Search

Find a vulnerability

Search criteria

    11467 vulnerabilities

    CVE-2026-92767 (GCVE-0-2026-92767)

    Vulnerability from cvelistv5 – Published: 2026-10-03 07:39 – Updated: 2026-10-03 15:14
    VLAI
    Title
    Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'offset' Shortcode Attribute
    Summary
    The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:12 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    zayedbaloch Twenty20 Image Before-After Affected: 0 , ≤ 2.0.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92767",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:12:50.413668Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:14:13.461Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Twenty20 Image Before-After",
              "vendor": "zayedbaloch",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dmitrii Ignatyev"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via \u0027offset\u0027 Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T07:39:17.534Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ae21be88-494f-4b24-95e1-97367d252cf7?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/twenty20/tags/2.0.4/inc/twenty20-shortcode.php#L90"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/twenty20/tags/2.0.4/inc/twenty20-shortcode.php#L95"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/twenty20/tags/2.0.4/inc/twenty20-shortcode.php#L8"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3712833%40twenty20%2Ftags%2F2.0.6\u0026old=3712169%40twenty20%2Ftags%2F2.0.5"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T10:39:43.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T18:40:29.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Twenty20 Image Before-After \u003c= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via \u0027offset\u0027 Shortcode Attribute"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-92767",
        "datePublished": "2026-10-03T07:39:17.534Z",
        "dateReserved": "2026-09-16T19:07:45.260Z",
        "dateUpdated": "2026-10-03T15:14:13.461Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92084 (GCVE-0-2026-92084)

    Vulnerability from cvelistv5 – Published: 2026-10-03 07:39 – Updated: 2026-10-03 15:14
    VLAI
    Title
    Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output
    Summary
    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:12 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92084",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:12:59.078099Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:14:04.869Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Beaver Builder Page Builder \u2013 Drag and Drop Website Builder",
              "vendor": "beaverbuilder",
              "versions": [
                {
                  "lessThanOrEqual": "2.11.0.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Samuele Santonicola"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The The Beaver Builder Page Builder \u2013 Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker\u0027s comment approved."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T07:39:17.001Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/794e6d9b-ac07-4261-a60d-81c474973005?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/classes/class-fl-builder.php#L2139"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/modules/sidebar/sidebar.php#L11"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/modules/sidebar/includes/frontend.php#L4"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/classes/class-fl-builder-module.php#L143"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.11.0.5/classes/class-fl-builder.php#L2264"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3713226/beaver-builder-lite-version/trunk/modules/sidebar/sidebar.php"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-15T13:28:32.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T18:39:13.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Beaver Builder Page Builder \u003c= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-92084",
        "datePublished": "2026-10-03T07:39:17.001Z",
        "dateReserved": "2026-09-15T13:13:39.819Z",
        "dateUpdated": "2026-10-03T15:14:04.869Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100157 (GCVE-0-2026-100157)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode)
    Summary
    The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    roxnor WP Ultimate Review Affected: 0 , ≤ 2.4.3 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100157",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:14.767164Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP Ultimate Review",
              "vendor": "roxnor",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "walid213"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:26.027Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ee3690d9-d1c3-4653-948b-cba1a7653574?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/app/content.php#L347"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/app/content.php#L217"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/app/content.php#L52"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/init.php#L286"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3720426%40wp-ultimate-review\u0026new=3720426%40wp-ultimate-review"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T12:33:09.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:41:41.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WP Ultimate Review \u003c= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via \u0027xs_reviw_summery\u0027 Parameter (Split-Shortcode / Late-Registered Shortcode)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-100157",
        "datePublished": "2026-10-03T06:38:26.027Z",
        "dateReserved": "2026-09-25T12:18:04.662Z",
        "dateUpdated": "2026-10-03T15:42:41.054Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-11601 (GCVE-0-2026-11601)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete
    Summary
    The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site's legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-11601",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:23.150935Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.202Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPCafe \u2013 Restaurant Menu, Online Food Ordering \u0026 Table Booking System",
              "vendor": "arraytics",
              "versions": [
                {
                  "lessThanOrEqual": "3.0.19",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Niv Kochan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPCafe \u2013 Restaurant Menu, Online Food Ordering \u0026 Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site\u0027s legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:25.636Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c01a06ca-ba3f-4e61-a17c-86d5e9f53ebf?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L58"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L156"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L282"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L138"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Utils/Helpers.php#L20"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/core/assets/localize.php#L47"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/core/email-automation/email-automation-service-provider.php#L43"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L58"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L156"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L282"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L138"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Utils/Helpers.php#L20"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/core/assets/localize.php#L47"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/core/email-automation/email-automation-service-provider.php#L43"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3706610%40wp-cafe\u0026new=3706610%40wp-cafe"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-08T15:22:38.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:36:16.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPCafe \u003c= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-11601",
        "datePublished": "2026-10-03T06:38:25.636Z",
        "dateReserved": "2026-06-08T15:07:27.415Z",
        "dateUpdated": "2026-10-03T15:42:41.202Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-18443 (GCVE-0-2026-18443)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter
    Summary
    The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal 'access-privilege' module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-18443",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:31.023467Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.352Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Smart Manager \u2013 WooCommerce Bulk Edit: Products, Orders, Users \u0026 More (Spreadsheet)",
              "vendor": "storeapps",
              "versions": [
                {
                  "lessThanOrEqual": "8.97.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "lhking"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Smart Manager \u2013 Advanced WooCommerce Bulk Edit \u0026 Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the \u0027access_privileges\u0027 parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal \u0027access-privilege\u0027 module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:25.238Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bc660a2d-9f9b-4ec1-b27a-74a41b528afa?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.93.0/pro/classes/class-smart-manager-pro-access-privilege.php#L99"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.93.0/pro/classes/class-smart-manager-pro-access-privilege.php#L38"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.93.0/common-core/classes/class-sa-manager-controller.php#L143"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.93.0/pro/classes/class-smart-manager-pro-access-privilege.php#L472"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.92.0/pro/classes/class-smart-manager-pro-access-privilege.php#L99"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.92.0/pro/classes/class-smart-manager-pro-access-privilege.php#L38"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.92.0/common-core/classes/class-sa-manager-controller.php#L143"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/smart-manager-for-wp-e-commerce/tags/8.92.0/pro/classes/class-smart-manager-pro-access-privilege.php#L472"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3712956%40smart-manager-for-wp-e-commerce\u0026new=3712956%40smart-manager-for-wp-e-commerce"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-17T04:42:17.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:34:31.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Smart Manager \u003c= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via \u0027access_privileges\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-18443",
        "datePublished": "2026-10-03T06:38:25.238Z",
        "dateReserved": "2026-07-30T20:49:25.041Z",
        "dateUpdated": "2026-10-03T15:42:41.352Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104313 (GCVE-0-2026-104313)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via 'rule_data' Parameter
    Summary
    The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104313",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:35.888396Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.487Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPC Estimated Delivery Date for WooCommerce",
              "vendor": "wpclever",
              "versions": [
                {
                  "lessThanOrEqual": "4.0.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Osvaldo Noe Gonzalez Del Rio (Os)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u0027rule_data\u0027 parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:24.857Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/947602ee-eaf2-4f00-af41-4080b6f6228f?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-estimated-delivery-date/tags/4.0.1/includes/templates/rule.php#L119"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-estimated-delivery-date/tags/4.0.1/includes/class-backend.php#L385"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-estimated-delivery-date/tags/4.0.1/includes/class-backend.php#L81"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3724040%40wpc-estimated-delivery-date\u0026new=3724040%40wpc-estimated-delivery-date"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T19:55:58.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:43:00.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPC Estimated Delivery Date for WooCommerce \u003c= 4.0.1 - Reflected Cross-Site Scripting via \u0027rule_data\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-104313",
        "datePublished": "2026-10-03T06:38:24.857Z",
        "dateReserved": "2026-10-01T19:40:47.822Z",
        "dateUpdated": "2026-10-03T15:42:41.487Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94505 (GCVE-0-2026-94505)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter
    Summary
    The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94505",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:39.732434Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.610Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Nelio Content \u2013 Editorial Calendar \u0026 Social Media Auto-Posting",
              "vendor": "nelio",
              "versions": [
                {
                  "lessThanOrEqual": "4.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wordfence PRISM"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Nelio Content \u2013 Editorial Calendar \u0026 Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:24.479Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/828050ce-4775-4256-8dcf-2cdb96d5ec4e?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/nelio-content/tags/4.5.0/includes/post-types/reusable-messages/class-nelio-content-reusable-message-rest-controller.php#L68"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/nelio-content/tags/4.5.0/includes/post-types/reusable-messages/class-nelio-content-reusable-message-rest-controller.php#L169"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/nelio-content/tags/4.5.0/includes/utils/functions/helpers.php#L80"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3724505/nelio-content/tags/4.5.1"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T06:09:21.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T18:35:30.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Nelio Content \u003c= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via \u0027id\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-94505",
        "datePublished": "2026-10-03T06:38:24.479Z",
        "dateReserved": "2026-09-21T18:23:48.273Z",
        "dateUpdated": "2026-10-03T15:42:41.610Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96267 (GCVE-0-2026-96267)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter
    Summary
    The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table, and the injection is triggered when an administrator next views the Traffic Sources dashboard.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96267",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:48.045048Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.771Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP Visitor Statistics (Real Time Traffic)",
              "vendor": "osamaesh",
              "versions": [
                {
                  "lessThanOrEqual": "8.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Nox Axter"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the \u0027fullRef\u0027 parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table, and the injection is triggered when an administrator next views the Traffic Sources dashboard."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:24.083Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8192cbb0-ea1f-4897-808c-67f5002d56fb?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-stats-manager/tags/8.6/includes/wsm_db.php#L1082"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-stats-manager/tags/8.6/includes/wsm_statistics.php#L3252"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-stats-manager/tags/8.6/includes/wsm_requests.php#L140"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-stats-manager/tags/8.6/includes/wsm_functions.php#L3091"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-stats-manager/tags/8.6/wp-stats-manager.php#L103"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3722831%40wp-stats-manager\u0026new=3722831%40wp-stats-manager"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-22T20:40:29.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:38:58.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WP Visitor Statistics (Real Time Traffic) \u003c= 8.7 - Unauthenticated SQL Injection via \u0027fullRef\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-96267",
        "datePublished": "2026-10-03T06:38:24.083Z",
        "dateReserved": "2026-09-22T20:25:24.416Z",
        "dateUpdated": "2026-10-03T15:42:41.771Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103519 (GCVE-0-2026-103519)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter
    Summary
    The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The bypass relies on WordPress's own strip_shortcodes() function unwrapping the [[tag]] double-bracket escape to a bare [tag] that survives wp_insert_post storage and fires when the publicly queryable xs_review post type is rendered through the_content.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    roxnor WP Ultimate Review Affected: 0 , ≤ 2.4.3 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-103519",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:54.105226Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:41.904Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WP Ultimate Review",
              "vendor": "roxnor",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Eunho Kim"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The bypass relies on WordPress\u0027s own strip_shortcodes() function unwrapping the [[tag]] double-bracket escape to a bare [tag] that survives wp_insert_post storage and fires when the publicly queryable xs_review post type is rendered through the_content."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:23.698Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/76986a3a-67f8-4d91-9f48-88fad356c3b4?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/app/content.php#L347"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/app/content.php#L366"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/init.php#L291"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.3/app/content.php#L217"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3720426%40wp-ultimate-review\u0026new=3720426%40wp-ultimate-review"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-30T19:17:10.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:41:13.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WP Ultimate Review \u003c= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via \u0027xs_reviw_summery\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-103519",
        "datePublished": "2026-10-03T06:38:23.698Z",
        "dateReserved": "2026-09-30T19:01:44.804Z",
        "dateUpdated": "2026-10-03T15:42:41.904Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87115 (GCVE-0-2026-87115)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter
    Summary
    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode, as this field is not created by default during plugin installation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:24 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87115",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:24:59.440128Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.039Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "VikAppointments Services Booking Calendar",
              "vendor": "e4jvikwp",
              "versions": [
                {
                  "lessThanOrEqual": "1.2.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "zickzick2"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode, as this field is not created by default during plugin installation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:23.319Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75fc5df5-a774-4fe1-8452-d35ba7b69081?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/libraries/customfields/types/file.php#L53"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/libraries/customfields/types/file.php#L131"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/controllers/confirmapp.php#L88"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/vikappointments.php#L237"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/site/helpers/libraries/customfields/types/file.php#L131"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/site/helpers/libraries/customfields/types/file.php#L53"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/site/controllers/confirmapp.php#L88"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.21/vikappointments.php#L237"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3721264%40vikappointments\u0026new=3721264%40vikappointments"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-08T21:01:02.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:35:22.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "VikAppointments Services Booking Calendar \u003c= 1.2.21 - Unauthenticated Arbitrary File Deletion via \u0027old_vapcfN\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-87115",
        "datePublished": "2026-10-03T06:38:23.319Z",
        "dateReserved": "2026-09-08T20:45:54.127Z",
        "dateUpdated": "2026-10-03T15:42:42.039Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93889 (GCVE-0-2026-93889)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message
    Summary
    The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    wardee Mail logging & Catcher Affected: 0 , ≤ 2.1.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93889",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:15.254747Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.248Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Mail logging \u0026 Catcher",
              "vendor": "wardee",
              "versions": [
                {
                  "lessThanOrEqual": "2.1.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Adrien Brunner"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Mail logging \u2013 WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer \u0027wp_mail_failed\u0027 Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:22.939Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6a1d9d03-0216-484c-85ca-73f157595713?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-mail-catcher/tags/2.1.12/src/Loggers/LogHelper.php#L69"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-mail-catcher/tags/2.1.12/src/Views/LogModal.php#L83"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-mail-catcher/tags/2.1.12/src/Loggers/WpMail.php#L30"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-mail-catcher/tags/2.1.12/src/MailAdminTable.php#L149"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3717442%40wp-mail-catcher\u0026new=3717442%40wp-mail-catcher"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-02T17:38:12.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Mail logging \u003c= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer \u0027wp_mail_failed\u0027 Error Message"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-93889",
        "datePublished": "2026-10-03T06:38:22.939Z",
        "dateReserved": "2026-09-18T20:19:15.745Z",
        "dateUpdated": "2026-10-03T15:42:42.248Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93896 (GCVE-0-2026-93896)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUEST_URI
    Summary
    The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER['REQUEST_URI'] through vprintf() directly inside a <script> block emitted on wp_footer, without any sanitization or escaping (see the 'Current URL is "%s"' log entry produced by the URL-text display filter in the filter() method). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    syammohanm WPFront Notification Bar Affected: 0 , ≤ 3.5.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93896",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:19.955385Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.391Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPFront Notification Bar",
              "vendor": "syammohanm",
              "versions": [
                {
                  "lessThanOrEqual": "3.5.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Nabil Irawan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER[\u0027REQUEST_URI\u0027] through vprintf() directly inside a \u003cscript\u003e block emitted on wp_footer, without any sanitization or escaping (see the \u0027Current URL is \"%s\"\u0027 log entry produced by the URL-text display filter in the filter() method). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:22.547Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39563589-d585-4fba-9685-7e4b4eaef30e?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpfront-notification-bar/tags/3.5.1/classes/class-wpfront-notification-bar-controller.php#L327"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpfront-notification-bar/tags/3.5.1/classes/class-wpfront-notification-bar-controller.php#L491"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpfront-notification-bar/tags/3.5.1/classes/class-wpfront-notification-bar-controller.php#L843"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3722432%40wpfront-notification-bar\u0026new=3722432%40wpfront-notification-bar"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-21T13:38:36.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:45:06.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPFront Notification Bar \u003c= 3.5.1 - Reflected Cross-Site Scripting via REQUEST_URI"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-93896",
        "datePublished": "2026-10-03T06:38:22.547Z",
        "dateReserved": "2026-09-18T20:31:52.879Z",
        "dateUpdated": "2026-10-03T15:42:42.391Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-75028 (GCVE-0-2026-75028)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPCafe <= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting
    Summary
    The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-75028",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:27.162969Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.516Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPCafe \u2013 Restaurant Menu, Online Food Ordering \u0026 Table Booking System",
              "vendor": "arraytics",
              "versions": [
                {
                  "lessThanOrEqual": "3.0.18",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wordfence PRISM"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPCafe \u2013 Restaurant Menu, Online Food Ordering \u0026 Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:22.143Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/31a1616d-a793-4153-bc19-551f39d699ec?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/core/shortcodes/views/food-menu/food-list.php#L53"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/core/shortcodes/views/food-menu/food-list.php#L53"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/core/shortcodes/views/food-menu/food-list.php#L6"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/widgets/wpc-menus-list/wpc-menus-list.php#L942"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/widgets/wpc-location-menu/wpc-location-menu.php#L898"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/widgets/wpc-food-menu-tab/wpc-food-menu-tab.php#L848"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/widgets/wpc-food-location/wpc-food-location.php#L830"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.18/core/shortcodes/views/food-menu/location-menu.php#L28"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/core/shortcodes/views/food-menu/food-list.php#L6"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/widgets/wpc-menus-list/wpc-menus-list.php#L942"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/widgets/wpc-location-menu/wpc-location-menu.php#L898"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/widgets/wpc-food-menu-tab/wpc-food-menu-tab.php#L848"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/widgets/wpc-food-location/wpc-food-location.php#L830"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.17/core/shortcodes/views/food-menu/location-menu.php#L28"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3706610%40wp-cafe\u0026new=3706610%40wp-cafe"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-17T15:10:13.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:37:33.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPCafe \u003c= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via \u0027food_menu_style\u0027 Elementor Widget Setting"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-75028",
        "datePublished": "2026-10-03T06:38:22.143Z",
        "dateReserved": "2026-08-17T14:55:07.634Z",
        "dateUpdated": "2026-10-03T15:42:42.516Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92974 (GCVE-0-2026-92974)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_url' Parameter
    Summary
    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92974",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:33.239304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.638Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery",
              "vendor": "10web",
              "versions": [
                {
                  "lessThanOrEqual": "1.8.46",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "r3foxx"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u0027thumb_url\u0027 parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:21.771Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29c33526-3a60-45ab-95ef-22c78b310f74?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/admin/views/Editimage.php#L273"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/admin/views/Editimage.php#L93"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/photo-gallery.php#L910"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/framework/WDWLibrary.php#L18"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3716530%40photo-gallery\u0026new=3716530%40photo-gallery"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-17T13:41:26.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T18:11:07.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Photo Gallery by 10Web \u003c= 1.8.46 - Reflected Cross-Site Scripting via \u0027thumb_url\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-92974",
        "datePublished": "2026-10-03T06:38:21.771Z",
        "dateReserved": "2026-09-17T13:26:33.966Z",
        "dateUpdated": "2026-10-03T15:42:42.638Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15795 (GCVE-0-2026-15795)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    Summary
    The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-15795",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:36.928760Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.767Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Responsive Starter Templates \u2013 Elementor Templates \u0026 Starter Sites",
              "vendor": "cyberchimps",
              "versions": [
                {
                  "lessThanOrEqual": "3.5.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wordfence PRISM"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Responsive Plus \u2013 Elementor Templates \u0026 Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:21.379Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/15eef02a-d6c9-4956-9e19-b8f3340768ff?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/responsive-add-ons/tags/3.5.2/includes/customizer/helper.php#L694"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/responsive-add-ons/tags/3.5.2/includes/customizer/helper.php#L672"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/responsive-add-ons/tags/3.5.2/includes/customizer/helper.php#L518"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3709359%40responsive-add-ons\u0026new=3709359%40responsive-add-ons"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-02T17:33:39.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Responsive Plus \u003c= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15795",
        "datePublished": "2026-10-03T06:38:21.379Z",
        "dateReserved": "2026-07-14T19:40:29.577Z",
        "dateUpdated": "2026-10-03T15:42:42.767Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97660 (GCVE-0-2026-97660)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name
    Summary
    The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable via guest checkout without authentication because the malicious payload is embedded in a multipart Content-Disposition field name beginning with 'wpcpo-', which PHP's RFC1867 parser preserves byte-for-byte and stores into order item meta.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    wpclever WPC Product Options for WooCommerce Affected: 0 , ≤ 4.0.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-97660",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:40.319034Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:42.892Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPC Product Options for WooCommerce",
              "vendor": "wpclever",
              "versions": [
                {
                  "lessThanOrEqual": "4.0.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Sebastian Albrecht (mySebbe)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable via guest checkout without authentication because the malicious payload is embedded in a multipart Content-Disposition field name beginning with \u0027wpcpo-\u0027, which PHP\u0027s RFC1867 parser preserves byte-for-byte and stores into order item meta."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:21.018Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/13a52c43-c14c-4322-9191-297e6c647d92?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-product-options/tags/4.0.5/includes/class-cart.php#L579"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-product-options/tags/4.0.5/includes/class-cart.php#L792"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-product-options/tags/4.0.5/includes/class-cart.php#L336"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-product-options/tags/4.0.5/includes/class-cart.php#L537"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpc-product-options/tags/4.0.5/includes/class-cart.php#L573"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3712354%40wpc-product-options\u0026new=3712354%40wpc-product-options"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-24T19:51:44.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:43:39.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPC Product Options for WooCommerce \u003c= 4.0.5 - Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-97660",
        "datePublished": "2026-10-03T06:38:21.018Z",
        "dateReserved": "2026-09-24T19:36:38.793Z",
        "dateUpdated": "2026-10-03T15:42:42.892Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103421 (GCVE-0-2026-103421)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/search/<value>/0' Path Segment
    Summary
    The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app's content mode to be configured as 'webview' (i.e., the 'speed' option is not set to '1'), which is a supported and still-shipped mode, though no longer the default.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-103421",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:02.448806Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.024Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPMobile.App \u2013 Android and iOS App Builder",
              "vendor": "amauric",
              "versions": [
                {
                  "lessThanOrEqual": "11.84",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kevin Whelan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPMobile.App \u2013 Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027REQUEST_URI (path segment after /android_json/search/)\u0027 parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the app\u0027s content mode to be configured as \u0027webview\u0027 (i.e., the \u0027speed\u0027 option is not set to \u00271\u0027), which is a supported and still-shipped mode, though no longer the default."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:20.624Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0dc77221-836b-45cd-a234-19dbf28ed0e7?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/stats/display.php#L361"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/stats/render.php#L74"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/stats/boot.php#L91"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wpappninja/trunk/inc/api/rewrite.php#L38"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3721624"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-30T15:06:13.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:42:22.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPMobile.App \u003c= 11.84 - Unauthenticated Stored Cross-Site Scripting via \u0027/android_json/search/\u003cvalue\u003e/0\u0027 Path Segment"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-103421",
        "datePublished": "2026-10-03T06:38:20.624Z",
        "dateReserved": "2026-09-30T14:51:05.234Z",
        "dateUpdated": "2026-10-03T15:42:43.024Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97343 (GCVE-0-2026-97343)

    Vulnerability from cvelistv5 – Published: 2026-10-03 06:38 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link Authentication Bypass via 'burst_share_token'
    Summary
    The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account — leaving WordPress core's built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin's daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:25 UTC
    CWE
    • CWE-287 - Improper Authentication
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-97343",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:25:55.557423Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.164Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Burst Statistics \u2013 Simple WordPress Analytics (Google Analytics Alternative)",
              "vendor": "burstbv",
              "versions": [
                {
                  "lessThanOrEqual": "3.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "crow"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Burst Statistics \u2013 Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session cookie for the `burst_statistics_viewer` account to any visitor presenting a valid share token via `wp_set_auth_cookie()`, while the plugin only blocks Application Passwords for the resulting `burst_viewer` role and does not restrict the core `/wp-json/wp/v2/users/me` password update endpoint or filter the `edit_user` capability for that account \u2014 leaving WordPress core\u0027s built-in rule that any authenticated user may update their own account fully in effect. This makes it possible for unauthenticated attackers to set an attacker-chosen password on the `burst_statistics_viewer` WordPress account, constituting a permanent takeover of that limited-privilege (`view_burst_statistics`) account that persists through share-token revocation, share-token expiration, and execution of the plugin\u0027s daily `cleanup_viewer_sessions()` routine. Exploitation requires that the attacker have obtained a valid `burst_share_token`, such as one that has been shared publicly or distributed to an untrusted party."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T06:38:19.918Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0aab68b4-fd5a-4471-bd29-a1a6dbfcf4ec?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.7.1/includes/Admin/Share/Services/class-share-ui.php#L124"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.7.1/includes/Admin/Share/Services/class-share-tokens.php#L506"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.7.1/includes/Admin/Share/class-share.php#L69"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.7.1/includes/class-burst.php#L105"
            },
            {
              "url": "https://github.com/Burst-Statistics/burst-statistics"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.7.2/includes/Admin/Share/Services/class-share-tokens.php"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-24T12:40:07.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T18:37:47.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Burst Statistics \u003c= 3.7.1 - Improper Authentication to Account Persistence via Share-Link Authentication Bypass via \u0027burst_share_token\u0027"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-97343",
        "datePublished": "2026-10-03T06:38:19.918Z",
        "dateReserved": "2026-09-24T12:25:02.165Z",
        "dateUpdated": "2026-10-03T15:42:43.164Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103888 (GCVE-0-2026-103888)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter
    Summary
    The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The WooCommerce "redirect to cart after add to cart" option must be enabled for the filter that reads the woosq-redirect parameter to execute; however, the ?quick-view= auto-open mechanism means no further user interaction beyond loading the crafted URL is required to trigger script execution.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    wpclever WPC Smart Quick View for WooCommerce Affected: 0 , ≤ 4.4.0 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-103888",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:08.920016Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.293Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPC Smart Quick View for WooCommerce",
              "vendor": "wpclever",
              "versions": [
                {
                  "lessThanOrEqual": "4.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kuba"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u0027woosq-redirect\u0027 parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The WooCommerce \"redirect to cart after add to cart\" option must be enabled for the filter that reads the woosq-redirect parameter to execute; however, the ?quick-view= auto-open mechanism means no further user interaction beyond loading the crafted URL is required to trigger script execution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:19.631Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fecb0a33-7608-4367-b9f6-0514b0bb2802?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-smart-quick-view/tags/4.4.0/assets/js/frontend.js#L98"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-smart-quick-view/tags/4.4.0/wpc-smart-quick-view.php#L1372"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-smart-quick-view/tags/4.4.0/wpc-smart-quick-view.php#L221"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3724035%40woo-smart-quick-view\u0026new=3724035%40woo-smart-quick-view"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T13:42:07.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:20:40.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPC Smart Quick View for WooCommerce \u003c= 4.4.0 - Reflected Cross-Site Scripting via \u0027woosq-redirect\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-103888",
        "datePublished": "2026-10-03T05:29:19.631Z",
        "dateReserved": "2026-10-01T13:26:33.957Z",
        "dateUpdated": "2026-10-03T15:42:43.293Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103909 (GCVE-0-2026-103909)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Calculated Fields Form <= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation
    Summary
    The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted site to host a publicly accessible form in which an administrator has configured at least two fields with url.<name> predefined values that are used together in a concatenation equation — a plausible but not universal configuration.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-103909",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:14.892505Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.422Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Calculated Fields Form \u2013 AI Form Builder for WordPress \u2013 Contact, Payment, Quote, Quiz \u0026 More",
              "vendor": "codepeople",
              "versions": [
                {
                  "lessThanOrEqual": "5.5.1.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "UKO"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Calculated Fields Form \u2013 AI Form Builder for WordPress \u2013 Contact, Payment, Quote, Quiz \u0026 More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the \u0027arbitrary (whichever names the admin bound via url.\u003cname\u003e)\u0027 parameter in all versions up to, and including, 5.5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted site to host a publicly accessible form in which an administrator has configured at least two fields with url.\u0026lt;name\u0026gt; predefined values that are used together in a concatenation equation \u2014 a plausible but not universal configuration."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:19.279Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fd61aa6f-79c5-4f81-964e-e71412d45b35?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fields-public/fbuilder.fcalculated.js#L416"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fields-public/fbuilder.fcalculated.js#L389"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fbuilder-pro-public.jquery.js#L167"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/fbuilder-pro-public.jquery.js#L1288"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.5/js/modules/08_url/public/01_url.js#L140"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3724009%40calculated-fields-form\u0026new=3724009%40calculated-fields-form"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T14:31:46.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T16:36:24.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Calculated Fields Form \u003c= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-103909",
        "datePublished": "2026-10-03T05:29:19.279Z",
        "dateReserved": "2026-10-01T14:16:34.128Z",
        "dateUpdated": "2026-10-03T15:42:43.422Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-96575 (GCVE-0-2026-96575)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder
    Summary
    The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives WordPress comment save-time sanitization because the tags and attributes used (such as a[title] and code) are permitted by the core comment kses allow-list, and the literal characters comprising the plugin's shortcode markers and placeholder tokens are not stripped.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-96575",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:19.593993Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.548Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Transliterator \u2013 Multilingual and Multi-script Text Conversion",
              "vendor": "ivijanstefan",
              "versions": [
                {
                  "lessThanOrEqual": "2.5.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "theviper17y"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Transliterator \u2013 Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives WordPress comment save-time sanitization because the tags and attributes used (such as a[title] and code) are permitted by the core comment kses allow-list, and the literal characters comprising the plugin\u0027s shortcode markers and placeholder tokens are not stripped."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:18.944Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f31bf520-2006-496b-b487-62faea679cf6?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/serbian-transliteration/tags/2.5.8/classes/controller.php#L679"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/serbian-transliteration/tags/2.5.8/classes/controller.php#L659"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/serbian-transliteration/tags/2.5.8/classes/controller.php#L689"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3714692%40serbian-transliteration\u0026new=3714692%40serbian-transliteration"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-26T19:17:12.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T16:41:23.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Transliterator \u003c= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-96575",
        "datePublished": "2026-10-03T05:29:18.944Z",
        "dateReserved": "2026-09-23T13:30:14.837Z",
        "dateUpdated": "2026-10-03T15:42:43.548Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100148 (GCVE-0-2026-100148)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Rich Showcase for Google Reviews <= 7.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API)
    Summary
    The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].text' parameter in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered entirely through a Google review posted for the connected business and requires no WordPress account; the plugin's default daily cron auto-imports the malicious review text, and execution triggers for every visitor on DOMContentLoaded without any further user interaction.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    widgetpack Rich Showcase for Google Reviews Affected: 0 , ≤ 7.1.3 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100148",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:26.250459Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.676Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Rich Showcase for Google Reviews",
              "vendor": "widgetpack",
              "versions": [
                {
                  "lessThanOrEqual": "7.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jakub Herman"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027reviews[].text\u0027 parameter in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered entirely through a Google review posted for the connected business and requires no WordPress account; the plugin\u0027s default daily cron auto-imports the malicious review text, and execution triggers for every visitor on DOMContentLoaded without any further user interaction."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:18.617Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f2f3a5be-0b69-43aa-a56f-d602d5def7dc?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/7.1.2/assets/7.1.2/js/public-main.js#L14"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/7.1.2/includes/class-view.php#L535"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/7.1.2/includes/class-view.php#L453"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/7.1.2/includes/core/class-google-dao.php#L410"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/7.1.2/includes/core/class-google-dao.php#L445"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3719682%40widget-google-reviews\u0026new=3719682%40widget-google-reviews"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T11:56:29.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:16:42.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Rich Showcase for Google Reviews \u003c= 7.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-100148",
        "datePublished": "2026-10-03T05:29:18.617Z",
        "dateReserved": "2026-09-25T11:41:25.358Z",
        "dateUpdated": "2026-10-03T15:42:43.676Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101357 (GCVE-0-2026-101357)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    SEOPress <= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'seopress_google_analytics_matomo_id' Parameter
    Summary
    The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin's Advanced > Security settings.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101357",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:31.798496Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.802Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SEOPress \u2013 AI SEO Plugin \u0026 On-site SEO",
              "vendor": "rainbowgeek",
              "versions": [
                {
                  "lessThanOrEqual": "10.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "braintx"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The SEOPress \u2013 AI SEO Plugin \u0026 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027seopress_google_analytics_matomo_id\u0027 parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin\u0027s Advanced \u003e Security settings."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:18.270Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e88ec391-8d1b-4544-a7d0-0ac156c91ba5?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/functions/options-matomo.php#L193"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/functions/options-matomo.php#L197"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/src/Actions/Api/Options/AnalyticsSettings.php#L90"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/admin/sanitize/Sanitize.php#L183"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3722789%40wp-seopress\u0026new=3722789%40wp-seopress"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T15:49:20.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:22:37.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "SEOPress \u003c= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via \u0027seopress_google_analytics_matomo_id\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-101357",
        "datePublished": "2026-10-03T05:29:18.270Z",
        "dateReserved": "2026-09-28T15:34:12.257Z",
        "dateUpdated": "2026-10-03T15:42:43.802Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100149 (GCVE-0-2026-100149)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…
    Summary
    The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for unauthenticated attackers to extract the full customer card — including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts — for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:26 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100149",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:26:43.236916Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:43.954Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons",
              "vendor": "wpzoom",
              "versions": [
                {
                  "lessThanOrEqual": "4.7.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "walid213"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the \u0027x-yamidoo-signature (attacker-obtained via inline_js identify payload)\u0027 parameter. This makes it possible for unauthenticated attackers to extract the full customer card \u2014 including name, WordPress user ID, order history, order totals, purchased products, payment method labels, and EDD Software Licensing license keys with status and activation counts \u2014 for any arbitrary victim email address on the site. Exploitation requires the attacker to register a WooCommerce customer or subscriber-level account with a crafted email address whose local part encodes the target timestamp and victim email, allowing the signature printed into the page HTML by inline_js() to pass verify_request() for an arbitrary victim; both the share_customer_data and identify_logged_in settings are enabled by default, so no non-default configuration is required."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:17.935Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e0c9026c-d83e-41ac-be3a-93a33c32c47b?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat-customer.php#L82"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat.php#L921"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/social-icons-widget-by-wpzoom/tags/4.7.3/includes/classes/class-wpzoom-ai-chat-customer.php#L93"
            },
            {
              "url": "https://github.com/wpzoom/social-icons-widget-by-wpzoom/commit/351a873ac6c99fd8fb63115628a9d612427c3097"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T11:58:05.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:06:00.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons \u0026 Share Buttons \u003c= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`\u2026"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-100149",
        "datePublished": "2026-10-03T05:29:17.935Z",
        "dateReserved": "2026-09-25T11:42:58.288Z",
        "dateUpdated": "2026-10-03T15:42:43.954Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-87091 (GCVE-0-2026-87091)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Welcart e-Commerce <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters
    Summary
    The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The IPN endpoint accepts the 'rel' and 'option' parameters with no authentication, nonce validation, or signature verification, meaning any unauthenticated attacker can directly submit malicious payloads that are stored and later rendered in the administrator's settlement error log view.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:27 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    uscnanbu Welcart e-Commerce Affected: 0 , ≤ 2.12.2 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-87091",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:27:03.790340Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:44.079Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Welcart e-Commerce",
              "vendor": "uscnanbu",
              "versions": [
                {
                  "lessThanOrEqual": "2.12.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "minhgalaxy"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The IPN endpoint accepts the \u0027rel\u0027 and \u0027option\u0027 parameters with no authentication, nonce validation, or signature verification, meaning any unauthenticated attacker can directly submit malicious payloads that are stored and later rendered in the administrator\u0027s settlement error log view."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:17.586Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d6046c06-9a77-450f-9cdf-c5239e73cb6b?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.12.2/functions/settlement_func.php#L906"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.12.2/functions/settlement_func.php#L951"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.12.2/functions/hoock_func.php#L631"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.12.2/functions/settlement_func.php#L569"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.11.29/functions/settlement_func.php#L906"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.11.29/functions/settlement_func.php#L951"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.11.29/functions/hoock_func.php#L631"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/usc-e-shop/tags/2.11.29/functions/settlement_func.php#L569"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3690880/usc-e-shop"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3690880/usc-e-shop/trunk/functions/settlement_func.php"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-08T20:19:12.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:10:52.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Welcart e-Commerce \u003c= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-87091",
        "datePublished": "2026-10-03T05:29:17.586Z",
        "dateReserved": "2026-09-08T20:03:43.422Z",
        "dateUpdated": "2026-10-03T15:42:44.079Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101923 (GCVE-0-2026-101923)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter
    Summary
    The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:27 UTC
    CWE
    Impacted products
    Vendor Product Version
    villatheme Photo Reviews for WooCommerce Affected: 0 , ≤ 1.2.30 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101923",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:27:10.370433Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:44.206Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Photo Reviews for WooCommerce",
              "vendor": "villatheme",
              "versions": [
                {
                  "lessThanOrEqual": "1.2.30",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ivaylo"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review\u0027s reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker\u0027s review (or when WordPress\u0027s built-in wp_scheduled_delete cron empties the comment trash after 30 days)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:17.225Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bdc330ea-e490-43a5-93eb-a434a0e02868?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-photo-reviews/trunk/admin/admin.php#L2390"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-photo-reviews/trunk/admin/admin.php#L31"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-photo-reviews/trunk/frontend/frontend.php#L1268"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/woo-photo-reviews/trunk/frontend/frontend.php#L1232"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3718551%40woo-photo-reviews\u0026new=3718551%40woo-photo-reviews"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T16:18:13.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:19:45.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Photo Reviews for WooCommerce \u003c= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via \u0027wcpr_image_upload_id\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-101923",
        "datePublished": "2026-10-03T05:29:17.225Z",
        "dateReserved": "2026-09-28T16:03:08.119Z",
        "dateUpdated": "2026-10-03T15:42:44.206Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97337 (GCVE-0-2026-97337)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Simple Membership <= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints
    Summary
    The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:27 UTC
    CWE
    Impacted products
    Vendor Product Version
    wpinsider-1 Simple Membership Affected: 0 , ≤ 4.8.3 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-97337",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:27:21.529011Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:44.331Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Simple Membership",
              "vendor": "wpinsider-1",
              "versions": [
                {
                  "lessThanOrEqual": "4.8.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kuba"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST[\u0027email\u0027] parameter (overriding the member\u0027s registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member\u0027s activation email \u2014 and the follow-up \u0027registration complete\u0027 email containing the member\u0027s username and plaintext password \u2014 to an attacker-chosen address, and to then activate that member\u0027s account without their consent."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:16.871Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ae2b6c4c-7dd6-41e7-8b8d-c09aa7fa660b?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-registration.php#L75"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L850"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L774"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-init-time-tasks.php#L167"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3716437%40simple-membership\u0026new=3716437%40simple-membership"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-24T12:37:46.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T16:42:12.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Simple Membership \u003c= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via \u0027email\u0027 Parameter on Activation Endpoints"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-97337",
        "datePublished": "2026-10-03T05:29:16.871Z",
        "dateReserved": "2026-09-24T12:22:41.848Z",
        "dateUpdated": "2026-10-03T15:42:44.331Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-12828 (GCVE-0-2025-12828)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Ultra Addons Lite for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget
    Summary
    The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:27 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    ultrapressorg Ultra Addons Lite for Elementor Affected: 0 , ≤ 1.3.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-12828",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:27:37.346504Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:44.465Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Ultra Addons Lite for Elementor",
              "vendor": "ultrapressorg",
              "versions": [
                {
                  "lessThanOrEqual": "1.3.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Abu Hurayra (HurayraIIT)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:16.509Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a29959ea-af64-4a80-b46e-1e3b3cddc531?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ut-elementor-addons-lite/tags/1.2.0/elements/typeout.php#L300"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-11-12T18:33:35.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T17:14:10.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Ultra Addons Lite for Elementor \u003c= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2025-12828",
        "datePublished": "2026-10-03T05:29:16.509Z",
        "dateReserved": "2025-11-06T19:20:23.554Z",
        "dateUpdated": "2026-10-03T15:42:44.465Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100152 (GCVE-0-2026-100152)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    All in One SEO <= 5.0.2 - Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter
    Summary
    The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:27 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100152",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:27:31.930798Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:44.600Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "All in One SEO \u2013 AI SEO Plugin to Boost SEO Rankings \u0026 Traffic (Schema, Local SEO, Sitemap \u0026 SEO Insights)",
              "vendor": "smub",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kuba"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The The All in One SEO \u2013 AI SEO Plugin to Boost SEO Rankings \u0026 Traffic (Schema, Local SEO, Sitemap \u0026 SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:16.146Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9fa47d2b-e9a9-4d1b-b933-fd4aa453ba1a?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.2/app/Common/Breadcrumbs/Frontend.php#L280"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.2/app/Common/Breadcrumbs/Frontend.php#L104"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.2/app/Common/Breadcrumbs/Breadcrumbs.php#L242"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.2/app/Common/Breadcrumbs/Tags.php#L108"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3723760/all-in-one-seo-pack/trunk/app/Common/Breadcrumbs/Frontend.php?old=3709877\u0026old_path=all-in-one-seo-pack%2Ftrunk%2Fapp%2FCommon%2FBreadcrumbs%2FFrontend.php"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3723760/all-in-one-seo-pack/trunk/app/Common/Breadcrumbs/Frontend.php"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-25T12:19:21.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T16:33:28.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "All in One SEO \u003c= 5.0.2 - Unauthenticated Arbitrary Shortcode Execution via \u0027s\u0027 Search Query Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-100152",
        "datePublished": "2026-10-03T05:29:16.146Z",
        "dateReserved": "2026-09-25T12:04:15.445Z",
        "dateUpdated": "2026-10-03T15:42:44.600Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101928 (GCVE-0-2026-101928)

    Vulnerability from cvelistv5 – Published: 2026-10-03 05:29 – Updated: 2026-10-03 15:42
    VLAI
    Title
    Magic Tooltips For Contact Form 7 <= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author
    Summary
    The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the plugin's esc_html filter callback decodes HTML-entity-encoded payloads (e.g. those containing '<tip>') back into live HTML, meaning an entity-encoded script payload submitted as a comment author name — which bypasses sanitize_text_field — is rendered as executable markup when an administrator views wp-admin/edit-comments.php.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-03 15:27 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    magicplugins Magic Tooltips For Contact Form 7 Affected: 0 , ≤ 1.0.34 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101928",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-03T15:27:43.986803Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-03T15:42:44.749Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Magic Tooltips For Contact Form 7",
              "vendor": "magicplugins",
              "versions": [
                {
                  "lessThanOrEqual": "1.0.34",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Afifudin Maarif"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027author\u0027 parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the plugin\u0027s esc_html filter callback decodes HTML-entity-encoded payloads (e.g. those containing \u0027\u0026lt;tip\u0026gt;\u0027) back into live HTML, meaning an entity-encoded script payload submitted as a comment author name \u2014 which bypasses sanitize_text_field \u2014 is rendered as executable markup when an administrator views wp-admin/edit-comments.php."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T05:29:15.809Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94e8de22-c373-4f0c-9723-f19752ade4e7?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/magic-tooltips-for-contact-form-7/trunk/magic-tooltips-for-contact-form-7.php#L18"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/magic-tooltips-for-contact-form-7/trunk/lib/wp-hooks.php#L96"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3723483%40magic-tooltips-for-contact-form-7\u0026new=3723483%40magic-tooltips-for-contact-form-7"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T16:30:27.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-02T16:39:35.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Magic Tooltips For Contact Form 7 \u003c= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via \u0027esc_html\u0027 Filter Override via Comment Author"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-101928",
        "datePublished": "2026-10-03T05:29:15.809Z",
        "dateReserved": "2026-09-28T16:15:22.184Z",
        "dateUpdated": "2026-10-03T15:42:44.749Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }