Security Digest: October 2, 2026 - 38 Critical Vulnerabilities
Today’s alert is dominated by multiple critical WordPress plugin takeover flaws, plus serious memory, authentication, and file-access issues in infrastructure software. Several of these bugs are unauthenticated and can lead directly to admin access, data theft, or remote code execution.
· 19 min read
Executive Summary
Today’s alert is dominated by multiple critical WordPress plugin takeover flaws, plus serious memory, authentication, and file-access issues in infrastructure software. Several of these bugs are unauthenticated and can lead directly to admin access, data theft, or remote code execution.
Act now: patch exposed systems first, disable affected features where no fix exists, and review logs for suspicious authentication, file access, and plugin activity.
Critical Vulnerabilities
- CVE-2026-97637: JSON API Auth plugin session-cookie disclosure
- Impact: Attackers can steal a valid admin session cookie and take over the site.
- Affected Systems: JSON API Auth plugin for WordPress up to 3.1.2 with PI-Media/json-api active.
- Immediate Action: Disable the plugin or Auth controller now; rotate all WordPress auth cookies and admin passwords.
- Mitigation: Update to a fixed release as soon as available; clear caches and transients.
- CVE-2026-19660: Divi Membership authentication bypass
- Impact: Unauthenticated attackers can log in as any user, including administrators.
- Affected Systems: Divi Membership plugin up to 2.3.0.
- Immediate Action: Remove or disable the plugin on public sites; force password resets for all admins.
- Mitigation: Patch immediately and review accounts for unauthorized logins.
- CVE-2026-94541: WPMobile.App password-reset URL exposure
- Impact: Attackers can retrieve reset links and hijack accounts.
- Affected Systems: WPMobile.App up to 11.82 with mail-to-push enabled.
- Immediate Action: Turn off mail-to-push now; invalidate outstanding reset links.
- Mitigation: Upgrade and audit push queues for leaked reset URLs.
- CVE-2026-14378: DevKit Pro revert-switch takeover
- Impact: Unauthenticated attackers can obtain an admin session.
- Affected Systems: DevKit Pro up to 2.3.0.
- Immediate Action: Disable the plugin or switch-back feature immediately.
- Mitigation: Patch and review cookie-handling logic.
- CVE-2026-103764: Mooncake transfer engine memory read/write
- Impact: Attackers can read secrets, corrupt memory, and potentially execute code.
- Affected Systems: Mooncake transfer engine before 0.3.13.
- Immediate Action: Block access to the TCP data port from untrusted networks.
- Mitigation: Upgrade immediately and rotate any exposed secrets.
- CVE-2026-103765: Mooncake metadata server unauthenticated access
- Impact: Attackers can read, overwrite, or delete metadata and redirect transfers.
- Affected Systems: Mooncake through 0.3.13.post1.
- Immediate Action: Restrict metadata server reachability to trusted hosts only.
- Mitigation: Patch and verify metadata integrity.
- CVE-2026-15896: Super Forms directory traversal
- Impact: Arbitrary file read on the server, including secrets and config files.
- Affected Systems: Super Forms up to 6.3.316.
- Immediate Action: Disable file upload features or the plugin if exposed publicly.
- Mitigation: Update and enable authentication for file uploads where possible.
- CVE-2026-86345: 389-ds-base StartTLS message collision
- Impact: A failed bind can be treated as successful, enabling authentication bypass.
- Affected Systems: 389-ds-base installations using StartTLS.
- Immediate Action: Restrict LDAP access and monitor for unusual bind behavior.
- Mitigation: Apply vendor fixes and restart affected services.
- CVE-2026-93697: WHM Mass Modify Accounts stored XSS
- Impact: Stored script execution may lead to account compromise and admin-session abuse.
- Affected Systems: WHM Mass Modify Accounts interface.
- Immediate Action: Review and sanitize recent account changes.
- Mitigation: Patch WHM/cPanel components promptly.
- CVE-2026-93029: WHM Manage SSL Hosts stored XSS
- Impact: Admin browser compromise can lead to broader server takeover.
- Affected Systems: WHM Manage SSL Hosts interface.
- Immediate Action: Limit WHM access and inspect recent SSL host entries.
- Mitigation: Apply the vendor update.
- CVE-2026-80298: Sef AI Chatbot SQL injection
- Impact: Database exposure, tampering, and possible code execution paths.
- Affected Systems: Sef - AI Chatbot Platform before 2.1.
- Immediate Action: Restrict public access and review database logs.
- Mitigation: Upgrade to 2.1 or later.
- CVE-2026-15897: Super Forms privilege escalation
- Impact: Authenticated users can overwrite admin credentials.
- Affected Systems: Super Forms up to 6.3.316.
- Immediate Action: Disable the Register & Login add-on if not needed.
- Mitigation: Patch and reset affected account credentials.
- CVE-2026-92820: Ninja Forms file operations
- Impact: Arbitrary file read/write/delete; write path may lead to RCE.
- Affected Systems: Ninja Forms - File Uploads up to 3.3.34 with external S3 flow.
- Immediate Action: Disable external uploads and review attached-file email settings.
- Mitigation: Update and isolate upload storage.
- CVE-2026-103096 / CVE-2026-103097 / CVE-2026-103098: Hardcoded or exposed API keys
- Impact: Credential theft and unauthorized API use.
- Affected Systems: Android applications containing embedded keys; sensitive key sent over HTTP in one case.
- Immediate Action: Revoke exposed keys immediately and rotate secrets.
- Mitigation: Move secrets server-side and enforce HTTPS only.
- CVE-2026-92174: SiteOrigin Widgets Bundle local file inclusion
- Impact: Authenticated attackers can include and execute PHP files.
- Affected Systems: SiteOrigin Widgets Bundle up to 1.73.2.
- Immediate Action: Restrict contributor access and block preview endpoint exposure.
- Mitigation: Patch immediately.
- CVE-2026-104123: SourceCodester Online Reviewer SQL injection
- Impact: Remote SQL injection may expose or alter reviewer data.
- Affected Systems: Online Reviewer Management System 1.0.
- Immediate Action: Treat as exploitable now; isolate the app.
- Mitigation: Apply vendor fixes or remove the app until patched.
- CVE-2026-103426: Relevanssi Premium stored XSS
- Impact: Attacker scripts can run in visitors’ browsers.
- Affected Systems: Relevanssi Premium up to 2.31.4 with click-tracking enabled.
- Immediate Action: Disable click-tracking/logging if not essential.
- Mitigation: Update and review search-result pages.
- CVE-2026-95817: DoFollow Case by Case stored XSS
- Impact: Malicious comments can execute in every visitor’s browser.
- Affected Systems: DoFollow Case by Case up to 3.6.0.
- Immediate Action: Tighten comment moderation and review recent approvals.
- Mitigation: Patch and clear cached pages.
- CVE-2026-97342: JetFormBuilder stored XSS
- Impact: Unauthenticated payloads can persist in post meta and execute later.
- Affected Systems: JetFormBuilder up to 3.6.5.4.
- Immediate Action: Disable public form submissions if possible.
- Mitigation: Update and audit stored meta values.
- CVE-2026-97641: Relevanssi A Better Search stored XSS
- Impact: Script injection through comments.
- Affected Systems: Relevanssi up to 4.28.3 with allowable-tags configured.
- Immediate Action: Review excerpt-tag settings now.
- Mitigation: Patch and sanitize comment inputs.
- CVE-2026-93756: Smash Balloon Social Post Feed stored XSS
- Impact: Facebook comments can trigger admin-side script execution.
- Affected Systems: Smash Balloon Social Post Feed up to 4.13.0.
- Immediate Action: Restrict builder access and review connected social feeds.
- Mitigation: Patch and audit addon installation permissions.
- CVE-2026-95670: No External Links stored XSS
- Impact: Malicious URL logs can execute scripts.
- Affected Systems: No External Links up to 5.2.0 with Base64 encoding enabled.
- Immediate Action: Disable Base64 link encoding if not needed.
- Mitigation: Update and purge stored logs.
- CVE-2026-97336: CMB2 file_list stored XSS
- Impact: Injected scripts can run in pages using exposed file_list fields.
- Affected Systems: CMB2 up to 2.13.0 where integrations expose public fields.
- Immediate Action: Inventory public forms and user-meta boxes using CMB2.
- Mitigation: Patch and escape output in integrating plugins/themes.
- CVE-2026-96566: Newsletter plugin stored XSS
- Impact: Subscription input can store script payloads.
- Affected Systems: Newsletter up to 9.4.0.
- Immediate Action: Add anti-abuse controls and inspect subscriber data.
- Mitigation: Update and validate subscription endpoints.
- CVE-2026-96871: Mang Board stored XSS
- Impact: Guest posts can plant scripts in public boards.
- Affected Systems: Mang Board up to 2.4.2 with default guest-post settings.
- Immediate Action: Disable guest posting or strict-filter inputs now.
- Mitigation: Patch and review board permissions.
- CVE-2026-97663: Customer Reviews for WooCommerce stored XSS
- Impact: Reviews can inject scripts and abuse image upload flow.
- Affected Systems: Customer Reviews for WooCommerce up to 5.122.0 with image attachments enabled.
- Immediate Action: Disable review image uploads if possible.
- Mitigation: Patch and inspect recent reviews.
- CVE-2026-96567: MW WP Form stored XSS
- Impact: Form submissions can store script payloads.
- Affected Systems: MW WP Form up to 5.1.7.
- Immediate Action: Review public forms and reset suspicious double-submit cookies.
- Mitigation: Update and harden CSRF handling.
- CVE-2026-102772: CMB2 textarea_code stored XSS
- Impact: Public form fields can store malicious script.
- Affected Systems: CMB2 up to 2.13.1 with public CMB2 forms.
- Immediate Action: Remove exposed CMB2 forms until patched.
- Mitigation: Update and escape rendered textarea content.
- CVE-2026-87920: W3 Total Cache stored XSS
- Impact: Cached content rewriting can turn comments into script execution.
- Affected Systems: W3 Total Cache up to 2.10.6 with query-string stripping enabled.
- Immediate Action: Disable the risky option now if enabled.
- Mitigation: Patch and purge all caches.
- CVE-2026-100182: Download Monitor admin-editor XSS
- Impact: An admin can be tricked into storing malicious content.
- Affected Systems: Download Monitor up to 5.2.10.
- Immediate Action: Warn admins not to open untrusted edit screens.
- Mitigation: Update and restrict cross-origin messaging.
- CVE-2026-96578: GSpeech TTS stored XSS
- Impact: Comment payloads can become active script at render time.
- Affected Systems: GSpeech TTS up to 3.22.0.
- Immediate Action: Suspend public comments where feasible.
- Mitigation: Patch and clear rendered caches.
- CVE-2026-103766: ClipBucket SQL injection
- Impact: Authenticated attackers can extract or alter database records.
- Affected Systems: ClipBucket v5 through 5.5.3-#197 with ad_manager_access.
- Immediate Action: Review admin-role assignments immediately.
- Mitigation: Patch and monitor ads-manager queries.
- CVE-2026-100107: Kubio AI Page Builder stored XSS
- Impact: Public comment fields can inject scripts.
- Affected Systems: Kubio AI Page Builder up to 2.9.2.
- Immediate Action: Inspect public pages using Kubio comment blocks.
- Mitigation: Update and sanitize frontend inputs.
- CVE-2026-102565: BA Book Everything stored XSS
- Impact: Malicious booking data can run in admin order views.
- Affected Systems: BA Book Everything up to 1.8.28.
- Immediate Action: Review recent booking records for suspicious values.
- Mitigation: Patch and limit order-management access.
- CVE-2026-90438: Ninja Forms Paragraph Text RTE stored XSS
- Impact: Rich-text form submissions can execute scripts.
- Affected Systems: Ninja Forms up to 3.15.4 with RTE enabled.
- Immediate Action: Disable RTE on public forms now.
- Mitigation: Update and revalidate field sanitization.
- CVE-2026-93367: Visitors Traffic Real Time Statistics Pro stored XSS
- Impact: Unauthenticated input can execute in admin dashboards.
- Affected Systems: Visitors Traffic Real Time Statistics Pro up to 11.22.
- Immediate Action: Restrict dashboard access and inspect recent traffic-title entries.
- Mitigation: Patch and purge malicious rows.
Previously Alerted
What to Do Now
- Patch or disable the highest-risk WordPress plugins and exposed services first, especially anything with unauthenticated admin takeover or file access.
- Rotate credentials for administrators, API keys, cookies, and reset links if any affected system was exposed.
- Restrict access to WHM, LDAP, metadata servers, and plugin admin panels to trusted networks only.
- Review logs for suspicious auth events, unexpected file reads, unusual SQL errors, and admin-page script injection indicators.
- Purge caches and transient stores after remediation to remove cached malicious or sensitive content.
Verification steps: confirm plugin versions, check whether risky features are enabled, and validate that no exposed endpoint still accepts unauthenticated requests. Search for recent admin logins, password-reset activity, and unexpected changes to form submissions, comments, reviews, or traffic logs.
Monitoring recommendations: alert on new admin sessions, outbound requests to unknown domains, sudden changes in plugin settings, and repeated requests to sensitive endpoints such as /wp-json/, /wp-admin/, LDAP StartTLS flows, and metadata handlers.
Related Resources
- Internal blog post: WordPress Plugin Triage for Active Exploitation (coming soon)
- Internal blog post: Fast Response Playbook for Admin Session Theft (coming soon)
- Official vendor advisories: WordPress plugin repositories, cPanel/WHM security notices, 389-ds-base release notes, and Mooncake project security updates