CVE-2026-62043
— WordPress Contact Form 7 – Dynamic Text Extension plugin <= 5.0.7 - Sensitive Data Exposu…
Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62038
— WordPress eRoom plugin <= 1.7.1 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
Remote
|
Authentication
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62037
— WordPress Document Embedder plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Document Embedder <= 2.4.0 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62035
— WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.1.0 - Broken Access Control …
Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.
Remote
|
Authorization
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62034
— WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Cros…
Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.
Remote
|
Cross-Site Scripting
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62033
— WordPress uListing plugin <= 2.2.0 - Settings Change vulnerability
Subscriber Settings Change in uListing <= 2.2.0 versions.
Remote
|
Authentication
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62032
— WordPress DirectoryPress plugin <= 3.6.27 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62031
— WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability
Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62030
— WordPress StreamCast plugin <= 2.4.5 - Server Side Request Forgery (SSRF) vulnerability
Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
Remote
|
Server-Side Request Forgery
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62027
— WordPress Team Section Block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.
Remote
|
Cross-Site Scripting
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62025
— WordPress Tailored Tools plugin <= 3.0.3 - Arbitrary File Upload vulnerability
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
Remote
|
Authentication
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62024
— WordPress CodeBard Help Desk plugin <= 1.1.2 - Arbitrary File Upload vulnerability
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62022
— WordPress Tonda Membership plugin <= 1.0.1 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
Remote
|
Authorization
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62021
— WordPress Angio theme <= 1.1.1 - PHP Object Injection vulnerability
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62020
— WordPress TouchUp theme < 1.4 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-57742
— WordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS.
This issue affects Kids Planet: from n/a throug…
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-48194
— WordPress DukaMarket theme <= 1.3.0 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-48193
— WordPress Uminex theme <= 1.0.9 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-45440
— WordPress WP Ultimate CSV Importer plugin <= 9.2 - SQL Injection vulnerability
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-42777
— WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026