CVE tracker
393 subscribers
5.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-93942 - WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability

CVE ID :CVE-2026-93942
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93943 - WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability

CVE ID :CVE-2026-93943
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93944 - WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability

CVE ID :CVE-2026-93944
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93945 - WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability

CVE ID :CVE-2026-93945
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93949 - WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability

CVE ID :CVE-2026-93949
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93950 - WordPress Motors theme <= 1.4.108 - Broken Access Control vulnerability

CVE ID :CVE-2026-93950
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93951 - WordPress Zeinet theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-93951
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Zeinet zeinet allows Reflected XSS.This issue affects Zeinet: from n/a through 1.0.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96278 - WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Session History

CVE ID :CVE-2026-96278
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96563 - Motors <= 1.4.123 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'stm_f_s' Parameter

CVE ID :CVE-2026-96563
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96653 - WP Directory Kit <= 1.5.9 - Authenticated (Subscriber+) SQL Injection via 'display_name' Profile Field (Second-Order)

CVE ID :CVE-2026-96653
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 13 minutes ago
Description :The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order injection: a Subscriber stores a display_name containing a single quote via their own profile, which WordPress preserves verbatim; the payload is then triggered when WdkCachedUserEditor::update_listings_user_editor() re-reads that stored value and passes it unsanitized to the SQL sink.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96662 - Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_id]' Parameter

CVE ID :CVE-2026-96662
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 12 minutes ago
Description :The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96765 - WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via 'id_token' Parameter (iss / unique_name JWT claims)

CVE ID :CVE-2026-96765
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 12 minutes ago
Description :The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is stored in the wpo365_errors transient for up to three days by submitting a crafted unauthenticated request with a forged id_token whose base64url-decoded unique_name or iss claim contains malicious HTML, requiring no prior authentication or user interaction beyond an administrator later visiting the WPO365 wizard page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97340 - Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'author_facebook' User Profile Field

CVE ID :CVE-2026-97340
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 12 minutes ago
Description :The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_facebook, author_twitter, author_linkedin, author_dribble, author_whatsapp, author_email) in versions up to, and including, 7.16.1. Avada registers these fields through the user_contactmethods filter and, on the author archive, emits them inside an anchor href using only esc_attr() in Fusion_Social_Icon::get_markup(), which escapes HTML metacharacters but does not reject dangerous URL schemes such as javascript:. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses their author page and clicks the injected social icon (a click is required, and the site must have 'Open Social Icons in a New Window' set to Off so the browser doesn't block the javascript: URL from opening in a new tab).
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97396 - Email Marketing for WordPress and WooCommerce <= 1.0.10 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter to /updateOptions REST Endpoint

CVE ID :CVE-2026-97396
Published : Oct. 10, 2026, 8:17 a.m. | 2 hours, 12 minutes ago
Description :The Email Marketing for WordPress and WooCommerce – Retainful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-108506 - Unauthorized access vulnerability in ZTE Z80 Ultra product

CVE ID :CVE-2026-108506
Published : Oct. 10, 2026, 9:08 a.m. | 1 hour, 22 minutes ago
Description :ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104722 - Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'ix[file]' Parameter

CVE ID :CVE-2026-104722
Published : Oct. 10, 2026, 9:16 a.m. | 1 hour, 13 minutes ago
Description :The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2 This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107657 - HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribute Value via Registration Form

CVE ID :CVE-2026-107657
Published : Oct. 10, 2026, 9:16 a.m. | 1 hour, 13 minutes ago
Description :The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have configured a text-type custom user attribute whose display format places %value% inside an HTML attribute context (e.g., the documented pattern <a href="%value%">Custom link</a>), and for front-end user profiles to be enabled — both of which reflect the plugin's standard, documented configuration.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-108505 - Information disclosure vulnerability in ZTE Z80 Ultra product

CVE ID :CVE-2026-108505
Published : Oct. 10, 2026, 9:16 a.m. | 1 hour, 13 minutes ago
Description :ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-4791 - PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Attribute

CVE ID :CVE-2026-4791
Published : Oct. 10, 2026, 9:16 a.m. | 1 hour, 13 minutes ago
Description :The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91136 - Divi Plus <= 2.4.0 - Unauthenticated Arbitrary File Read via 'svg_image' Parameter

CVE ID :CVE-2026-91136
Published : Oct. 10, 2026, 9:16 a.m. | 1 hour, 13 minutes ago
Description :The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — sanitize_text_field() and esc_html() do not restrict filesystem paths, the file:// stream wrapper, or arbitrary URLs — before it is passed to file_get_contents() (with a wp_remote_get() fallback) and the raw response body is returned in the JSON 'html' field. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106138 - Cross-Site Scripting via Chart Tooltip in KendoReact

CVE ID :CVE-2026-106138
Published : Oct. 10, 2026, 9:23 a.m. | 1 hour, 7 minutes ago
Description :In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...