Search
Find a vulnerability
Search criteria
378997 vulnerabilities
CVE-2026-97318 (GCVE-0-2026-97318)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter
Summary
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/a171b0f1-b2d2-44… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Giveaways and Contests by RafflePress |
Affected:
0 , < 1.12.27
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Giveaways and Contests by RafflePress",
"vendor": "Unknown",
"versions": [
{
"lessThan": "1.12.27",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Dick Snel"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway\u0027s parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site\u0027s own giveaway confirmation and referral links redirect visitors to an arbitrary external site."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:27.170Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/a171b0f1-b2d2-4482-b44f-bd4a1f3b223b/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Giveaways and Contests by RafflePress \u003c 1.12.27 - Unauthenticated Stored Open Redirect via \u0027parent_url\u0027 Parameter",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-97318",
"datePublished": "2026-10-02T06:00:27.170Z",
"dateReserved": "2026-09-24T11:27:52.068Z",
"dateUpdated": "2026-10-02T06:00:27.170Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97317 (GCVE-0-2026-97317)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page
Summary
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/f8779fd4-f362-40… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Giveaways and Contests by RafflePress |
Affected:
0 , < 1.12.27
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Giveaways and Contests by RafflePress",
"vendor": "Unknown",
"versions": [
{
"lessThan": "1.12.27",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Dmitrii Ignatyev"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-200 Information Exposure",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:26.940Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/f8779fd4-f362-40c4-8df1-145620c69103/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Giveaways and Contests by RafflePress \u003c 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-97317",
"datePublished": "2026-10-02T06:00:26.940Z",
"dateReserved": "2026-09-24T11:27:48.588Z",
"dateUpdated": "2026-10-02T06:00:26.940Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94298 (GCVE-0-2026-94298)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter
Summary
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/6f6c8718-7e7e-47… | exploitvdb-entrytechnical-description |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "BuildKit",
"vendor": "Unknown",
"versions": [
{
"lessThan": "1.0.29",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Naiches"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-89 SQL Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:26.412Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/6f6c8718-7e7e-4700-a4c2-ee177c44b7ea/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "BuildKit \u003c 1.0.29 - Contributor+ Stored SQLi via list_content Parameter",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-94298",
"datePublished": "2026-10-02T06:00:26.412Z",
"dateReserved": "2026-09-21T09:44:15.108Z",
"dateUpdated": "2026-10-02T06:00:26.412Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91023 (GCVE-0-2026-91023)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured
Summary
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/c2400c65-5d77-45… | exploitvdb-entrytechnical-description |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Motors",
"vendor": "Unknown",
"versions": [
{
"lessThan": "1.4.124",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yaswanth Reddy Sunkara"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124\u0027s paid featured-listing option is enabled, neither of which is a default configuration."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:25.876Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/c2400c65-5d77-454c-9691-5e664556341b/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Motors \u2013 Car Dealership \u0026 Classified Listings \u003c 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-91023",
"datePublished": "2026-10-02T06:00:25.876Z",
"dateReserved": "2026-09-14T17:07:28.393Z",
"dateUpdated": "2026-10-02T06:00:25.876Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91022 (GCVE-0-2026-91022)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color
Summary
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/72672806-e2f3-41… | exploitvdb-entrytechnical-description |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Motors",
"vendor": "Unknown",
"versions": [
{
"lessThan": "1.4.124",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yaswanth Reddy Sunkara"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-79 Cross-Site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:25.652Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/72672806-e2f3-417e-83c0-854c604028e4/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Motors \u003c 1.4.124 - Listing Manager+ Stored XSS via Badge Color",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-91022",
"datePublished": "2026-10-02T06:00:25.652Z",
"dateReserved": "2026-09-14T17:07:10.725Z",
"dateUpdated": "2026-10-02T06:00:25.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85016 (GCVE-0-2026-85016)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter
Summary
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/1d488c84-2797-4c… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Unlimited Elements for Elementor |
Affected:
0 , < 2.0.21
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Unlimited Elements for Elementor",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.0.21",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Revanth Hari Narayana Matte"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-79 Cross-Site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:25.438Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/1d488c84-2797-4c02-8c13-54b80e4128dc/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Unlimited Elements For Elementor \u003c 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-85016",
"datePublished": "2026-10-02T06:00:25.438Z",
"dateReserved": "2026-09-02T19:18:47.849Z",
"dateUpdated": "2026-10-02T06:00:25.438Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91828 (GCVE-0-2026-91828)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
OMGF < 6.3.11 - Unauthenticated DoS via do_optimize
Summary
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/be25f7b5-5790-4d… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. |
Affected:
0 , < 6.3.11
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.",
"vendor": "Unknown",
"versions": [
{
"lessThan": "6.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "\u00c1ngel Santana"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site\u0027s PHP worker pool and make the entire site unavailable."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:25.216Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/be25f7b5-5790-4db7-9056-b43b538a7183/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "OMGF \u003c 6.3.11 - Unauthenticated DoS via do_optimize",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-91828",
"datePublished": "2026-10-02T06:00:25.216Z",
"dateReserved": "2026-09-15T08:11:48.154Z",
"dateUpdated": "2026-10-02T06:00:25.216Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-13718 (GCVE-0-2026-13718)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content
Summary
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/ff0da7b7-f415-46… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Tabs Responsive |
Affected:
0 , ≤ 2.5
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "Tabs Responsive",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "2.5",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "J4ck13Ch4n"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-79 Cross-Site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:24.997Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/ff0da7b7-f415-466e-9f6e-4c559d2699a9/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Tabs Responsive \u003c= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-13718",
"datePublished": "2026-10-02T06:00:24.997Z",
"dateReserved": "2026-06-29T14:06:03.048Z",
"dateUpdated": "2026-10-02T06:00:24.997Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90988 (GCVE-0-2026-90988)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum
Summary
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/6c02759e-b37e-43… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Request a Quote |
Affected:
0 , ≤ 2.5.6
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "Request a Quote",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "2.5.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Artus KG"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-200 Information Exposure",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:24.780Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/6c02759e-b37e-43ce-a4f4-467e8af63a17/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Request a Quote \u003c= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-90988",
"datePublished": "2026-10-02T06:00:24.780Z",
"dateReserved": "2026-09-14T13:58:23.882Z",
"dateUpdated": "2026-10-02T06:00:24.780Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85004 (GCVE-0-2026-85004)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect
Summary
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/38041b58-7738-47… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Popup Maker |
Affected:
0 , ≤ 1.4.5
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "Popup Maker",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "1.4.5",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Artus KG"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:24.239Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/38041b58-7738-4710-a1b6-4005e9ec2c01/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Popup Maker WP \u003c= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-85004",
"datePublished": "2026-10-02T06:00:24.239Z",
"dateReserved": "2026-09-02T18:30:03.819Z",
"dateUpdated": "2026-10-02T06:00:24.239Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81740 (GCVE-0-2026-81740)
Vulnerability from cvelistv5 – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
VLAI
EPSS
VEX
Title
Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback
Summary
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/13767875-5010-49… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Paytm Payment Gateway |
Affected:
0 , < 2.8.9
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Paytm Payment Gateway",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.8.9",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Artus KG"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T06:00:24.014Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/13767875-5010-494a-b3ed-133d58b8ecea/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Paytm Payment Gateway \u003c 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-81740",
"datePublished": "2026-10-02T06:00:24.014Z",
"dateReserved": "2026-08-27T11:47:22.935Z",
"dateUpdated": "2026-10-02T06:00:24.014Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15896 (GCVE-0-2026-15896)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
Summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
Severity
9.1 (Critical)
CWE
- CWE-26 - Path Traversal: '/dir/../filename'
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder |
Affected:
0 , ≤ 6.3.316
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
"vendor": "WebRehab",
"versions": [
{
"lessThanOrEqual": "6.3.316",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "afei"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional \u0027file_upload_auth\u0027 setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin\u0027s file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-26",
"description": "CWE-26 Path Traversal: \u0027/dir/../filename\u0027",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:18.601Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc3df045-1020-403f-8e10-a1b75261b769?source=cve"
},
{
"url": "https://github.com/RensTillmann/super-forms/pull/205"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-15T18:14:05.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:32:09.000Z",
"value": "Disclosed"
}
],
"title": "Super Forms \u003c= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via \u0027sfgtfi\u0027 URL Path Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15896",
"datePublished": "2026-10-02T05:30:18.601Z",
"dateReserved": "2026-07-15T17:58:41.955Z",
"dateUpdated": "2026-10-02T05:30:18.601Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78471 (GCVE-0-2026-78471)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Summary
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize's 'Lazy-load images?' option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders.
Severity
5.4 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| optimizingmatters | Autoptimize |
Affected:
0 , ≤ 3.1.15.1
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Autoptimize",
"vendor": "optimizingmatters",
"versions": [
{
"lessThanOrEqual": "3.1.15.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "theviper17y"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled Autoptimize\u0027s \u0027Lazy-load images?\u0027 option, the w3-total-cache/w3-total-cache.php file to be present on disk with the plugin disabled, a class named Minify_HTML to be loaded into scope by another plugin, and the malicious comment to be approved by a moderator before the payload renders."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:18.257Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b14f574d-1490-423e-9ef3-ce8f844cb8f0?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L1232"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L960"
},
{
"url": "https://plugins.trac.wordpress.org/browser/autoptimize/tags/3.1.15.1/classes/autoptimizeImages.php#L908"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3713884%40autoptimize%2Ftags%2F3.1.16\u0026old=3657650%40autoptimize%2Ftags%2F3.1.15.1"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3713884/autoptimize/trunk/classes/autoptimizeImages.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-08-24T17:04:26.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:42:10.000Z",
"value": "Disclosed"
}
],
"title": "Autoptimize \u003c= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-78471",
"datePublished": "2026-10-02T05:30:18.257Z",
"dateReserved": "2026-08-24T16:49:16.127Z",
"dateUpdated": "2026-10-02T05:30:18.257Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92174 (GCVE-0-2026-92174)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
Summary
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.
Severity
7.5 (High)
CWE
- CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Assigner
References
7 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| gpriday | SiteOrigin Widgets Bundle |
Affected:
0 , ≤ 1.73.2
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "SiteOrigin Widgets Bundle",
"vendor": "gpriday",
"versions": [
{
"lessThanOrEqual": "1.73.2",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "kiemtiendinhau"
}
],
"descriptions": [
{
"lang": "en",
"value": "The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the \u0027theme\u0027 parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:17.908Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a184ee1a-5fe2-47d5-8db1-a226c73e5bb1?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/base/siteorigin-widget.class.php#L214"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/base/inc/routes/siteorigin-widgets-resource.class.php#L140"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/compat/block-editor/widget-block.php#L710"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/widgets/price-table/price-table.php#L450"
},
{
"url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.73.1/widgets/price-table/price-table.php#L332"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3605767/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T16:47:11.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:32:57.000Z",
"value": "Disclosed"
}
],
"title": "SiteOrigin Widgets Bundle \u003c= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via \u0027theme\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-92174",
"datePublished": "2026-10-02T05:30:17.908Z",
"dateReserved": "2026-09-15T17:56:19.851Z",
"dateUpdated": "2026-10-02T05:30:17.908Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90438 (GCVE-0-2026-90438)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission
Summary
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled.
Severity
7.2 (High)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
11 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| kstover | Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder |
Affected:
0 , ≤ 3.15.4
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Ninja Forms \u2013 Contact Form Builder with Calculators, Quizzes, Signatures \u0026 AI Form Builder",
"vendor": "kstover",
"versions": [
{
"lessThanOrEqual": "3.15.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "UKO"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:17.547Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a159485d-ce5b-46e7-8e63-a72012ccc180?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/build/submissions.js#L1"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Helper.php#L261"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L308"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/AJAX/Controllers/Submission.php#L61"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/build/submissions.js#L1"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/Helper.php#L261"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/Database/Models/Submission.php#L308"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.2/includes/AJAX/Controllers/Submission.php#L61"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3717122%40ninja-forms%2Ftags%2F3.15.5\u0026old=3705719%40ninja-forms%2Ftags%2F3.15.4"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3717122/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-11T20:31:25.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T17:13:05.000Z",
"value": "Disclosed"
}
],
"title": "Ninja Forms \u003c= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-90438",
"datePublished": "2026-10-02T05:30:17.547Z",
"dateReserved": "2026-09-11T20:06:06.961Z",
"dateUpdated": "2026-10-02T05:30:17.547Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15897 (GCVE-0-2026-15897)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
Summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.
Severity
8.8 (High)
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder |
Affected:
0 , ≤ 6.3.316
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
"vendor": "WebRehab",
"versions": [
{
"lessThanOrEqual": "6.3.316",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "d.v4n_s3c"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register \u0026 Login add-on\u0027s before_email_success_msg() function, in its register_login_action=\u0027update\u0027 flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action=\u0027update\u0027 with register_login_user_id_update=\u0027true\u0027) and then submit it with user_id set to an administrator\u0027s ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts \u2014 including administrators \u2014 resulting in account takeover and full site compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:17.190Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94297481-9ebb-42cb-9362-be8bc52b126f?source=cve"
},
{
"url": "https://github.com/RensTillmann/super-forms/pull/205"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-15T18:52:23.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:34:31.000Z",
"value": "Disclosed"
}
],
"title": "Super Forms \u2013 Drag \u0026 Drop Form Builder \u003c= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via \u0027user_id\u0027 Parameter in Register \u0026 Login"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15897",
"datePublished": "2026-10-02T05:30:17.190Z",
"dateReserved": "2026-07-15T18:15:21.788Z",
"dateUpdated": "2026-10-02T05:30:17.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92820 (GCVE-0-2026-92820)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
Summary
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
Severity
8.1 (High)
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| SaturdayDrive | Ninja Forms - File Uploads |
Affected:
0 , ≤ 3.3.34
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Ninja Forms - File Uploads",
"vendor": "SaturdayDrive",
"versions": [
{
"lessThanOrEqual": "3.3.34",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "daroo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload\u0027s file_path, which is then used without validation to attach a file to the form\u0027s notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin\u0027s External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:15.764Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d5f0ec1-abcb-4aa2-a130-53682fa13f00?source=cve"
},
{
"url": "https://ninjaforms.com/extensions/file-uploads/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-16T20:35:09.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:54:50.000Z",
"value": "Disclosed"
}
],
"title": "Ninja Forms - File Uploads \u003c= 3.3.34 - Unauthenticated Arbitrary File Upload"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-92820",
"datePublished": "2026-10-02T05:30:15.764Z",
"dateReserved": "2026-09-16T20:19:51.864Z",
"dateUpdated": "2026-10-02T05:30:15.764Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84925 (GCVE-0-2026-84925)
Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
VLAI
EPSS
VEX
Title
Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter
Summary
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox.
Severity
6.1 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ThemeFusion | Avada | Website Builder For WordPress & WooCommerce |
Affected:
0 , ≤ 7.16.1
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Avada | Website Builder For WordPress \u0026 WooCommerce",
"vendor": "ThemeFusion",
"versions": [
{
"lessThanOrEqual": "7.16.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "daroo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Avada | Website Builder For WordPress \u0026 WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u0027lang\u0027 parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected value is propagated through Fusion_Multilingual::set_active_language() and concatenated into a URL by Fusion_Settings::get_setting_link() without applying urlencode(), esc_url(), or esc_attr() before being echoed raw into a double-quoted href attribute in the post editor metabox."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T05:30:15.238Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4c3936aa-58d6-4ac0-a077-2faaed48828f?source=cve"
},
{
"url": "https://classic.avada.com/documentation/avada-changelog/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-02T16:14:12.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T16:39:02.000Z",
"value": "Disclosed"
}
],
"title": "Avada | Website Builder For WordPress \u0026 WooCommerce \u003c= 7.16.1 - Reflected Cross-Site Scripting via \u0027lang\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-84925",
"datePublished": "2026-10-02T05:30:15.238Z",
"dateReserved": "2026-09-02T15:58:18.740Z",
"dateUpdated": "2026-10-02T05:30:15.238Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-10026 (GCVE-0-2026-10026)
Vulnerability from cvelistv5 – Published: 2026-10-02 04:27 – Updated: 2026-10-02 04:27
VLAI
EPSS
VEX
Title
CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
Summary
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server.
Severity
7.2 (High)
CWE
- CWE-94 - Improper Control of Generation of Code ('Code Injection')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| CTX | CTX Feed Pro |
Affected:
0 , ≤ 7.6.12
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CTX Feed Pro",
"vendor": "CTX",
"versions": [
{
"lessThanOrEqual": "7.6.12",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nguyen Truong (Roll)"
},
{
"lang": "en",
"type": "finder",
"value": "Phap Nguyen Anh"
}
],
"descriptions": [
{
"lang": "en",
"value": "The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the \u0027Feed Config\u0027 field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T04:27:11.832Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50aa4bff-60dd-469c-a8f0-be6dd2dfa91e?source=cve"
},
{
"url": "https://webappick.com/plugin/woocommerce-product-feed-pro/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T15:53:07.000Z",
"value": "Disclosed"
}
],
"title": "CTX Feed Pro \u003c= 7.6.12 - Authenticated (Administrator+) Remote Code Execution"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-10026",
"datePublished": "2026-10-02T04:27:11.832Z",
"dateReserved": "2026-05-28T18:09:26.014Z",
"dateUpdated": "2026-10-02T04:27:11.832Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19660 (GCVE-0-2026-19660)
Vulnerability from cvelistv5 – Published: 2026-10-02 04:27 – Updated: 2026-10-02 04:27
VLAI
EPSS
VEX
Title
Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
Summary
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.
Severity
9.8 (Critical)
CWE
- CWE-287 - Improper Authentication
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| DiviEngine | Divi Membership |
Affected:
0 , ≤ 2.3.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Divi Membership",
"vendor": "DiviEngine",
"versions": [
{
"lessThanOrEqual": "2.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "0xd4rk5id3"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user \u2014 including administrators \u2014 by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T04:27:11.341Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d650cda-341f-4772-9b67-1bac200e3fb7?source=cve"
},
{
"url": "https://diviengine.com/divi-membership-changelog/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T16:24:08.000Z",
"value": "Disclosed"
}
],
"title": "Divi Membership \u003c= 2.3.0 - Unauthenticated Authentication Bypass via \u0027paypal_param\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-19660",
"datePublished": "2026-10-02T04:27:11.341Z",
"dateReserved": "2026-08-12T20:11:51.671Z",
"dateUpdated": "2026-10-02T04:27:11.341Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93367 (GCVE-0-2026-93367)
Vulnerability from cvelistv5 – Published: 2026-10-02 03:38 – Updated: 2026-10-02 03:38
VLAI
EPSS
VEX
Title
Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
Summary
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.
Severity
7.2 (High)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wp-buy | Visitor Traffic Real Time Statistics pro |
Affected:
0 , ≤ 11.22
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Visitor Traffic Real Time Statistics pro",
"vendor": "wp-buy",
"versions": [
{
"lessThanOrEqual": "11.22",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rafie Muhammad"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST[\u0027page_title\u0027] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin\u0027s dashboard, the \u0027Traffic by Title\u0027 DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator\u0027s session."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:38:46.638Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a72261e5-7376-4a34-9264-27bd4f27e938?source=cve"
},
{
"url": "https://www.wp-buy.com/product/visitors-traffic-real-time-statistics-pro/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-21T13:05:40.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T14:53:24.000Z",
"value": "Disclosed"
}
],
"title": "Visitors Traffic Real Time Statistics Pro \u003c= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-93367",
"datePublished": "2026-10-02T03:38:46.638Z",
"dateReserved": "2026-09-17T18:58:09.010Z",
"dateUpdated": "2026-10-02T03:38:46.638Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-14378 (GCVE-0-2026-14378)
Vulnerability from cvelistv5 – Published: 2026-10-02 03:38 – Updated: 2026-10-02 03:38
VLAI
EPSS
VEX
Title
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
Summary
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.
Severity
9.8 (Critical)
CWE
- CWE-287 - Improper Authentication
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| dplugins | DevKit Pro |
Affected:
0 , ≤ 2.3.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "DevKit Pro",
"vendor": "dplugins",
"versions": [
{
"lessThanOrEqual": "2.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "h0xilo"
}
],
"descriptions": [
{
"lang": "en",
"value": "The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor \u2014 including unauthenticated users \u2014 whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator\u0027s user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator\u0027s ID and granting the attacker a full administrator-level authenticated session and complete site takeover."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T03:38:46.144Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab3986a-69e0-442f-8e79-35b1bc5376d9?source=cve"
},
{
"url": "https://docs.dplugins.com/devkit/changelog"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-14T15:02:19.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-10-01T14:44:20.000Z",
"value": "Disclosed"
}
],
"title": "DevKit Pro \u003c= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via \u0027original_user_id\u0027 Cookie in Frontend Revert Switch Flow"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-14378",
"datePublished": "2026-10-02T03:38:46.144Z",
"dateReserved": "2026-07-01T20:35:33.849Z",
"dateUpdated": "2026-10-02T03:38:46.144Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104123 (GCVE-0-2026-104123)
Vulnerability from cvelistv5 – Published: 2026-10-02 02:45 – Updated: 2026-10-02 02:45 X_Freeware
VLAI
EPSS
VEX
Title
SourceCodester Online Reviewer Management System btn_functions.php activity sql injection
Summary
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Severity
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412765 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412765/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104123 | third-party-advisory |
| https://vuldb.com/submit/961692 | third-party-advisory |
| https://github.com/lemssh77/cve/issues/1 | exploitissue-tracking |
| https://www.sourcecodester.com/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| SourceCodester | Online Reviewer Management System |
Affected:
1.0
cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*"
],
"product": "Online Reviewer Management System",
"vendor": "SourceCodester",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Ethan.KY.WONG (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T02:45:13.229Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412765 | SourceCodester Online Reviewer Management System btn_functions.php activity sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412765"
},
{
"name": "VDB-412765 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412765/cti"
},
{
"name": "CVE-2026-104123 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104123"
},
{
"name": "Submit #961692 | SourceCodester Online Reviewer Management System using PHP/MySQL /reviewer_0/admins/assessments/activities/btn_functions.php?action=activi 1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/961692"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/lemssh77/cve/issues/1"
},
{
"tags": [
"product"
],
"url": "https://www.sourcecodester.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T20:34:13.000Z",
"value": "VulDB entry last update"
}
],
"title": "SourceCodester Online Reviewer Management System btn_functions.php activity sql injection",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104123",
"datePublished": "2026-10-02T02:45:13.229Z",
"dateReserved": "2026-10-01T18:29:07.832Z",
"dateUpdated": "2026-10-02T02:45:13.229Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104120 (GCVE-0-2026-104120)
Vulnerability from cvelistv5 – Published: 2026-10-02 02:15 – Updated: 2026-10-02 02:15
VLAI
EPSS
VEX
Title
modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery
Summary
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Severity
CWE
- CWE-918 - Server-Side Request Forgery
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412764 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412764/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104120 | third-party-advisory |
| https://vuldb.com/submit/960099 | third-party-advisory |
| https://github.com/modelcontextprotocol/servers/i… | exploitissue-tracking |
| https://github.com/modelcontextprotocol/servers/p… | issue-trackingpatch |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| modelcontextprotocol | mcp-server-fetch |
Affected:
2026.6.0
Affected: 2026.6.1 Affected: 2026.6.2 Affected: 2026.6.3 Affected: 2026.6.4 cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:* |
|
| modelcontextprotocol | mcp-server-everything |
Affected:
2026.6.0
Affected: 2026.6.1 Affected: 2026.6.2 Affected: 2026.6.3 Affected: 2026.6.4 cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:modelcontextprotocol:mcp-server-fetch:*:*:*:*:*:*:*:*"
],
"modules": [
"Fetch Tool"
],
"product": "mcp-server-fetch",
"vendor": "modelcontextprotocol",
"versions": [
{
"status": "affected",
"version": "2026.6.0"
},
{
"status": "affected",
"version": "2026.6.1"
},
{
"status": "affected",
"version": "2026.6.2"
},
{
"status": "affected",
"version": "2026.6.3"
},
{
"status": "affected",
"version": "2026.6.4"
}
]
},
{
"cpes": [
"cpe:2.3:a:modelcontextprotocol:mcp-server-everything:*:*:*:*:*:*:*:*"
],
"modules": [
"Fetch Tool"
],
"product": "mcp-server-everything",
"vendor": "modelcontextprotocol",
"versions": [
{
"status": "affected",
"version": "2026.6.0"
},
{
"status": "affected",
"version": "2026.6.1"
},
{
"status": "affected",
"version": "2026.6.2"
},
{
"status": "affected",
"version": "2026.6.3"
},
{
"status": "affected",
"version": "2026.6.4"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "geochen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T02:15:18.514Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412764 | modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412764"
},
{
"name": "VDB-412764 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412764/cti"
},
{
"name": "CVE-2026-104120 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104120"
},
{
"name": "Submit #960099 | https://github.com/modelcontextprotocol/ servers 2026.6.4 Server-Side Request Forgery",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/960099"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/modelcontextprotocol/servers/issues/4492"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/modelcontextprotocol/servers/pull/4890"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T20:20:15.000Z",
"value": "VulDB entry last update"
}
],
"title": "modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104120",
"datePublished": "2026-10-02T02:15:18.514Z",
"dateReserved": "2026-10-01T18:15:10.419Z",
"dateUpdated": "2026-10-02T02:15:18.514Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104054 (GCVE-0-2026-104054)
Vulnerability from cvelistv5 – Published: 2026-10-02 02:00 – Updated: 2026-10-02 02:00
VLAI
EPSS
VEX
Title
calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
Summary
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Severity
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412762 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412762/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104054 | third-party-advisory |
| https://vuldb.com/submit/959492 | third-party-advisory |
| https://github.com/calcom/cal.diy/issues/29802 | exploitissue-tracking |
| https://github.com/calcom/cal.diy/pull/30253 | issue-trackingpatch |
| https://github.com/calcom/cal.diy/ | product |
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:calcom:cal.diy:*:*:*:*:*:*:*:*"
],
"modules": [
"PBAC Permission Engine"
],
"product": "cal.diy",
"vendor": "calcom",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"status": "affected",
"version": "6.1"
},
{
"status": "affected",
"version": "6.2.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "geochen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T02:00:11.876Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412762 | calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412762"
},
{
"name": "VDB-412762 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412762/cti"
},
{
"name": "CVE-2026-104054 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104054"
},
{
"name": "Submit #959492 | https://github.com/calcom/ cal.diy commit 4026669 broken access control",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/959492"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/calcom/cal.diy/issues/29802"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/calcom/cal.diy/pull/30253"
},
{
"tags": [
"product"
],
"url": "https://github.com/calcom/cal.diy/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T20:02:21.000Z",
"value": "VulDB entry last update"
}
],
"title": "calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104054",
"datePublished": "2026-10-02T02:00:11.876Z",
"dateReserved": "2026-10-01T17:57:14.224Z",
"dateUpdated": "2026-10-02T02:00:11.876Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104053 (GCVE-0-2026-104053)
Vulnerability from cvelistv5 – Published: 2026-10-02 01:15 – Updated: 2026-10-02 01:15 X_Freeware
VLAI
EPSS
VEX
Title
itsourcecode Pet Shop Management System admin_reservefilter.php sql injection
Summary
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Severity
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412761 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412761/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104053 | third-party-advisory |
| https://vuldb.com/submit/959328 | third-party-advisory |
| https://github.com/LAt-forever/vuldb-docs/issues/1 | broken-linkexploitissue-tracking |
| https://itsourcecode.com/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| itsourcecode | Pet Shop Management System |
Affected:
1.0
cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*"
],
"product": "Pet Shop Management System",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "lan_huahua (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T01:15:16.482Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412761 | itsourcecode Pet Shop Management System admin_reservefilter.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412761"
},
{
"name": "VDB-412761 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412761/cti"
},
{
"name": "CVE-2026-104053 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104053"
},
{
"name": "Submit #959328 | itsourcecode Pet Shop Management System V1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/959328"
},
{
"tags": [
"broken-link",
"exploit",
"issue-tracking"
],
"url": "https://github.com/LAt-forever/vuldb-docs/issues/1"
},
{
"tags": [
"product"
],
"url": "https://itsourcecode.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T20:01:01.000Z",
"value": "VulDB entry last update"
}
],
"title": "itsourcecode Pet Shop Management System admin_reservefilter.php sql injection",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104053",
"datePublished": "2026-10-02T01:15:16.482Z",
"dateReserved": "2026-10-01T17:55:51.198Z",
"dateUpdated": "2026-10-02T01:15:16.482Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104052 (GCVE-0-2026-104052)
Vulnerability from cvelistv5 – Published: 2026-10-02 01:00 – Updated: 2026-10-02 01:00 X_Freeware
VLAI
EPSS
VEX
Title
itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
Summary
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Severity
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412760 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412760/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104052 | third-party-advisory |
| https://vuldb.com/submit/959310 | third-party-advisory |
| https://github.com/Useless-Noob-hub/cve/issues/1 | exploitissue-tracking |
| https://itsourcecode.com/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| itsourcecode | Pet Shop Management System |
Affected:
1.0
cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:pet_shop_management_system:*:*:*:*:*:*:*:*"
],
"product": "Pet Shop Management System",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "hongyangwang (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "SQL Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T01:00:15.385Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412760 | itsourcecode Pet Shop Management System admin_reject_completed.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412760"
},
{
"name": "VDB-412760 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412760/cti"
},
{
"name": "CVE-2026-104052 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104052"
},
{
"name": "Submit #959310 | itsourcecode Pet Shop Management System V1.0 SQL Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/959310"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/Useless-Noob-hub/cve/issues/1"
},
{
"tags": [
"product"
],
"url": "https://itsourcecode.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T20:00:57.000Z",
"value": "VulDB entry last update"
}
],
"title": "itsourcecode Pet Shop Management System admin_reject_completed.php sql injection",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104052",
"datePublished": "2026-10-02T01:00:15.385Z",
"dateReserved": "2026-10-01T17:55:45.907Z",
"dateUpdated": "2026-10-02T01:00:15.385Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104480 (GCVE-0-2026-104480)
Vulnerability from cvelistv5 – Published: 2026-10-02 00:57 – Updated: 2026-10-02 00:57
VLAI
EPSS
VEX
Title
Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
Summary
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
Severity
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/discord/libdave/commit/9686fba… | patch |
| https://github.com/discord/libdave/releases/tag/v… | release-notes |
| https://daveprotocol.com/ | technical-description |
| https://github.com/discord/libdave | product |
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"modules": [
"C++ library"
],
"packageName": "discord/libdave",
"product": "libdave",
"programFiles": [
"cpp/src/mls/session.cpp"
],
"programRoutines": [
{
"name": "discord::dave::mls::Session::VerifyWelcomeState"
}
],
"repo": "https://github.com/discord/libdave",
"vendor": "Discord",
"versions": [
{
"lessThan": "1.2.0",
"status": "affected",
"version": "1.1.0",
"versionType": "semver"
},
{
"lessThan": "9686fbaea864aa19f0675e486672b6a77811b6a1",
"status": "affected",
"version": "7b15f1fc16f159da0478aa6be909e38f1e957833",
"versionType": "git"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "MDL (https://heartbreak.ing)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-390",
"description": "CWE-390 Detection of Error Condition Without Action",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T00:57:55.648Z",
"orgId": "4ac701fe-44e9-4bcd-9585-dd6449257611",
"shortName": "Bugcrowd"
},
"references": [
{
"name": "[cpp] restore strict validation of MLS welcome state",
"tags": [
"patch"
],
"url": "https://github.com/discord/libdave/commit/9686fbaea864aa19f0675e486672b6a77811b6a1"
},
{
"name": "libdave v1.2.0 release notes",
"tags": [
"release-notes"
],
"url": "https://github.com/discord/libdave/releases/tag/v1.2.0/cpp"
},
{
"name": "Discord Audio and Video End-to-End Encryption (DAVE) Protocol Whitepaper",
"tags": [
"technical-description"
],
"url": "https://daveprotocol.com/"
},
{
"tags": [
"product"
],
"url": "https://github.com/discord/libdave"
}
],
"title": "Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "4ac701fe-44e9-4bcd-9585-dd6449257611",
"assignerShortName": "Bugcrowd",
"cveId": "CVE-2026-104480",
"datePublished": "2026-10-02T00:57:55.648Z",
"dateReserved": "2026-10-02T00:57:11.860Z",
"dateUpdated": "2026-10-02T00:57:55.648Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103098 (GCVE-0-2026-103098)
Vulnerability from cvelistv5 – Published: 2026-10-02 00:15 – Updated: 2026-10-02 00:15
VLAI
EPSS
VEX
Title
GV-Eye Sensitive information exposure in URL query parameter Vulnerability
Summary
Transmission of a sensitive key in the URL
over an unencrypted HTTP connection. The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traffic could intercept the request and obtain the key
Severity
7.5 (High)
CWE
- CWE-319 - Cleartext transmission of sensitive information
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.geovision.com.tw/cyber_security.php | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GeoVision Inc. | GV-Eye |
Affected:
V3.6.0
Unaffected: V3.7.2 cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:* |
Date Public
2026-09-30 02:15
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "tw.com.geovision.gveye",
"platforms": [
"Android"
],
"product": "GV-Eye",
"vendor": "GeoVision Inc.",
"versions": [
{
"status": "affected",
"version": "V3.6.0"
},
{
"status": "unaffected",
"version": "V3.7.2"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lloyd Lexter Gealon"
}
],
"datePublic": "2026-09-30T02:15:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u0026nbsp; The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
}
],
"value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u00a0 The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
}
],
"impacts": [
{
"capecId": "CAPEC-158",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-158 Sniffing Network Traffic"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319 Cleartext transmission of sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T00:15:17.848Z",
"orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"shortName": "GV"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.geovision.com.tw/cyber_security.php"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "GV-Eye Sensitive information exposure in URL query parameter Vulnerability",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"assignerShortName": "GV",
"cveId": "CVE-2026-103098",
"datePublished": "2026-10-02T00:15:17.848Z",
"dateReserved": "2026-09-30T02:10:02.128Z",
"dateUpdated": "2026-10-02T00:15:17.848Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103097 (GCVE-0-2026-103097)
Vulnerability from cvelistv5 – Published: 2026-10-02 00:14 – Updated: 2026-10-02 00:14
VLAI
EPSS
VEX
Title
GV-Eye Relay Payment API Key Vulnerability
Summary
An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.
Severity
7.5 (High)
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.geovision.com.tw/cyber_security.php | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| GeoVision Inc. | GV-Eye |
Affected:
V3.6.0
Unaffected: V3.7.2 cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:* |
Date Public
2026-09-30 02:15
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "tw.com.geovision.gveye",
"platforms": [
"Android"
],
"product": "GV-Eye",
"vendor": "GeoVision Inc.",
"versions": [
{
"status": "affected",
"version": "V3.6.0"
},
{
"status": "unaffected",
"version": "V3.7.2"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lloyd Lexter Gealon"
}
],
"datePublic": "2026-09-30T02:15:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.\u003c/p\u003e"
}
],
"value": "An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key."
}
],
"impacts": [
{
"capecId": "CAPEC-37",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-37 Retrieve Embedded Sensitive Data"
}
]
},
{
"capecId": "CAPEC-188",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-188 Reverse Engineering"
}
]
},
{
"capecId": "CAPEC-618",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-618 Cellular Broadcast Message Request"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "CWE-798: Use of Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-540",
"description": "CWE-540 Inclusion of sensitive information in source code",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-312",
"description": "CWE-312 Cleartext storage of sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T00:14:46.555Z",
"orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"shortName": "GV"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.geovision.com.tw/cyber_security.php"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "GV-Eye Relay Payment API Key Vulnerability",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"assignerShortName": "GV",
"cveId": "CVE-2026-103097",
"datePublished": "2026-10-02T00:14:46.555Z",
"dateReserved": "2026-09-30T02:10:01.788Z",
"dateUpdated": "2026-10-02T00:14:46.555Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}