Search
Find a vulnerability
Search criteria
11385 vulnerabilities
CVE-2026-15896 (GCVE-0-2026-15896)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
Summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
Severity
9.1 (Critical)
CWE
- CWE-26 - Path Traversal: '/dir/../filename'
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder |
Affected:
0 , ≤ 6.3.316
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
"vendor": "WebRehab",
"versions": [
{
"lessThanOrEqual": "6.3.316",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "afei"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional \u0027file_upload_auth\u0027 setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin\u0027s file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-26",
"description": "CWE-26 Path Traversal: \u0027/dir/../filename\u0027",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:18.601Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc3df045-1020-403f-8e10-a1b75261b769?source=cve"
},
{
"url": "https://github.com/RensTillmann/super-forms/pull/205"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-15T18:14:05.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:32:09.000Z",
"value": "Disclosed"
}
],
"title": "Super Forms \u003c= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via \u0027sfgtfi\u0027 URL Path Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15896",
"datePublished": "2026-10-02T05:30:18.601Z",
"dateReserved": "2026-07-15T17:58:41.955Z",
"dateUpdated": "2026-10-02T05:30:18.601Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78471 (GCVE-0-2026-78471)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Summary
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders.
Severity
5.4 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| optimizingmatters | Autoptimize |
Affected:
0 , ≤ 3.1.15.1
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Autoptimize",
"vendor": "optimizingmatters",
"versions": [
{
"lessThanOrEqual": "3.1.15.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "theviper17y"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize\u0027s \u0027Lazy-load images?\u0027 option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:18.257Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b14f574d-1490-423e-9ef3-ce8f844cb8f0?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L1232"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L960"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L908"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3713884%40autoptimize%2Ftags%2F3.1.16\u0026old=3657650%40autoptimize%2Ftags%2F3.1.15.1"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3713884/autoptimize/trunk/classes/autoptimizeImages.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-08-24T17:04:26.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:42:10.000Z",
"value": "Disclosed"
}
],
"title": "Autoptimize \u003c= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-78471",
"datePublished": "2026-10-02T05:30:18.257Z",
"dateReserved": "2026-08-24T16:49:16.127Z",
"dateUpdated": "2026-10-02T05:30:18.257Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92174 (GCVE-0-2026-92174)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
Summary
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.
Severity
7.5 (High)
CWE
- CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| gpriday | SiteOrigin Widgets Bundle |
Affected:
0 , ≤ 1.73.2
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "SiteOrigin Widgets Bundle",
"vendor": "gpriday",
"versions": [
{
"lessThanOrEqual": "1.73.2",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "kiemtiendinhau"
}
],
"descriptions": [
{
"lang": "en",
"value": "The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the \u0027theme\u0027 parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:17.908Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a184ee1a-5fe2-47d5-8db1-a226c73e5bb1?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/base/siteorigin-widget.class.php#L214"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/base/inc/routes/siteorigin-widgets-resource.class.php#L140"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/compat/block-editor/widget-block.php#L710"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/widgets/price-table/price-table.php#L450"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/widgets/price-table/price-table.php#L332"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3605767/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T16:47:11.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:32:57.000Z",
"value": "Disclosed"
}
],
"title": "SiteOrigin Widgets Bundle \u003c= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via \u0027theme\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-92174",
"datePublished": "2026-10-02T05:30:17.908Z",
"dateReserved": "2026-09-15T17:56:19.851Z",
"dateUpdated": "2026-10-02T05:30:17.908Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90438 (GCVE-0-2026-90438)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission
Summary
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled.
Severity
7.2 (High)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
11 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| kstover | Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder |
Affected:
0 , ≤ 3.15.4
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Ninja Forms \u2013 Contact Form Builder with Calculators, Quizzes, Signatures \u0026 AI Form Builder",
"vendor": "kstover",
"versions": [
{
"lessThanOrEqual": "3.15.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "UKO"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:17.547Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a159485d-ce5b-46e7-8e63-a72012ccc180?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/build/submissions.js#L1"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Helper.php#L261"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L308"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/AJAX/Controllers/Submission.php#L61"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/build/submissions.js#L1"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/Helper.php#L261"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/Database/Models/Submission.php#L308"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/AJAX/Controllers/Submission.php#L61"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3717122%40ninja-forms%2Ftags%2F3.15.5\u0026old=3705719%40ninja-forms%2Ftags%2F3.15.4"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3717122/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-11T20:31:25.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T17:13:05.000Z",
"value": "Disclosed"
}
],
"title": "Ninja Forms \u003c= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-90438",
"datePublished": "2026-10-02T05:30:17.547Z",
"dateReserved": "2026-09-11T20:06:06.961Z",
"dateUpdated": "2026-10-02T05:30:17.547Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15897 (GCVE-0-2026-15897)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
Summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.
Severity
8.8 (High)
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder |
Affected:
0 , ≤ 6.3.316
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
"vendor": "WebRehab",
"versions": [
{
"lessThanOrEqual": "6.3.316",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "d.v4n_s3c"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register \u0026 Login add-on\u0027s before_email_success_msg() function, in its register_login_action=\u0027update\u0027 flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action=\u0027update\u0027 with register_login_user_id_update=\u0027true\u0027) and then submit it with user_id set to an administrator\u0027s ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts \u2014 including administrators \u2014 resulting in account takeover and full site compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:17.190Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94297481-9ebb-42cb-9362-be8bc52b126f?source=cve"
},
{
"url": "https://github.com/RensTillmann/super-forms/pull/205"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-15T18:52:23.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:34:31.000Z",
"value": "Disclosed"
}
],
"title": "Super Forms \u2013 Drag \u0026 Drop Form Builder \u003c= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via \u0027user_id\u0027 Parameter in Register \u0026 Login"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15897",
"datePublished": "2026-10-02T05:30:17.190Z",
"dateReserved": "2026-07-15T18:15:21.788Z",
"dateUpdated": "2026-10-02T05:30:17.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92820 (GCVE-0-2026-92820)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
Summary
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
Severity
8.1 (High)
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| SaturdayDrive | Ninja Forms - File Uploads |
Affected:
0 , ≤ 3.3.34
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Ninja Forms - File Uploads",
"vendor": "SaturdayDrive",
"versions": [
{
"lessThanOrEqual": "3.3.34",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "daroo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload\u0027s file_path, which is then used without validation to attach a file to the form\u0027s notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin\u0027s External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:15.764Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d5f0ec1-abcb-4aa2-a130-53682fa13f00?source=cve"
},
{
"url": "https://ninjaforms.com/extensions/file-uploads/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-16T20:35:09.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:54:50.000Z",
"value": "Disclosed"
}
],
"title": "Ninja Forms - File Uploads \u003c= 3.3.34 - Unauthenticated Arbitrary File Upload"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-92820",
"datePublished": "2026-10-02T05:30:15.764Z",
"dateReserved": "2026-09-16T20:19:51.864Z",
"dateUpdated": "2026-10-02T05:30:15.764Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84925 (GCVE-0-2026-84925)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter
Summary
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox.
Severity
6.1 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ThemeFusion | Avada | Website Builder For WordPress & WooCommerce |
Affected:
0 , ≤ 7.16.1
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Avada | Website Builder For WordPress \u0026 WooCommerce",
"vendor": "ThemeFusion",
"versions": [
{
"lessThanOrEqual": "7.16.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "daroo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Avada | Website Builder For WordPress \u0026 WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u0027lang\u0027 parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:15.238Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4c3936aa-58d6-4ac0-a077-2faaed48828f?source=cve"
},
{
"url": "https://classic.avada.com/documentation/avada-changelog/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-02T16:14:12.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:39:02.000Z",
"value": "Disclosed"
}
],
"title": "Avada | Website Builder For WordPress \u0026 WooCommerce \u003c= 7.16.1 - Reflected Cross-Site Scripting via \u0027lang\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-84925",
"datePublished": "2026-10-02T05:30:15.238Z",
"dateReserved": "2026-09-02T15:58:18.740Z",
"dateUpdated": "2026-10-02T05:30:15.238Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-10026 (GCVE-0-2026-10026)
Vulnerability from cvelistv5 – Published: 2026-10-02 04:27 – Updated: 2026-10-02 04:27
VLAI
EPSS
VEX
Title
CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
Summary
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.
Severity
7.2 (High)
CWE
- CWE-94 - Improper Control of Generation of Code ('Code Injection')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| CTX | CTX Feed Pro |
Affected:
0 , ≤ 7.6.12
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CTX Feed Pro",
"vendor": "CTX",
"versions": [
{
"lessThanOrEqual": "7.6.12",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nguyen Truong (Roll)"
},
{
"lang": "en",
"type": "finder",
"value": "Phap Nguyen Anh"
}
],
"descriptions": [
{
"lang": "en",
"value": "The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the \u0027Feed Config\u0027 field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T04:27:11.832Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50aa4bff-60dd-469c-a8f0-be6dd2dfa91e?source=cve"
},
{
"url": "https://webappick.com/plugin/woocommerce-product-feed-pro/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T15:53:07.000Z",
"value": "Disclosed"
}
],
"title": "CTX Feed Pro \u003c= 7.6.12 - Authenticated (Administrator+) Remote Code Execution"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-10026",
"datePublished": "2026-10-02T04:27:11.832Z",
"dateReserved": "2026-05-28T18:09:26.014Z",
"dateUpdated": "2026-10-02T04:27:11.832Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19660 (GCVE-0-2026-19660)
Vulnerability from cvelistv5 – Published: 2026-10-02 04:27 – Updated: 2026-10-02 04:27
VLAI
EPSS
VEX
Title
Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
Summary
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.
Severity
9.8 (Critical)
CWE
- CWE-287 - Improper Authentication
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| DiviEngine | Divi Membership |
Affected:
0 , ≤ 2.3.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Divi Membership",
"vendor": "DiviEngine",
"versions": [
{
"lessThanOrEqual": "2.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "0xd4rk5id3"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user \u2014 including administrators \u2014 by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T04:27:11.341Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d650cda-341f-4772-9b67-1bac200e3fb7?source=cve"
},
{
"url": "https://diviengine.com/divi-membership-changelog/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T16:24:08.000Z",
"value": "Disclosed"
}
],
"title": "Divi Membership \u003c= 2.3.0 - Unauthenticated Authentication Bypass via \u0027paypal_param\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-19660",
"datePublished": "2026-10-02T04:27:11.341Z",
"dateReserved": "2026-08-12T20:11:51.671Z",
"dateUpdated": "2026-10-02T04:27:11.341Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93367 (GCVE-0-2026-93367)
Vulnerability from cvelistv5 – Published: 2026-10-02 03:38 – Updated: 2026-10-02 03:38
VLAI
EPSS
VEX
Title
Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
Summary
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.
Severity
7.2 (High)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wp-buy | Visitor Traffic Real Time Statistics pro |
Affected:
0 , ≤ 11.22
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Visitor Traffic Real Time Statistics pro",
"vendor": "wp-buy",
"versions": [
{
"lessThanOrEqual": "11.22",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rafie Muhammad"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST[\u0027page_title\u0027] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin\u0027s dashboard, the \u0027Traffic by Title\u0027 DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator\u0027s session."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:38:46.638Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a72261e5-7376-4a34-9264-27bd4f27e938?source=cve"
},
{
"url": "https://www.wp-buy.com/product/visitors-traffic-real-time-statistics-pro/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-21T13:05:40.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T14:53:24.000Z",
"value": "Disclosed"
}
],
"title": "Visitors Traffic Real Time Statistics Pro \u003c= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-93367",
"datePublished": "2026-10-02T03:38:46.638Z",
"dateReserved": "2026-09-17T18:58:09.010Z",
"dateUpdated": "2026-10-02T03:38:46.638Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-14378 (GCVE-0-2026-14378)
Vulnerability from cvelistv5 – Published: 2026-10-02 03:38 – Updated: 2026-10-02 03:38
VLAI
EPSS
VEX
Title
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
Summary
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.
Severity
9.8 (Critical)
CWE
- CWE-287 - Improper Authentication
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| dplugins | DevKit Pro |
Affected:
0 , ≤ 2.3.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "DevKit Pro",
"vendor": "dplugins",
"versions": [
{
"lessThanOrEqual": "2.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "h0xilo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor \u2014 including unauthenticated users \u2014 whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator\u0027s user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator\u0027s ID and granting the attacker a full administrator-level authenticated session and complete site takeover."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:38:46.144Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab3986a-69e0-442f-8e79-35b1bc5376d9?source=cve"
},
{
"url": "https://docs.dplugins.com/devkit/changelog"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-14T15:02:19.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T14:44:20.000Z",
"value": "Disclosed"
}
],
"title": "DevKit Pro \u003c= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via \u0027original_user_id\u0027 Cookie in Frontend Revert Switch Flow"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-14378",
"datePublished": "2026-10-02T03:38:46.144Z",
"dateReserved": "2026-07-01T20:35:33.849Z",
"dateUpdated": "2026-10-02T03:38:46.144Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92144 (GCVE-0-2026-92144)
Vulnerability from cvelistv5 – Published: 2026-10-01 09:26 – Updated: 2026-10-01 14:14
VLAI
EPSS
VEX
Title
Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
Summary
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form submission nonce is freely obtainable by unauthenticated users via the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the full attack chain exploitable without any authentication or prior account.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:14 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
9 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder |
Affected:
0 , ≤ 1.57.2
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92144",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:14:03.746988Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:14:09.835Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Forminator Forms \u2013 Contact Form, Payment Form \u0026 Custom Form Builder",
"vendor": "wpmudev",
"versions": [
{
"lessThanOrEqual": "1.57.2",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Luke Eldridge (system)"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Forminator Forms \u2013 Contact Form, Payment Form \u0026 Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via \u0027postdata-1[post-custom]\u0027 Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form submission nonce is freely obtainable by unauthenticated users via the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the full attack chain exploitable without any authentication or prior account."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T09:26:58.287Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f320d2-fd24-47b5-804d-31e3afdc31ba?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/class-core.php#L690"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/class-core.php#L756"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/fields/postdata.php#L1012"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/abstracts/abstract-class-front-action.php#L973"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/abstracts/abstract-class-front-action.php#L127"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/custom-forms/front/front-action.php#L3528"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3700709%40forminator%2Ftags%2F1.57.2.1\u0026old=3668424%40forminator%2Ftags%2F1.57.2"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3700690/forminator/trunk/library/abstracts/abstract-class-front-action.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-15T17:24:25.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:33:06.000Z",
"value": "Disclosed"
}
],
"title": "Forminator Forms \u003c= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via \u0027postdata-1[post-custom]\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-92144",
"datePublished": "2026-10-01T09:26:58.287Z",
"dateReserved": "2026-09-15T17:08:52.563Z",
"dateUpdated": "2026-10-01T14:14:09.835Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96256 (GCVE-0-2026-96256)
Vulnerability from cvelistv5 – Published: 2026-10-01 09:26 – Updated: 2026-10-01 09:26
VLAI
EPSS
VEX
Title
Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute
Summary
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker title/content values, which are stored as JSON and then decoded and concatenated directly into raw HTML by the frontend script's InfoWindow content builder. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity
6.4 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
9 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns |
Affected:
0 , ≤ 6.4.5
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Gutenberg Essential Blocks \u2013 Page Builder for Gutenberg Blocks \u0026 Patterns",
"vendor": "wpdevteam",
"versions": [
{
"lessThanOrEqual": "6.4.5",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Webbernaut"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Gutenberg Essential Blocks \u2013 Page Builder for Gutenberg Blocks \u0026 Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block\u0027s \u0027marker\u0027 attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker title/content values, which are stored as JSON and then decoded and concatenated directly into raw HTML by the frontend script\u0027s InfoWindow content builder. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T09:26:57.815Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/606f25d9-f8c7-416a-8bb8-0cc57901ff5a?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.4.5/assets/blocks/google-map/frontend.js#L1"
},
{
"url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.4.5/includes/Blocks/GoogleMap.php#L82"
},
{
"url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.4.5/src/blocks/google-map/src/save.js#L35"
},
{
"url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.3.0/assets/blocks/google-map/frontend.js#L1"
},
{
"url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.3.0/includes/Blocks/GoogleMap.php#L82"
},
{
"url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.3.0/src/blocks/google-map/src/save.js#L35"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3715353%40essential-blocks%2Ftags%2F6.4.6\u0026old=3706819%40essential-blocks%2Ftags%2F6.4.5"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3715353/essential-blocks/trunk/assets/blocks/google-map/frontend.js"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T19:37:10.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:30:35.000Z",
"value": "Disclosed"
}
],
"title": "Gutenberg Essential Blocks \u003c= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via \u0027marker\u0027 Attribute"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-96256",
"datePublished": "2026-10-01T09:26:57.815Z",
"dateReserved": "2026-09-22T19:20:02.066Z",
"dateUpdated": "2026-10-01T09:26:57.815Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97661 (GCVE-0-2026-97661)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:18
VLAI
EPSS
VEX
Title
Business Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field
Summary
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Payments module to be enabled and a form to be configured to accept both PayPal and Stripe as payment gateways.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:18 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| scottpaterson | Business Essentials for Contact Form 7 |
Affected:
0 , ≤ 1.2.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97661",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:18:29.974570Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:18:37.934Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Business Essentials for Contact Form 7",
"vendor": "scottpaterson",
"versions": [
{
"lessThanOrEqual": "1.2.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Adrien Brunner"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via \u0027gateway\u0027 Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Payments module to be enabled and a form to be configured to accept both PayPal and Stripe as payment gateways."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:45.774Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e6a60043-a060-472b-9b43-e82a4d2420b0?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/cf7-redirect-thank-you-page/tags/1.2.1/includes/modules/payments/redirect_methods.php#L205"
},
{
"url": "https://plugins.trac.wordpress.org/browser/cf7-redirect-thank-you-page/tags/1.2.1/includes/modules/payments/functions.php#L15"
},
{
"url": "https://plugins.trac.wordpress.org/browser/cf7-redirect-thank-you-page/tags/1.2.1/includes/modules/payments/cpt.php#L313"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3713721/cf7-redirect-thank-you-page"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-24T19:43:37.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:15:27.000Z",
"value": "Disclosed"
}
],
"title": "Business Essentials for Contact Form 7 \u003c= 1.2.1 - Unauthenticated Stored Cross-Site Scripting via \u0027gateway\u0027 Form Field"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-97661",
"datePublished": "2026-10-01T08:28:45.774Z",
"dateReserved": "2026-09-24T19:39:58.461Z",
"dateUpdated": "2026-10-01T18:18:37.934Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89424 (GCVE-0-2026-89424)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 14:13
VLAI
EPSS
VEX
Title
Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter
Summary
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:13 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| inisev | Duplicate Post |
Affected:
0 , ≤ 1.5.6
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89424",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:13:40.454787Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:13:50.290Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Duplicate Post",
"vendor": "inisev",
"versions": [
{
"lessThanOrEqual": "1.5.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Kuba"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027noti_token\u0027 parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin\u0027s User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:45.432Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c475c51e-f01d-4698-822f-5b8df999bf6d?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.5.6/menu/notifications.php#L53"
},
{
"url": "https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.5.6/menu/notifications.php#L84"
},
{
"url": "https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.5.6/post/handler.php#L1598"
},
{
"url": "https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.5.6/post/handler.php#L1601"
},
{
"url": "https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.5.6/post/handler.php#L15"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3709767%40copy-delete-posts%2Ftags%2F1.5.7\u0026old=3652254%40copy-delete-posts%2Ftags%2F1.5.6"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3709767/copy-delete-posts/trunk/menu/notifications.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-11T18:46:23.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T19:57:20.000Z",
"value": "Disclosed"
}
],
"title": "Duplicate Post \u003c= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via \u0027noti_token\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-89424",
"datePublished": "2026-10-01T08:28:45.432Z",
"dateReserved": "2026-09-11T18:30:36.215Z",
"dateUpdated": "2026-10-01T14:13:50.290Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89427 (GCVE-0-2026-89427)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter
Summary
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature.
Severity
6.1 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| spacetime | Ad Inserter – Ad Manager & AdSense Ads |
Affected:
0 , ≤ 2.8.18
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Ad Inserter \u2013 Ad Manager \u0026 AdSense Ads",
"vendor": "spacetime",
"versions": [
{
"lessThanOrEqual": "2.8.18",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Kuba"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ad Inserter \u2013 Ad Manager \u0026 AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via \u0027s\u0027 Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:45.082Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c01f98a4-c349-4cb2-b09a-5cbadfcad830?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L13081"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L13012"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.18/ad-inserter.php#L12903"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3709970%40ad-inserter%2Ftags%2F2.8.19\u0026old=3624916%40ad-inserter%2Ftags%2F2.8.18"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3709957/ad-inserter/trunk/ad-inserter.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-11T18:58:31.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:28:37.000Z",
"value": "Disclosed"
}
],
"title": "Ad Inserter \u003c= 2.8.18 - Reflected Cross-Site Scripting via \u0027s\u0027 Search Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-89427",
"datePublished": "2026-10-01T08:28:45.082Z",
"dateReserved": "2026-09-11T18:43:11.240Z",
"dateUpdated": "2026-10-01T08:28:45.082Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96813 (GCVE-0-2026-96813)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields
Summary
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity
7.2 (High)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
13 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder |
Affected:
0 , ≤ 1.15.47
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Form Maker by 10Web \u2013 Mobile-Friendly Drag \u0026 Drop Contact Form Builder",
"vendor": "10web",
"versions": [
{
"lessThanOrEqual": "1.15.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "lhking"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Form Maker by 10Web \u2013 Mobile-Friendly Drag \u0026 Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:44.737Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/87fa5b87-1b32-4d00-8b43-fd51416d3099?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.47/admin/views/FMMapEditinPopup.php#L35"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.47/admin/controllers/FormMakerMapEditinPopup.php#L31"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.47/admin/views/Submissions_fm.php#L626"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.47/frontend/models/form_maker.php#L1651"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.47/framework/WDW_FM_Library.php#L366"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.44/admin/views/FMMapEditinPopup.php#L35"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.44/admin/controllers/FormMakerMapEditinPopup.php#L31"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.44/admin/views/Submissions_fm.php#L626"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.44/frontend/models/form_maker.php#L1651"
},
{
"url": "https://plugins.trac.wordpress.org/browser/form-maker/tags/1.15.44/framework/WDW_FM_Library.php#L366"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3716589%40form-maker%2Ftags%2F1.15.48\u0026old=3686568%40form-maker%2Ftags%2F1.15.47"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3716587/form-maker/trunk/admin/views/FMMapEditinPopup.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T17:29:21.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T19:51:50.000Z",
"value": "Disclosed"
}
],
"title": "Form Maker by 10Web \u003c= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-96813",
"datePublished": "2026-10-01T08:28:44.737Z",
"dateReserved": "2026-09-23T17:13:46.431Z",
"dateUpdated": "2026-10-01T08:28:44.737Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100184 (GCVE-0-2026-100184)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value
Summary
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a 'url.<name>' Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature.
Severity
4.7 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| codepeople | Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More |
Affected:
0 , ≤ 5.5.1.3
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Calculated Fields Form \u2013 AI Form Builder for WordPress \u2013 Contact, Payment, Quote, Quiz \u0026 More",
"vendor": "codepeople",
"versions": [
{
"lessThanOrEqual": "5.5.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "UKO"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Calculated Fields Form \u2013 AI Form Builder for WordPress \u2013 Contact, Payment, Quote, Quiz \u0026 More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the \u0027x (attacker-chosen name matching the form\u0027s url.\u003cname\u003e predefined value)\u0027 parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the targeted form has a Text Area field configured with a \u0027url.\u003cname\u003e\u0027 Predefined Value and predefinedClick disabled, which is a documented and commonly used plugin feature."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:44.400Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f1d2fe6-6cee-4e21-85ac-37d2d48156d2?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/fbuilder-pro-public.jquery.js#L692"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/fields-public/05_fbuilder.ftextarea.js#L23"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/fbuilder-pro-public.jquery.js#L1288"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/modules/08_url/public/01_url.js#L140"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3713574%40calculated-fields-form\u0026new=3713574%40calculated-fields-form"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T13:55:25.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:14:54.000Z",
"value": "Disclosed"
}
],
"title": "Calculated Fields Form \u003c= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via \u0027x\u0027 URL Query Parameter via Text Area Predefined Value"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-100184",
"datePublished": "2026-10-01T08:28:44.400Z",
"dateReserved": "2026-09-25T13:40:20.684Z",
"dateUpdated": "2026-10-01T08:28:44.400Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96268 (GCVE-0-2026-96268)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:20
VLAI
EPSS
VEX
Title
Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action
Summary
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:20 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin |
Affected:
0 , ≤ 6.4.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96268",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:20:13.900024Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:20:21.281Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Awesome Support \u2013 WordPress HelpDesk \u0026 Support Plugin",
"vendor": "awesomesupport",
"versions": [
{
"lessThanOrEqual": "6.4.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nhien Pham (nhienit) (nhienit)"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Awesome Support \u2013 WordPress HelpDesk \u0026 Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027gdpr-data\u0027 parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:44.069Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/617afd4e-107a-48ad-9e3e-1771874796ff?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.4.0/includes/gdpr-integration/gdpr-user-profile.php#L250"
},
{
"url": "https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.4.0/includes/gdpr-integration/gdpr-privacy-options.php#L1186"
},
{
"url": "https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.4.0/includes/gdpr-integration/gdpr-privacy-options.php#L1111"
},
{
"url": "https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.4.0/includes/functions-user.php#L1538"
},
{
"url": "https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.4.0/includes/functions-general.php#L2190"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3719753%40awesome-support\u0026new=3719753%40awesome-support"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T20:41:37.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:12:07.000Z",
"value": "Disclosed"
}
],
"title": "Awesome Support \u003c= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via \u0027gdpr-data\u0027 Parameter via wpas_gdpr_user_opt_out AJAX Action"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-96268",
"datePublished": "2026-10-01T08:28:44.069Z",
"dateReserved": "2026-09-22T20:26:44.298Z",
"dateUpdated": "2026-10-01T18:20:21.281Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95687 (GCVE-0-2026-95687)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint
Summary
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.
Severity
8.8 (High)
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpclever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 2.0.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "2.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "clever"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user\u0027s role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator\u0027s user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator\u0027s password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:43.728Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/539cdee3-78bc-42a2-9c34-0f7d46f95d16?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L253"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L228"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L96"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3708414%40wpc-shop-as-customer%2Ftags%2F2.0.1\u0026old=3708360%40wpc-shop-as-customer%2Ftags%2F2.0.0"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3708414/wpc-shop-as-customer/trunk/wpc-shop-as-customer.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T14:29:24.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T19:45:46.000Z",
"value": "Disclosed"
}
],
"title": "WPC Shop as a Customer for WooCommerce \u003c= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-95687",
"datePublished": "2026-10-01T08:28:43.728Z",
"dateReserved": "2026-09-22T14:14:09.896Z",
"dateUpdated": "2026-10-01T08:28:43.728Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101925 (GCVE-0-2026-101925)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:21
VLAI
EPSS
VEX
Title
bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name
Summary
The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a <pre> block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:21 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| robin-w | bbp style pack |
Affected:
0 , ≤ 6.4.8
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101925",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:21:15.523000Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:21:22.142Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "bbp style pack",
"vendor": "robin-w",
"versions": [
{
"lessThanOrEqual": "6.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "zickzick2"
}
],
"descriptions": [
{
"lang": "en",
"value": "The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u0027display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)\u0027 parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a \u0026lt;pre\u0026gt; block, which prevents WordPress\u0027s wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:43.363Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/31c9b86b-c971-4a0b-95ef-10bc7781e93f?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L249"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L223"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L244"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L83"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.8/includes/functions_quote.php#L275"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3719484%40bbp-style-pack\u0026new=3719484%40bbp-style-pack"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T16:19:12.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:12:56.000Z",
"value": "Disclosed"
}
],
"title": "bbp style pack \u003c= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-101925",
"datePublished": "2026-10-01T08:28:43.363Z",
"dateReserved": "2026-09-28T16:04:07.165Z",
"dateUpdated": "2026-10-01T18:21:22.142Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96573 (GCVE-0-2026-96573)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 14:13
VLAI
EPSS
VEX
Title
Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer
Summary
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'list_readmore_numberofwords' Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:13 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| codepeople | Appointment Hour Booking – Booking Calendar |
Affected:
0 , ≤ 1.5.97
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96573",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:13:16.706277Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:13:25.726Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Appointment Hour Booking \u2013 Booking Calendar",
"vendor": "codepeople",
"versions": [
{
"lessThanOrEqual": "1.5.97",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Zackary Loevseth"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Appointment Hour Booking \u2013 Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the \u0027list_readmore_numberofwords\u0027 Other Parameters setting to be configured with a positive integer value; the default value of 0 bypasses the decode-and-truncate branch entirely and is not exploitable through this sink."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:42.513Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3044e60f-b930-42db-ba5d-656e71b84226?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/mv/js/jquery.calendar.js"
},
{
"url": "https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1473"
},
{
"url": "https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1609"
},
{
"url": "https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/cp-main-class.inc.php#L1745"
},
{
"url": "https://plugins.trac.wordpress.org/browser/appointment-hour-booking/tags/1.5.97/classes/cp-base-class.inc.php#L81"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3718725%40appointment-hour-booking\u0026new=3718725%40appointment-hour-booking"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T13:43:40.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:09:56.000Z",
"value": "Disclosed"
}
],
"title": "Appointment Hour Booking \u003c= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-96573",
"datePublished": "2026-10-01T08:28:42.513Z",
"dateReserved": "2026-09-23T13:27:20.103Z",
"dateUpdated": "2026-10-01T14:13:25.726Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85235 (GCVE-0-2026-85235)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:22
VLAI
EPSS
VEX
Title
Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Summary
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:22 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder |
Affected:
0 , ≤ 1.57.2
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85235",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:22:24.616308Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:22:36.089Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Forminator Forms \u2013 Contact Form, Payment Form \u0026 Custom Form Builder",
"vendor": "wpmudev",
"versions": [
{
"lessThanOrEqual": "1.57.2",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "tiborisaak"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Forminator Forms \u2013 Contact Form, Payment Form \u0026 Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core\u0027s jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker\u0027s payload in the administrator\u0027s authenticated wp-admin session."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:42.179Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ff3d390-ad00-4233-ab25-f1afb679300e?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.1/admin/views/custom-form/entries/content-details.php#L213"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.1/library/helpers/helper-forms.php#L1295"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.1/library/fields/textarea.php#L405"
},
{
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.1/library/abstracts/abstract-class-front-action.php#L127"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3700709%40forminator%2Ftags%2F1.57.2.1\u0026old=3668424%40forminator%2Ftags%2F1.57.2"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-03T15:13:12.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:25:18.000Z",
"value": "Disclosed"
}
],
"title": "Forminator Forms \u003c= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-85235",
"datePublished": "2026-10-01T08:28:42.179Z",
"dateReserved": "2026-09-03T14:57:57.478Z",
"dateUpdated": "2026-10-01T18:22:36.089Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92244 (GCVE-0-2026-92244)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 14:10
VLAI
EPSS
VEX
Title
PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields
Summary
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives initial storage because WooCommerce's sanitize_text_field() and wc_clean() do not strip entity-encoded strings containing no literal '<' character, allowing unauthenticated guest-checkout orders to plant the malicious content.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:10 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpovernight | PDF Invoices & Packing Slips for WooCommerce |
Affected:
0 , ≤ 5.16.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92244",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:10:42.722900Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:10:55.917Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "PDF Invoices \u0026 Packing Slips for WooCommerce",
"vendor": "wpovernight",
"versions": [
{
"lessThanOrEqual": "5.16.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Kuba"
}
],
"descriptions": [
{
"lang": "en",
"value": "The PDF Invoices \u0026 Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives initial storage because WooCommerce\u0027s sanitize_text_field() and wc_clean() do not strip entity-encoded strings containing no literal \u0027\u003c\u0027 character, allowing unauthenticated guest-checkout orders to plant the malicious content."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:41.843Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ec3bd67-6e4b-46b6-8027-feeea149f3a4?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.16.1/assets/js/admin-script.js#L766"
},
{
"url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.16.1/includes/Settings.php#L470"
},
{
"url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.16.1/wpo-ips-functions.php#L658"
},
{
"url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.16.1/includes/Settings.php#L409"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3707106%40woocommerce-pdf-invoices-packing-slips%2Ftags%2F5.16.2\u0026old=3658456%40woocommerce-pdf-invoices-packing-slips%2Ftags%2F5.16.1"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-15T20:33:53.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:22:53.000Z",
"value": "Disclosed"
}
],
"title": "PDF Invoices \u0026 Packing Slips for WooCommerce \u003c= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-92244",
"datePublished": "2026-10-01T08:28:41.843Z",
"dateReserved": "2026-09-15T20:18:42.426Z",
"dateUpdated": "2026-10-01T14:10:55.917Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15983 (GCVE-0-2026-15983)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter
Summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.
Severity
8.1 (High)
CWE
- CWE-73 - External Control of File Name or Path
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder |
Affected:
0 , ≤ 6.3.316
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
"vendor": "WebRehab",
"versions": [
{
"lessThanOrEqual": "6.3.316",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "d.v4n_s3c"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check \u2014 allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting \u2014 combined with the `super_submit_form` handler\u0027s `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST[\u0027data\u0027]` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-73",
"description": "CWE-73 External Control of File Name or Path",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:41.509Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/25704473-1200-49df-aa16-9a9558bb4844?source=cve"
},
{
"url": "https://github.com/RensTillmann/super-forms/pull/205"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-16T17:31:50.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:15:01.000Z",
"value": "Disclosed"
}
],
"title": "Super Forms \u003c= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via \u0027subdir\u0027 / \u0027path\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15983",
"datePublished": "2026-10-01T08:28:41.509Z",
"dateReserved": "2026-07-16T17:09:44.014Z",
"dateUpdated": "2026-10-01T08:28:41.509Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90992 (GCVE-0-2026-90992)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 18:25
VLAI
EPSS
VEX
Title
Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field
Summary
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:24 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| davidanderson | Redux Framework |
Affected:
0 , ≤ 4.5.14
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90992",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:24:23.758653Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:25:50.057Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Redux Framework",
"vendor": "davidanderson",
"versions": [
{
"lessThanOrEqual": "4.5.14",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "daroo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via \u0027user-mediaurl\u0027 Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:41.178Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2274a464-4eeb-4c8a-b138-44fef6b4a3a5?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/assets/js/vendor/jsonview.js#L136"
},
{
"url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/users/class-redux-extension-users.php#L365"
},
{
"url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/extensions/users/class-redux-users-api.php#L558"
},
{
"url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/classes/class-redux-options-constructor.php#L632"
},
{
"url": "https://plugins.trac.wordpress.org/browser/redux-framework/tags/4.5.14/redux-core/inc/classes/class-redux-options-constructor.php#L189"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3705066%40redux-framework%2Ftags%2F4.5.15\u0026old=3688279%40redux-framework%2Ftags%2F4.5.14"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3705066/redux-framework/trunk/redux-core/assets/js/vendor/jsonview.js"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-14T15:22:31.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:01:14.000Z",
"value": "Disclosed"
}
],
"title": "Redux Framework \u003c= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via \u0027user-mediaurl\u0027 Media Field"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-90992",
"datePublished": "2026-10-01T08:28:41.178Z",
"dateReserved": "2026-09-14T14:30:20.066Z",
"dateUpdated": "2026-10-01T18:25:50.057Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100179 (GCVE-0-2026-100179)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 14:07
VLAI
EPSS
VEX
Title
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()
Summary
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the target site to have a public form configured with a Select2-enabled dropdown whose choices are populated via a calculated equation that pipes a URL parameter through GETURLPARAMETER() into setChoices({texts:[...]}); given that configuration, exploitation requires only a single crafted link.
Severity
6.1 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:06 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| codepeople | Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More |
Affected:
0 , ≤ 5.5.1.3
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100179",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:06:04.022587Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:07:25.580Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Calculated Fields Form \u2013 AI Form Builder for WordPress \u2013 Contact, Payment, Quote, Quiz \u0026 More",
"vendor": "codepeople",
"versions": [
{
"lessThanOrEqual": "5.5.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "UKO"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Calculated Fields Form \u2013 AI Form Builder for WordPress \u2013 Contact, Payment, Quote, Quiz \u0026 More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the \u0027x (any URL parameter consumed by the form\u0027s calculated equation)\u0027 parameter in all versions up to, and including, 5.5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the target site to have a public form configured with a Select2-enabled dropdown whose choices are populated via a calculated equation that pipes a URL parameter through GETURLPARAMETER() into setChoices({texts:[...]}); given that configuration, exploitation requires only a single crafted link."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:40.837Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/215a9f92-e922-4fa3-a4ac-83af788f4e55?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/fields-public/08_fbuilder.fdropdown.js#L84"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/fields-public/08_fbuilder.fdropdown.js#L240"
},
{
"url": "https://plugins.trac.wordpress.org/browser/calculated-fields-form/tags/5.5.1.2/js/modules/08_url/public/01_url.js"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3713574%40calculated-fields-form\u0026new=3713574%40calculated-fields-form"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T13:50:57.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:14:18.000Z",
"value": "Disclosed"
}
],
"title": "Calculated Fields Form \u003c= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via \u0027x\u0027 URL Parameter via setChoices()"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-100179",
"datePublished": "2026-10-01T08:28:40.837Z",
"dateReserved": "2026-09-25T13:35:52.516Z",
"dateUpdated": "2026-10-01T14:07:25.580Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-14995 (GCVE-0-2026-14995)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 14:02
VLAI
EPSS
VEX
Title
Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path
Summary
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Critical CSS feature to be active with a valid API key configured, as this is the precondition for unauthenticated frontend requests to trigger queue entries via ao_ccss_enqueue().
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:02 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| optimizingmatters | Autoptimize |
Affected:
0 , ≤ 3.1.15.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-14995",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:02:35.543960Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:02:56.840Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Autoptimize",
"vendor": "optimizingmatters",
"versions": [
{
"lessThanOrEqual": "3.1.15.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "lhking"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Critical CSS feature to be active with a valid API key configured, as this is the precondition for unauthenticated frontend requests to trigger queue entries via ao_ccss_enqueue()."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:40.341Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1704cffa-75ed-415e-864f-de7ff8eea8dc?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/critcss-inc/admin_settings_queue.js.php#L125"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeCriticalCSSEnqueue.php#L57"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeCriticalCSSEnqueue.php#L218"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/critcss-inc/admin_settings_queue.php#L82"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3713884%40autoptimize\u0026new=3713884%40autoptimize"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-07T19:13:00.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T20:10:48.000Z",
"value": "Disclosed"
}
],
"title": "Autoptimize \u003c= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-14995",
"datePublished": "2026-10-01T08:28:40.341Z",
"dateReserved": "2026-07-07T18:57:46.336Z",
"dateUpdated": "2026-10-01T14:02:56.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19807 (GCVE-0-2026-19807)
Vulnerability from cvelistv5 – Published: 2026-10-01 07:40 – Updated: 2026-10-01 07:40
VLAI
EPSS
VEX
Title
ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
Summary
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.
Severity
8.8 (High)
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
13 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| bytecorestack | ByteCoreStack – MCP Connector for AI Tools |
Affected:
0 , ≤ 1.2.3
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ByteCoreStack \u2013 MCP Connector for AI Tools",
"vendor": "bytecorestack",
"versions": [
{
"lessThanOrEqual": "1.2.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "D\u00e9cio Brand\u00e3o"
}
],
"descriptions": [
{
"lang": "en",
"value": "The ByteCoreStack \u2013 MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can(\u0027edit_user\u0027, $uid)` \u2014 a check that WordPress core\u0027s `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller\u0027s own \u2014 while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{\u0027administrator\u0027: true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T07:40:24.252Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ac09bf3e-49cf-4f11-92ba-d1fbf6f587d7?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L2046"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L2042"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L2044"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L332"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/OAuth/Server.php#L122"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2046"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2042"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2044"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L332"
},
{
"url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/OAuth/Server.php#L122"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3711909%40bcs-mcp-manager%2Ftags%2F1.2.4\u0026old=3711721%40bcs-mcp-manager%2Ftags%2F1.2.3"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3711908/bcs-mcp-manager/trunk/includes/MCP/Server.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T19:31:11.000Z",
"value": "Disclosed"
}
],
"title": "ByteCoreStack \u003c= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-19807",
"datePublished": "2026-10-01T07:40:24.252Z",
"dateReserved": "2026-08-13T21:31:00.532Z",
"dateUpdated": "2026-10-01T07:40:24.252Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15989 (GCVE-0-2026-15989)
Vulnerability from cvelistv5 – Published: 2026-10-01 07:40 – Updated: 2026-10-01 13:47
VLAI
EPSS
VEX
Title
Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
Summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:43 UTC
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder |
Affected:
0 , ≤ 6.3.316
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15989",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:43:13.238462Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:47:45.799Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
"vendor": "WebRehab",
"versions": [
{
"lessThanOrEqual": "6.3.316",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "d.v4n_s3c"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register \u0026 Login add-on\u0027s before_email_success_msg() function whitelisting the client-submitted \u0027role\u0027 key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action=\u0027register\u0027)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T07:40:23.893Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7eb62d35-3f0e-4733-8f7f-723d0f25b710?source=cve"
},
{
"url": "https://github.com/RensTillmann/super-forms/pull/205"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-16T19:55:18.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T19:23:33.000Z",
"value": "Disclosed"
}
],
"title": "Super Forms \u003c= 6.3.316 - Unauthenticated Privilege Escalation via \u0027role\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15989",
"datePublished": "2026-10-01T07:40:23.893Z",
"dateReserved": "2026-07-16T19:39:59.927Z",
"dateUpdated": "2026-10-01T13:47:45.799Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}