CVE-2026-105990 - Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via CSV Export
CVE ID :CVE-2026-105990
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105990
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105995 - Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure
CVE ID :CVE-2026-105995
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105995
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107120 - Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN
CVE ID :CVE-2026-107120
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-107120
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107321 - W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import
CVE ID :CVE-2026-107321
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The W3 Total Cache WordPress plugin before 2.10.6 does not confine a media-import file copy to the document root, nor enforce an effective file-type restriction on it, allowing users with the Author role or higher to plant content that, once an administrator runs the import, copies an arbitrary server-readable file into a publicly served directory, exposing it to unauthenticated retrieval.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-107321
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The W3 Total Cache WordPress plugin before 2.10.6 does not confine a media-import file copy to the document root, nor enforce an effective file-type restriction on it, allowing users with the Author role or higher to plant content that, once an administrator runs the import, copies an arbitrary server-readable file into a publicly served directory, exposing it to unauthenticated retrieval.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107323 - Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS
CVE ID :CVE-2026-107323
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-107323
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85571 - Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR
CVE ID :CVE-2026-85571
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-85571
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87780 - LTL Freight Quotes – Old Dominion Edition < 4.2.19 - Unauthenticated Stored XSS via Shipping Rules
CVE ID :CVE-2026-87780
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87780
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87781 - LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipping Rule 'edit_id' Parameter
CVE ID :CVE-2026-87781
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87781
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94256 - SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP
CVE ID :CVE-2026-94256
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-94256
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94257 - SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
CVE ID :CVE-2026-94257
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset, allowing unauthenticated attackers to set a new password on an arbitrary account, including an administrator, by verifying a one-time code sent to a phone number they control.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-94257
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The SMS Alert WordPress plugin before 4.0.1 does not bind the account whose password is being changed to the phone number that was actually verified during its OTP password reset, allowing unauthenticated attackers to set a new password on an arbitrary account, including an administrator, by verifying a one-time code sent to a phone number they control.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93938 - WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93938
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93938
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93940 - WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93940
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93940
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93941 - WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93941
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93941
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93942 - WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93942
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93942
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93943 - WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93943
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93943
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93944 - WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93944
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93944
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93945 - WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability
CVE ID :CVE-2026-93945
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93945
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93949 - WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability
CVE ID :CVE-2026-93949
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93949
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93950 - WordPress Motors theme <= 1.4.108 - Broken Access Control vulnerability
CVE ID :CVE-2026-93950
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93950
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93951 - WordPress Zeinet theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-93951
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Zeinet zeinet allows Reflected XSS.This issue affects Zeinet: from n/a through 1.0.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93951
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Zeinet zeinet allows Reflected XSS.This issue affects Zeinet: from n/a through 1.0.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96278 - WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Session History
CVE ID :CVE-2026-96278
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-96278
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...