CVE-2026-97297
— WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability
Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97284
— WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97281
— WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97280
— WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Review Schema: 3.1.0.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97277
— WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97273
— WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS…
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97269
— WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerabi…
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97268
— WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS…
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97260
— WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97258
— WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97251
— WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Obje…
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-95588
— WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerabi…
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Remote
|
Authentication
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-94390
— WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vul…
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
Remote
|
Injection
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the valu…
Remote
|
Memory Corruption
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-79899
— Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the…
|
Misconfiguration
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-79898
— Fortra BoKS Manager crlserver command injection vulnerability
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interfac…
Remote
|
Injection
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-67106
— HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch furth…
Remote
|
Information Disclosure
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-67105
— HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend …
Remote
|
Cryptography
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-67104
— HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the disco…
Remote
|
Information Disclosure
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-62073
— WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026