CVE-2026-103347
— WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Remote
|
Authentication
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103068
— WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalati…
Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-102378
— WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerabili…
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-100517
— WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object Referen…
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-100514
— WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnera…
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97297
— WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability
Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97284
— WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
Remote
|
Injection
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97281
— WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97277
— WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97273
— WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS…
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97269
— WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerabi…
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97268
— WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS…
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97260
— WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97258
— WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-97251
— WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Obje…
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-95588
— WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerabi…
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Remote
|
Authentication
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-94390
— WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vul…
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
Remote
|
Injection
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-62073
— WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-62071
— WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Remote
|
Injection
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103752
— WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026