injection vulnerability | ThemeREX | Stargaze | Critical | 9.8 | 2026-10-10 19:35:38 | Deep Dive |
| CVE-2026-62050 | WordPress Splendour theme <= 1.23 - PHP Object Injection vulnerability | ThemeREX | Splendour | Critical | 9.8 | 2026-10-10 19:35:37 | Deep Dive |
| CVE-2026-62043 | WordPress Contact Form 7 – Dynamic Text Extension plugin <= 5.0.7 - Sensitive Data Exposure vulnerability | sevenspark | Contact Form 7 – Dynamic Text Extension | High | 7.5 | 2026-10-10 19:35:36 | Deep Dive |
| CVE-2026-62038 | WordPress eRoom plugin <= 1.7.1 - Broken Authentication vulnerability | DigitalME | eRoom | High | 7.3 | 2026-10-10 19:35:36 | Deep Dive |
| CVE-2026-62037 | WordPress Document Embedder plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability | bPlugins | Document Embedder | High | 7.1 | 2026-10-10 19:35:35 | Deep Dive |
| CVE-2026-62035 | WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.1.0 - Broken Access Control vulnerability | upcasted | AWS S3 for WordPress Plugin – Upcasted | Medium | 6.3 | 2026-10-10 19:35:34 | Deep Dive |
| CVE-2026-62033 | WordPress uListing plugin <= 2.2.0 - Settings Change vulnerability | Stylemix | uListing | High | 7.6 | 2026-10-10 19:35:33 | Deep Dive |
| CVE-2026-62034 | WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Cross Site Scripting (XSS) vulnerability | bPlugins | Before After Image Comparison – Image comparison for WP | High | 7.1 | 2026-10-10 19:35:33 | Deep Dive |
| CVE-2026-62032 | WordPress DirectoryPress plugin <= 3.6.27 - Local File Inclusion vulnerability | Designinvento | DirectoryPress | Critical | 9.8 | 2026-10-10 19:35:32 | Deep Dive |
| CVE-2026-62031 | WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability | Stylemix | uListing | Critical | 9.3 | 2026-10-10 19:35:31 | Deep Dive |
| CVE-2026-62030 | WordPress StreamCast plugin <= 2.4.5 - Server Side Request Forgery (SSRF) vulnerability | bPlugins | StreamCast | High | 7.2 | 2026-10-10 19:35:30 | Deep Dive |
| CVE-2026-62027 | WordPress Team Section Block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability | bPlugins | Team Section Block | High | 7.1 | 2026-10-10 19:35:30 | Deep Dive |
| CVE-2026-62025 | WordPress Tailored Tools plugin <= 3.0.3 - Arbitrary File Upload vulnerability | Tailored Media | Tailored Tools | Critical | 9.0 | 2026-10-10 19:35:29 | Deep Dive |
| CVE-2026-62024 | WordPress CodeBard Help Desk plugin <= 1.1.2 - Arbitrary File Upload vulnerability | CodeBard | CodeBard Help Desk | Critical | 9.9 | 2026-10-10 19:35:28 | Deep Dive |
| CVE-2026-62022 | WordPress Tonda Membership plugin <= 1.0.1 - Privilege Escalation vulnerability | Select-Themes | Tonda Membership | Critical | 9.8 | 2026-10-10 19:35:27 | Deep Dive |