Search

Find a vulnerability

Search criteria

    378997 vulnerabilities

    CVE-2026-97318 (GCVE-0-2026-97318)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter
    Summary
    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/a171b0f1-b2d2-44… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Giveaways and Contests by RafflePress Affected: 0 , < 1.12.27 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Giveaways and Contests by RafflePress",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.12.27",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dick Snel"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not properly validate a giveaway\u0027s parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site\u0027s own giveaway confirmation and referral links redirect visitors to an arbitrary external site."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:27.170Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/a171b0f1-b2d2-4482-b44f-bd4a1f3b223b/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Giveaways and Contests by RafflePress \u003c 1.12.27 - Unauthenticated Stored Open Redirect via \u0027parent_url\u0027 Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-97318",
        "datePublished": "2026-10-02T06:00:27.170Z",
        "dateReserved": "2026-09-24T11:27:52.068Z",
        "dateUpdated": "2026-10-02T06:00:27.170Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97317 (GCVE-0-2026-97317)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page
    Summary
    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/f8779fd4-f362-40… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Giveaways and Contests by RafflePress Affected: 0 , < 1.12.27 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Giveaways and Contests by RafflePress",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.12.27",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dmitrii Ignatyev"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Information Exposure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:26.940Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/f8779fd4-f362-40c4-8df1-145620c69103/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Giveaways and Contests by RafflePress \u003c 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-97317",
        "datePublished": "2026-10-02T06:00:26.940Z",
        "dateReserved": "2026-09-24T11:27:48.588Z",
        "dateUpdated": "2026-10-02T06:00:26.940Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94298 (GCVE-0-2026-94298)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter
    Summary
    The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/6f6c8718-7e7e-47… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown BuildKit Affected: 0 , < 1.0.29 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "BuildKit",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.0.29",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Naiches"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The BuildKit  WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-89 SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:26.412Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/6f6c8718-7e7e-4700-a4c2-ee177c44b7ea/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "BuildKit \u003c 1.0.29 - Contributor+ Stored SQLi via list_content Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-94298",
        "datePublished": "2026-10-02T06:00:26.412Z",
        "dateReserved": "2026-09-21T09:44:15.108Z",
        "dateUpdated": "2026-10-02T06:00:26.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91023 (GCVE-0-2026-91023)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured
    Summary
    The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/c2400c65-5d77-45… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Motors Affected: 0 , < 1.4.124 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Motors",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.4.124",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yaswanth Reddy Sunkara"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Motors  WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors  WordPress plugin before 1.4.124\u0027s paid featured-listing option is enabled, neither of which is a default configuration."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.876Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/c2400c65-5d77-454c-9691-5e664556341b/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Motors \u2013 Car Dealership \u0026 Classified Listings \u003c 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91023",
        "datePublished": "2026-10-02T06:00:25.876Z",
        "dateReserved": "2026-09-14T17:07:28.393Z",
        "dateUpdated": "2026-10-02T06:00:25.876Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91022 (GCVE-0-2026-91022)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color
    Summary
    The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/72672806-e2f3-41… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Motors Affected: 0 , < 1.4.124 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Motors",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.4.124",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yaswanth Reddy Sunkara"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Motors  WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.652Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/72672806-e2f3-417e-83c0-854c604028e4/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Motors \u003c 1.4.124 - Listing Manager+ Stored XSS via Badge Color",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91022",
        "datePublished": "2026-10-02T06:00:25.652Z",
        "dateReserved": "2026-09-14T17:07:10.725Z",
        "dateUpdated": "2026-10-02T06:00:25.652Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85016 (GCVE-0-2026-85016)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter
    Summary
    The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/1d488c84-2797-4c… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Unlimited Elements for Elementor Affected: 0 , < 2.0.21 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Unlimited Elements for Elementor",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Revanth Hari Narayana Matte"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.438Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/1d488c84-2797-4c02-8c13-54b80e4128dc/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unlimited Elements For Elementor \u003c 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-85016",
        "datePublished": "2026-10-02T06:00:25.438Z",
        "dateReserved": "2026-09-02T19:18:47.849Z",
        "dateUpdated": "2026-10-02T06:00:25.438Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91828 (GCVE-0-2026-91828)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    OMGF < 6.3.11 - Unauthenticated DoS via do_optimize
    Summary
    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/be25f7b5-5790-4d… exploitvdb-entrytechnical-description
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "6.3.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "\u00c1ngel Santana"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site\u0027s PHP worker pool and make the entire site unavailable."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.216Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/be25f7b5-5790-4db7-9056-b43b538a7183/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "OMGF \u003c 6.3.11 - Unauthenticated DoS via do_optimize",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91828",
        "datePublished": "2026-10-02T06:00:25.216Z",
        "dateReserved": "2026-09-15T08:11:48.154Z",
        "dateUpdated": "2026-10-02T06:00:25.216Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13718 (GCVE-0-2026-13718)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content
    Summary
    The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/ff0da7b7-f415-46… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Tabs Responsive Affected: 0 , ≤ 2.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Tabs Responsive",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "2.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "J4ck13Ch4n"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Tabs Responsive  WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.997Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/ff0da7b7-f415-466e-9f6e-4c559d2699a9/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Tabs Responsive \u003c= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-13718",
        "datePublished": "2026-10-02T06:00:24.997Z",
        "dateReserved": "2026-06-29T14:06:03.048Z",
        "dateUpdated": "2026-10-02T06:00:24.997Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90988 (GCVE-0-2026-90988)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum
    Summary
    The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/6c02759e-b37e-43… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Request a Quote Affected: 0 , ≤ 2.5.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Request a Quote",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "2.5.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Request a Quote  WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Information Exposure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.780Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/6c02759e-b37e-43ce-a4f4-467e8af63a17/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Request a Quote \u003c= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-90988",
        "datePublished": "2026-10-02T06:00:24.780Z",
        "dateReserved": "2026-09-14T13:58:23.882Z",
        "dateUpdated": "2026-10-02T06:00:24.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85004 (GCVE-0-2026-85004)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect
    Summary
    The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/38041b58-7738-47… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Popup Maker Affected: 0 , ≤ 1.4.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Popup Maker",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Popup Maker  WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker  WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.239Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/38041b58-7738-4710-a1b6-4005e9ec2c01/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Popup Maker WP \u003c= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-85004",
        "datePublished": "2026-10-02T06:00:24.239Z",
        "dateReserved": "2026-09-02T18:30:03.819Z",
        "dateUpdated": "2026-10-02T06:00:24.239Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-81740 (GCVE-0-2026-81740)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback
    Summary
    The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/13767875-5010-49… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Paytm Payment Gateway Affected: 0 , < 2.8.9 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Paytm Payment Gateway",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.8.9",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.014Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/13767875-5010-494a-b3ed-133d58b8ecea/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Paytm Payment Gateway \u003c 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-81740",
        "datePublished": "2026-10-02T06:00:24.014Z",
        "dateReserved": "2026-08-27T11:47:22.935Z",
        "dateUpdated": "2026-10-02T06:00:24.014Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15896 (GCVE-0-2026-15896)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
    CWE
    • CWE-26 - Path Traversal: '/dir/../filename'
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.316 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.316",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "afei"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional \u0027file_upload_auth\u0027 setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin\u0027s file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-26",
                  "description": "CWE-26 Path Traversal: \u0027/dir/../filename\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:18.601Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc3df045-1020-403f-8e10-a1b75261b769?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/pull/205"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-15T18:14:05.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:32:09.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u003c= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via \u0027sfgtfi\u0027 URL Path Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15896",
        "datePublished": "2026-10-02T05:30:18.601Z",
        "dateReserved": "2026-07-15T17:58:41.955Z",
        "dateUpdated": "2026-10-02T05:30:18.601Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78471 (GCVE-0-2026-78471)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
    Summary
    The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    optimizingmatters Autoptimize Affected: 0 , ≤ 3.1.15.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Autoptimize",
              "vendor": "optimizingmatters",
              "versions": [
                {
                  "lessThanOrEqual": "3.1.15.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "theviper17y"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize\u0027s \u0027Lazy-load images?\u0027 option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:18.257Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b14f574d-1490-423e-9ef3-ce8f844cb8f0?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L1232"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L960"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L908"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3713884%40autoptimize%2Ftags%2F3.1.16\u0026old=3657650%40autoptimize%2Ftags%2F3.1.15.1"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3713884/autoptimize/trunk/classes/autoptimizeImages.php"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-24T17:04:26.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:42:10.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Autoptimize \u003c= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-78471",
        "datePublished": "2026-10-02T05:30:18.257Z",
        "dateReserved": "2026-08-24T16:49:16.127Z",
        "dateUpdated": "2026-10-02T05:30:18.257Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92174 (GCVE-0-2026-92174)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
    Summary
    The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    Impacted products
    Vendor Product Version
    gpriday SiteOrigin Widgets Bundle Affected: 0 , ≤ 1.73.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SiteOrigin Widgets Bundle",
              "vendor": "gpriday",
              "versions": [
                {
                  "lessThanOrEqual": "1.73.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "kiemtiendinhau"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the \u0027theme\u0027 parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:17.908Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a184ee1a-5fe2-47d5-8db1-a226c73e5bb1?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/base/siteorigin-widget.class.php#L214"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/base/inc/routes/siteorigin-widgets-resource.class.php#L140"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/compat/block-editor/widget-block.php#L710"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/widgets/price-table/price-table.php#L450"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/widgets/price-table/price-table.php#L332"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3605767/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T16:47:11.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:32:57.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "SiteOrigin Widgets Bundle \u003c= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via \u0027theme\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-92174",
        "datePublished": "2026-10-02T05:30:17.908Z",
        "dateReserved": "2026-09-15T17:56:19.851Z",
        "dateUpdated": "2026-10-02T05:30:17.908Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90438 (GCVE-0-2026-90438)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission
    Summary
    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Ninja Forms \u2013 Contact Form Builder with Calculators, Quizzes, Signatures \u0026 AI Form Builder",
              "vendor": "kstover",
              "versions": [
                {
                  "lessThanOrEqual": "3.15.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "UKO"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:17.547Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a159485d-ce5b-46e7-8e63-a72012ccc180?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/build/submissions.js#L1"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Helper.php#L261"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L308"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/AJAX/Controllers/Submission.php#L61"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/build/submissions.js#L1"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/Helper.php#L261"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/Database/Models/Submission.php#L308"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/AJAX/Controllers/Submission.php#L61"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3717122%40ninja-forms%2Ftags%2F3.15.5\u0026old=3705719%40ninja-forms%2Ftags%2F3.15.4"
            },
            {
              "url": "https://plugins.trac.wordpress.org/changeset/3717122/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-11T20:31:25.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T17:13:05.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Ninja Forms \u003c= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-90438",
        "datePublished": "2026-10-02T05:30:17.547Z",
        "dateReserved": "2026-09-11T20:06:06.961Z",
        "dateUpdated": "2026-10-02T05:30:17.547Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15897 (GCVE-0-2026-15897)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.316 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.316",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "d.v4n_s3c"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register \u0026 Login add-on\u0027s before_email_success_msg() function, in its register_login_action=\u0027update\u0027 flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action=\u0027update\u0027 with register_login_user_id_update=\u0027true\u0027) and then submit it with user_id set to an administrator\u0027s ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts \u2014 including administrators \u2014 resulting in account takeover and full site compromise."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:17.190Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94297481-9ebb-42cb-9362-be8bc52b126f?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/pull/205"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-15T18:52:23.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:34:31.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u2013 Drag \u0026 Drop Form Builder \u003c= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via \u0027user_id\u0027 Parameter in Register \u0026 Login"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15897",
        "datePublished": "2026-10-02T05:30:17.190Z",
        "dateReserved": "2026-07-15T18:15:21.788Z",
        "dateUpdated": "2026-10-02T05:30:17.190Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92820 (GCVE-0-2026-92820)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
    Summary
    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Impacted products
    Vendor Product Version
    SaturdayDrive Ninja Forms - File Uploads Affected: 0 , ≤ 3.3.34 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Ninja Forms - File Uploads",
              "vendor": "SaturdayDrive",
              "versions": [
                {
                  "lessThanOrEqual": "3.3.34",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "daroo"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload\u0027s file_path, which is then used without validation to attach a file to the form\u0027s notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin\u0027s External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:15.764Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d5f0ec1-abcb-4aa2-a130-53682fa13f00?source=cve"
            },
            {
              "url": "https://ninjaforms.com/extensions/file-uploads/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T20:35:09.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:54:50.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Ninja Forms - File Uploads \u003c= 3.3.34 - Unauthenticated Arbitrary File Upload"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-92820",
        "datePublished": "2026-10-02T05:30:15.764Z",
        "dateReserved": "2026-09-16T20:19:51.864Z",
        "dateUpdated": "2026-10-02T05:30:15.764Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84925 (GCVE-0-2026-84925)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter
    Summary
    The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Avada | Website Builder For WordPress \u0026 WooCommerce",
              "vendor": "ThemeFusion",
              "versions": [
                {
                  "lessThanOrEqual": "7.16.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "daroo"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Avada | Website Builder For WordPress \u0026 WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u0027lang\u0027 parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:15.238Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4c3936aa-58d6-4ac0-a077-2faaed48828f?source=cve"
            },
            {
              "url": "https://classic.avada.com/documentation/avada-changelog/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-02T16:14:12.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:39:02.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Avada | Website Builder For WordPress \u0026 WooCommerce \u003c= 7.16.1 - Reflected Cross-Site Scripting via \u0027lang\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-84925",
        "datePublished": "2026-10-02T05:30:15.238Z",
        "dateReserved": "2026-09-02T15:58:18.740Z",
        "dateUpdated": "2026-10-02T05:30:15.238Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-10026 (GCVE-0-2026-10026)

    Vulnerability from cvelistv5 – Published: 2026-10-02 04:27 – Updated: 2026-10-02 04:27
    VLAI
    Title
    CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
    Summary
    The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    CTX CTX Feed Pro Affected: 0 , ≤ 7.6.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CTX Feed Pro",
              "vendor": "CTX",
              "versions": [
                {
                  "lessThanOrEqual": "7.6.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Nguyen Truong (Roll)"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Phap Nguyen Anh"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the \u0027Feed Config\u0027 field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T04:27:11.832Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50aa4bff-60dd-469c-a8f0-be6dd2dfa91e?source=cve"
            },
            {
              "url": "https://webappick.com/plugin/woocommerce-product-feed-pro/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T15:53:07.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "CTX Feed Pro \u003c= 7.6.12 - Authenticated (Administrator+) Remote Code Execution"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-10026",
        "datePublished": "2026-10-02T04:27:11.832Z",
        "dateReserved": "2026-05-28T18:09:26.014Z",
        "dateUpdated": "2026-10-02T04:27:11.832Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-19660 (GCVE-0-2026-19660)

    Vulnerability from cvelistv5 – Published: 2026-10-02 04:27 – Updated: 2026-10-02 04:27
    VLAI
    Title
    Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
    Summary
    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.
    CWE
    • CWE-287 - Improper Authentication
    Impacted products
    Vendor Product Version
    DiviEngine Divi Membership Affected: 0 , ≤ 2.3.0 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Divi Membership",
              "vendor": "DiviEngine",
              "versions": [
                {
                  "lessThanOrEqual": "2.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "0xd4rk5id3"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user \u2014 including administrators \u2014 by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T04:27:11.341Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d650cda-341f-4772-9b67-1bac200e3fb7?source=cve"
            },
            {
              "url": "https://diviengine.com/divi-membership-changelog/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T16:24:08.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Divi Membership \u003c= 2.3.0 - Unauthenticated Authentication Bypass via \u0027paypal_param\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-19660",
        "datePublished": "2026-10-02T04:27:11.341Z",
        "dateReserved": "2026-08-12T20:11:51.671Z",
        "dateUpdated": "2026-10-02T04:27:11.341Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93367 (GCVE-0-2026-93367)

    Vulnerability from cvelistv5 – Published: 2026-10-02 03:38 – Updated: 2026-10-02 03:38
    VLAI
    Title
    Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
    Summary
    The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    wp-buy Visitor Traffic Real Time Statistics pro Affected: 0 , ≤ 11.22 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Visitor Traffic Real Time Statistics pro",
              "vendor": "wp-buy",
              "versions": [
                {
                  "lessThanOrEqual": "11.22",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Rafie Muhammad"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST[\u0027page_title\u0027] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin\u0027s dashboard, the \u0027Traffic by Title\u0027 DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator\u0027s session."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T03:38:46.638Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a72261e5-7376-4a34-9264-27bd4f27e938?source=cve"
            },
            {
              "url": "https://www.wp-buy.com/product/visitors-traffic-real-time-statistics-pro/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-21T13:05:40.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T14:53:24.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Visitors Traffic Real Time Statistics Pro \u003c= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-93367",
        "datePublished": "2026-10-02T03:38:46.638Z",
        "dateReserved": "2026-09-17T18:58:09.010Z",
        "dateUpdated": "2026-10-02T03:38:46.638Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-14378 (GCVE-0-2026-14378)

    Vulnerability from cvelistv5 – Published: 2026-10-02 03:38 – Updated: 2026-10-02 03:38
    VLAI
    Title
    DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
    Summary
    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.
    CWE
    • CWE-287 - Improper Authentication
    Impacted products
    Vendor Product Version
    dplugins DevKit Pro Affected: 0 , ≤ 2.3.0 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "DevKit Pro",
              "vendor": "dplugins",
              "versions": [
                {
                  "lessThanOrEqual": "2.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "h0xilo"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor \u2014 including unauthenticated users \u2014 whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator\u0027s user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator\u0027s ID and granting the attacker a full administrator-level authenticated session and complete site takeover."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T03:38:46.144Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab3986a-69e0-442f-8e79-35b1bc5376d9?source=cve"
            },
            {
              "url": "https://docs.dplugins.com/devkit/changelog"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-14T15:02:19.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T14:44:20.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "DevKit Pro \u003c= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via \u0027original_user_id\u0027 Cookie in Frontend Revert Switch Flow"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-14378",
        "datePublished": "2026-10-02T03:38:46.144Z",
        "dateReserved": "2026-07-01T20:35:33.849Z",
        "dateUpdated": "2026-10-02T03:38:46.144Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104123 (GCVE-0-2026-104123)

    Vulnerability from cvelistv5 – Published: 2026-10-02 02:45 – Updated: 2026-10-02 02:45 X_Freeware
    VLAI
    Title
    SourceCodester Online Reviewer Management System btn_functions.php activity sql injection
    Summary
    A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/412765 vdb-entrytechnical-description
    https://vuldb.com/vuln/412765/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-104123 third-party-advisory
    https://vuldb.com/submit/961692 third-party-advisory
    https://github.com/lemssh77/cve/issues/1 exploitissue-tracking
    https://www.sourcecodester.com/ product
    Impacted products
    Vendor Product Version
    SourceCodester Online Reviewer Management System Affected: 1.0
        cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*"
              ],
              "product": "Online Reviewer Management System",
              "vendor": "SourceCodester",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Ethan.KY.WONG (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T02:45:13.229Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412765 | SourceCodester Online Reviewer Management System btn_functions.php activity sql injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412765"
            },
            {
              "name": "VDB-412765 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412765/cti"
            },
            {
              "name": "CVE-2026-104123 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-104123"
            },
            {
              "name": "Submit #961692 | SourceCodester Online Reviewer Management System using PHP/MySQL /reviewer_0/admins/assessments/activities/btn_functions.php?action=activi 1.0 SQL Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/961692"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/lemssh77/cve/issues/1"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.sourcecodester.com/"
            }
          ],
          "tags": [
            "x_freeware"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T20:34:13.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "SourceCodester Online Reviewer Management System btn_functions.php activity sql injection",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-104123",
        "datePublished": "2026-10-02T02:45:13.229Z",
        "dateReserved": "2026-10-01T18:29:07.832Z",
        "dateUpdated": "2026-10-02T02:45:13.229Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104120 (GCVE-0-2026-104120)

    Vulnerability from cvelistv5 – Published: 2026-10-02 02:15 – Updated: 2026-10-02 02:15
    VLAI
    Title
    modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery
    Summary
    A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    URL Tags
    https://vuldb.com/vuln/412764 vdb-entrytechnical-description
    https://vuldb.com/vuln/412764/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-104120 third-party-advisory
    https://vuldb.com/submit/960099 third-party-advisory
    https://github.com/modelcontextprotocol/servers/i… exploitissue-tracking
    https://github.com/modelcontextprotocol/servers/p… issue-trackingpatch
    Impacted products
    Vendor Product Version
    modelcontextprotocol mcp-server-fetch Affected: 2026.6.0
    Affected: 2026.6.1
    Affected: 2026.6.2
    Affected: 2026.6.3
    Affected: 2026.6.4
        cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:*
    Create a notification for this product.
    modelcontextprotocol mcp-server-everything Affected: 2026.6.0
    Affected: 2026.6.1
    Affected: 2026.6.2
    Affected: 2026.6.3
    Affected: 2026.6.4
        cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Fetch Tool"
              ],
              "product": "mcp-server-fetch",
              "vendor": "modelcontextprotocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026.6.0"
                },
                {
                  "status": "affected",
                  "version": "2026.6.1"
                },
                {
                  "status": "affected",
                  "version": "2026.6.2"
                },
                {
                  "status": "affected",
                  "version": "2026.6.3"
                },
                {
                  "status": "affected",
                  "version": "2026.6.4"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Fetch Tool"
              ],
              "product": "mcp-server-everything",
              "vendor": "modelcontextprotocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026.6.0"
                },
                {
                  "status": "affected",
                  "version": "2026.6.1"
                },
                {
                  "status": "affected",
                  "version": "2026.6.2"
                },
                {
                  "status": "affected",
                  "version": "2026.6.3"
                },
                {
                  "status": "affected",
                  "version": "2026.6.4"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "geochen (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T02:15:18.514Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412764 | modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412764"
            },
            {
              "name": "VDB-412764 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412764/cti"
            },
            {
              "name": "CVE-2026-104120 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-104120"
            },
            {
              "name": "Submit #960099 | https://github.com/modelcontextprotocol/ servers 2026.6.4 Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/960099"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/modelcontextprotocol/servers/issues/4492"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/modelcontextprotocol/servers/pull/4890"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T20:20:15.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-104120",
        "datePublished": "2026-10-02T02:15:18.514Z",
        "dateReserved": "2026-10-01T18:15:10.419Z",
        "dateUpdated": "2026-10-02T02:15:18.514Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104054 (GCVE-0-2026-104054)

    Vulnerability from cvelistv5 – Published: 2026-10-02 02:00 – Updated: 2026-10-02 02:00
    VLAI
    Title
    calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
    Summary
    A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/412762 vdb-entrytechnical-description
    https://vuldb.com/vuln/412762/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-104054 third-party-advisory
    https://vuldb.com/submit/959492 third-party-advisory
    https://github.com/calcom/cal.diy/issues/29802 exploitissue-tracking
    https://github.com/calcom/cal.diy/pull/30253 issue-trackingpatch
    https://github.com/calcom/cal.diy/ product
    Impacted products
    Vendor Product Version
    calcom cal.diy Affected: 6.0
    Affected: 6.1
    Affected: 6.2.0
        cpe:2.3:a:calcom:cal.diy:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:calcom:cal.diy:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "PBAC Permission Engine"
              ],
              "product": "cal.diy",
              "vendor": "calcom",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "status": "affected",
                  "version": "6.2.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "geochen (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T02:00:11.876Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412762 | calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412762"
            },
            {
              "name": "VDB-412762 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412762/cti"
            },
            {
              "name": "CVE-2026-104054 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-104054"
            },
            {
              "name": "Submit #959492 | https://github.com/calcom/ cal.diy commit 4026669 broken access control",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/959492"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/calcom/cal.diy/issues/29802"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/calcom/cal.diy/pull/30253"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/calcom/cal.diy/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T20:02:21.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-104054",
        "datePublished": "2026-10-02T02:00:11.876Z",
        "dateReserved": "2026-10-01T17:57:14.224Z",
        "dateUpdated": "2026-10-02T02:00:11.876Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104053 (GCVE-0-2026-104053)

    Vulnerability from cvelistv5 – Published: 2026-10-02 01:15 – Updated: 2026-10-02 01:15 X_Freeware
    VLAI
    Title
    itsourcecode Pet Shop Management System admin_reservefilter.php sql injection
    Summary
    A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/412761 vdb-entrytechnical-description
    https://vuldb.com/vuln/412761/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-104053 third-party-advisory
    https://vuldb.com/submit/959328 third-party-advisory
    https://github.com/LAt-forever/vuldb-docs/issues/1 broken-linkexploitissue-tracking
    https://itsourcecode.com/ product
    Impacted products
    Vendor Product Version
    itsourcecode Pet Shop Management System Affected: 1.0
        cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*"
              ],
              "product": "Pet Shop Management System",
              "vendor": "itsourcecode",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lan_huahua (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T01:15:16.482Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412761 | itsourcecode Pet Shop Management System admin_reservefilter.php sql injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412761"
            },
            {
              "name": "VDB-412761 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412761/cti"
            },
            {
              "name": "CVE-2026-104053 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-104053"
            },
            {
              "name": "Submit #959328 | itsourcecode Pet Shop Management System V1.0 SQL Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/959328"
            },
            {
              "tags": [
                "broken-link",
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/LAt-forever/vuldb-docs/issues/1"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://itsourcecode.com/"
            }
          ],
          "tags": [
            "x_freeware"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T20:01:01.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "itsourcecode Pet Shop Management System admin_reservefilter.php sql injection",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-104053",
        "datePublished": "2026-10-02T01:15:16.482Z",
        "dateReserved": "2026-10-01T17:55:51.198Z",
        "dateUpdated": "2026-10-02T01:15:16.482Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104052 (GCVE-0-2026-104052)

    Vulnerability from cvelistv5 – Published: 2026-10-02 01:00 – Updated: 2026-10-02 01:00 X_Freeware
    VLAI
    Title
    itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
    Summary
    A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/412760 vdb-entrytechnical-description
    https://vuldb.com/vuln/412760/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-104052 third-party-advisory
    https://vuldb.com/submit/959310 third-party-advisory
    https://github.com/Useless-Noob-hub/cve/issues/1 exploitissue-tracking
    https://itsourcecode.com/ product
    Impacted products
    Vendor Product Version
    itsourcecode Pet Shop Management System Affected: 1.0
        cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*"
              ],
              "product": "Pet Shop Management System",
              "vendor": "itsourcecode",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "hongyangwang (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T01:00:15.385Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-412760 | itsourcecode Pet Shop Management System admin_reject_completed.php sql injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/412760"
            },
            {
              "name": "VDB-412760 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/412760/cti"
            },
            {
              "name": "CVE-2026-104052 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-104052"
            },
            {
              "name": "Submit #959310 | itsourcecode Pet Shop Management System V1.0 SQL Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/959310"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/Useless-Noob-hub/cve/issues/1"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://itsourcecode.com/"
            }
          ],
          "tags": [
            "x_freeware"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-10-01T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-10-01T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-10-01T20:00:57.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "itsourcecode Pet Shop Management System admin_reject_completed.php sql injection",
          "x_generator": [
            "VulDB PVTS v202610"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-104052",
        "datePublished": "2026-10-02T01:00:15.385Z",
        "dateReserved": "2026-10-01T17:55:45.907Z",
        "dateUpdated": "2026-10-02T01:00:15.385Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104480 (GCVE-0-2026-104480)

    Vulnerability from cvelistv5 – Published: 2026-10-02 00:57 – Updated: 2026-10-02 00:57
    VLAI
    Title
    Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
    Summary
    Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
    CWE
    • CWE-390 - Detection of Error Condition Without Action
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Discord libdave Affected: 1.1.0 , < 1.2.0 (semver)
    Affected: 7b15f1fc16f159da0478aa6be909e38f1e957833 , < 9686fbaea864aa19f0675e486672b6a77811b6a1 (git)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com",
              "defaultStatus": "unaffected",
              "modules": [
                "C++ library"
              ],
              "packageName": "discord/libdave",
              "product": "libdave",
              "programFiles": [
                "cpp/src/mls/session.cpp"
              ],
              "programRoutines": [
                {
                  "name": "discord::dave::mls::Session::VerifyWelcomeState"
                }
              ],
              "repo": "https://github.com/discord/libdave",
              "vendor": "Discord",
              "versions": [
                {
                  "lessThan": "1.2.0",
                  "status": "affected",
                  "version": "1.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "9686fbaea864aa19f0675e486672b6a77811b6a1",
                  "status": "affected",
                  "version": "7b15f1fc16f159da0478aa6be909e38f1e957833",
                  "versionType": "git"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "MDL (https://heartbreak.ing)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.4,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
                "version": "4.0"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-390",
                  "description": "CWE-390 Detection of Error Condition Without Action",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T00:57:55.648Z",
            "orgId": "4ac701fe-44e9-4bcd-9585-dd6449257611",
            "shortName": "Bugcrowd"
          },
          "references": [
            {
              "name": "[cpp] restore strict validation of MLS welcome state",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/discord/libdave/commit/9686fbaea864aa19f0675e486672b6a77811b6a1"
            },
            {
              "name": "libdave v1.2.0 release notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/discord/libdave/releases/tag/v1.2.0/cpp"
            },
            {
              "name": "Discord Audio and Video End-to-End Encryption (DAVE) Protocol Whitepaper",
              "tags": [
                "technical-description"
              ],
              "url": "https://daveprotocol.com/"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/discord/libdave"
            }
          ],
          "title": "Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4ac701fe-44e9-4bcd-9585-dd6449257611",
        "assignerShortName": "Bugcrowd",
        "cveId": "CVE-2026-104480",
        "datePublished": "2026-10-02T00:57:55.648Z",
        "dateReserved": "2026-10-02T00:57:11.860Z",
        "dateUpdated": "2026-10-02T00:57:55.648Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103098 (GCVE-0-2026-103098)

    Vulnerability from cvelistv5 – Published: 2026-10-02 00:15 – Updated: 2026-10-02 00:15
    VLAI
    Title
    GV-Eye Sensitive information exposure in URL query parameter Vulnerability
    Summary
    Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
    CWE
    • CWE-319 - Cleartext transmission of sensitive information
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-Eye Affected: V3.6.0
    Unaffected: V3.7.2
        cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 02:15
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "tw.com.geovision.gveye",
              "platforms": [
                "Android"
              ],
              "product": "GV-Eye",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "V3.7.2"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lloyd Lexter Gealon"
            }
          ],
          "datePublic": "2026-09-30T02:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u0026nbsp; The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
                }
              ],
              "value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u00a0 The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-158",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-158 Sniffing Network Traffic"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "CWE-319 Cleartext transmission of sensitive information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T00:15:17.848Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GV-Eye Sensitive information exposure in URL query parameter Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-103098",
        "datePublished": "2026-10-02T00:15:17.848Z",
        "dateReserved": "2026-09-30T02:10:02.128Z",
        "dateUpdated": "2026-10-02T00:15:17.848Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-103097 (GCVE-0-2026-103097)

    Vulnerability from cvelistv5 – Published: 2026-10-02 00:14 – Updated: 2026-10-02 00:14
    VLAI
    Title
    GV-Eye Relay Payment API Key Vulnerability
    Summary
    An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
    CWE
    • CWE-798 - Use of Hard-coded Credentials
    • CWE-540 - Inclusion of sensitive information in source code
    • CWE-312 - Cleartext storage of sensitive information
    References
    Impacted products
    Vendor Product Version
    GeoVision Inc. GV-Eye Affected: V3.6.0
    Unaffected: V3.7.2
        cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 02:15
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "tw.com.geovision.gveye",
              "platforms": [
                "Android"
              ],
              "product": "GV-Eye",
              "vendor": "GeoVision Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "V3.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "V3.7.2"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lloyd Lexter Gealon"
            }
          ],
          "datePublic": "2026-09-30T02:15:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.\u003c/p\u003e"
                }
              ],
              "value": "An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-37",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-37 Retrieve Embedded Sensitive Data"
                }
              ]
            },
            {
              "capecId": "CAPEC-188",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-188 Reverse Engineering"
                }
              ]
            },
            {
              "capecId": "CAPEC-618",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-618 Cellular Broadcast Message Request"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "CWE-798: Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-540",
                  "description": "CWE-540 Inclusion of sensitive information in source code",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-312",
                  "description": "CWE-312 Cleartext storage of sensitive information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T00:14:46.555Z",
            "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "shortName": "GV"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.geovision.com.tw/cyber_security.php"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GV-Eye Relay Payment API Key Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "assignerShortName": "GV",
        "cveId": "CVE-2026-103097",
        "datePublished": "2026-10-02T00:14:46.555Z",
        "dateReserved": "2026-09-30T02:10:01.788Z",
        "dateUpdated": "2026-10-02T00:14:46.555Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }