Security Digest: October 2, 2026 - 38 Critical Vulnerabilities

Today’s alert is dominated by multiple critical WordPress plugin takeover flaws, plus serious memory, authentication, and file-access issues in infrastructure software. Several of these bugs are unauthenticated and can lead directly to admin access, data theft, or remote code execution.

· 19 min read

Executive Summary

Today’s alert is dominated by multiple critical WordPress plugin takeover flaws, plus serious memory, authentication, and file-access issues in infrastructure software. Several of these bugs are unauthenticated and can lead directly to admin access, data theft, or remote code execution.

Act now: patch exposed systems first, disable affected features where no fix exists, and review logs for suspicious authentication, file access, and plugin activity.

Critical Vulnerabilities

  • CVE-2026-97637: JSON API Auth plugin session-cookie disclosure
    • Impact: Attackers can steal a valid admin session cookie and take over the site.
    • Affected Systems: JSON API Auth plugin for WordPress up to 3.1.2 with PI-Media/json-api active.
    • Immediate Action: Disable the plugin or Auth controller now; rotate all WordPress auth cookies and admin passwords.
    • Mitigation: Update to a fixed release as soon as available; clear caches and transients.
  • CVE-2026-19660: Divi Membership authentication bypass
    • Impact: Unauthenticated attackers can log in as any user, including administrators.
    • Affected Systems: Divi Membership plugin up to 2.3.0.
    • Immediate Action: Remove or disable the plugin on public sites; force password resets for all admins.
    • Mitigation: Patch immediately and review accounts for unauthorized logins.
  • CVE-2026-94541: WPMobile.App password-reset URL exposure
    • Impact: Attackers can retrieve reset links and hijack accounts.
    • Affected Systems: WPMobile.App up to 11.82 with mail-to-push enabled.
    • Immediate Action: Turn off mail-to-push now; invalidate outstanding reset links.
    • Mitigation: Upgrade and audit push queues for leaked reset URLs.
  • CVE-2026-14378: DevKit Pro revert-switch takeover
    • Impact: Unauthenticated attackers can obtain an admin session.
    • Affected Systems: DevKit Pro up to 2.3.0.
    • Immediate Action: Disable the plugin or switch-back feature immediately.
    • Mitigation: Patch and review cookie-handling logic.
  • CVE-2026-103764: Mooncake transfer engine memory read/write
    • Impact: Attackers can read secrets, corrupt memory, and potentially execute code.
    • Affected Systems: Mooncake transfer engine before 0.3.13.
    • Immediate Action: Block access to the TCP data port from untrusted networks.
    • Mitigation: Upgrade immediately and rotate any exposed secrets.
  • CVE-2026-103765: Mooncake metadata server unauthenticated access
    • Impact: Attackers can read, overwrite, or delete metadata and redirect transfers.
    • Affected Systems: Mooncake through 0.3.13.post1.
    • Immediate Action: Restrict metadata server reachability to trusted hosts only.
    • Mitigation: Patch and verify metadata integrity.
  • CVE-2026-15896: Super Forms directory traversal
    • Impact: Arbitrary file read on the server, including secrets and config files.
    • Affected Systems: Super Forms up to 6.3.316.
    • Immediate Action: Disable file upload features or the plugin if exposed publicly.
    • Mitigation: Update and enable authentication for file uploads where possible.
  • CVE-2026-86345: 389-ds-base StartTLS message collision
    • Impact: A failed bind can be treated as successful, enabling authentication bypass.
    • Affected Systems: 389-ds-base installations using StartTLS.
    • Immediate Action: Restrict LDAP access and monitor for unusual bind behavior.
    • Mitigation: Apply vendor fixes and restart affected services.
  • CVE-2026-93697: WHM Mass Modify Accounts stored XSS
    • Impact: Stored script execution may lead to account compromise and admin-session abuse.
    • Affected Systems: WHM Mass Modify Accounts interface.
    • Immediate Action: Review and sanitize recent account changes.
    • Mitigation: Patch WHM/cPanel components promptly.
  • CVE-2026-93029: WHM Manage SSL Hosts stored XSS
    • Impact: Admin browser compromise can lead to broader server takeover.
    • Affected Systems: WHM Manage SSL Hosts interface.
    • Immediate Action: Limit WHM access and inspect recent SSL host entries.
    • Mitigation: Apply the vendor update.
  • CVE-2026-80298: Sef AI Chatbot SQL injection
    • Impact: Database exposure, tampering, and possible code execution paths.
    • Affected Systems: Sef - AI Chatbot Platform before 2.1.
    • Immediate Action: Restrict public access and review database logs.
    • Mitigation: Upgrade to 2.1 or later.
  • CVE-2026-15897: Super Forms privilege escalation
    • Impact: Authenticated users can overwrite admin credentials.
    • Affected Systems: Super Forms up to 6.3.316.
    • Immediate Action: Disable the Register & Login add-on if not needed.
    • Mitigation: Patch and reset affected account credentials.
  • CVE-2026-92820: Ninja Forms file operations
    • Impact: Arbitrary file read/write/delete; write path may lead to RCE.
    • Affected Systems: Ninja Forms - File Uploads up to 3.3.34 with external S3 flow.
    • Immediate Action: Disable external uploads and review attached-file email settings.
    • Mitigation: Update and isolate upload storage.
  • CVE-2026-103096 / CVE-2026-103097 / CVE-2026-103098: Hardcoded or exposed API keys
    • Impact: Credential theft and unauthorized API use.
    • Affected Systems: Android applications containing embedded keys; sensitive key sent over HTTP in one case.
    • Immediate Action: Revoke exposed keys immediately and rotate secrets.
    • Mitigation: Move secrets server-side and enforce HTTPS only.
  • CVE-2026-92174: SiteOrigin Widgets Bundle local file inclusion
    • Impact: Authenticated attackers can include and execute PHP files.
    • Affected Systems: SiteOrigin Widgets Bundle up to 1.73.2.
    • Immediate Action: Restrict contributor access and block preview endpoint exposure.
    • Mitigation: Patch immediately.
  • CVE-2026-104123: SourceCodester Online Reviewer SQL injection
    • Impact: Remote SQL injection may expose or alter reviewer data.
    • Affected Systems: Online Reviewer Management System 1.0.
    • Immediate Action: Treat as exploitable now; isolate the app.
    • Mitigation: Apply vendor fixes or remove the app until patched.
  • CVE-2026-103426: Relevanssi Premium stored XSS
    • Impact: Attacker scripts can run in visitors’ browsers.
    • Affected Systems: Relevanssi Premium up to 2.31.4 with click-tracking enabled.
    • Immediate Action: Disable click-tracking/logging if not essential.
    • Mitigation: Update and review search-result pages.
  • CVE-2026-95817: DoFollow Case by Case stored XSS
    • Impact: Malicious comments can execute in every visitor’s browser.
    • Affected Systems: DoFollow Case by Case up to 3.6.0.
    • Immediate Action: Tighten comment moderation and review recent approvals.
    • Mitigation: Patch and clear cached pages.
  • CVE-2026-97342: JetFormBuilder stored XSS
    • Impact: Unauthenticated payloads can persist in post meta and execute later.
    • Affected Systems: JetFormBuilder up to 3.6.5.4.
    • Immediate Action: Disable public form submissions if possible.
    • Mitigation: Update and audit stored meta values.
  • CVE-2026-97641: Relevanssi A Better Search stored XSS
    • Impact: Script injection through comments.
    • Affected Systems: Relevanssi up to 4.28.3 with allowable-tags configured.
    • Immediate Action: Review excerpt-tag settings now.
    • Mitigation: Patch and sanitize comment inputs.
  • CVE-2026-93756: Smash Balloon Social Post Feed stored XSS
    • Impact: Facebook comments can trigger admin-side script execution.
    • Affected Systems: Smash Balloon Social Post Feed up to 4.13.0.
    • Immediate Action: Restrict builder access and review connected social feeds.
    • Mitigation: Patch and audit addon installation permissions.
  • CVE-2026-95670: No External Links stored XSS
    • Impact: Malicious URL logs can execute scripts.
    • Affected Systems: No External Links up to 5.2.0 with Base64 encoding enabled.
    • Immediate Action: Disable Base64 link encoding if not needed.
    • Mitigation: Update and purge stored logs.
  • CVE-2026-97336: CMB2 file_list stored XSS
    • Impact: Injected scripts can run in pages using exposed file_list fields.
    • Affected Systems: CMB2 up to 2.13.0 where integrations expose public fields.
    • Immediate Action: Inventory public forms and user-meta boxes using CMB2.
    • Mitigation: Patch and escape output in integrating plugins/themes.
  • CVE-2026-96566: Newsletter plugin stored XSS
    • Impact: Subscription input can store script payloads.
    • Affected Systems: Newsletter up to 9.4.0.
    • Immediate Action: Add anti-abuse controls and inspect subscriber data.
    • Mitigation: Update and validate subscription endpoints.
  • CVE-2026-96871: Mang Board stored XSS
    • Impact: Guest posts can plant scripts in public boards.
    • Affected Systems: Mang Board up to 2.4.2 with default guest-post settings.
    • Immediate Action: Disable guest posting or strict-filter inputs now.
    • Mitigation: Patch and review board permissions.
  • CVE-2026-97663: Customer Reviews for WooCommerce stored XSS
    • Impact: Reviews can inject scripts and abuse image upload flow.
    • Affected Systems: Customer Reviews for WooCommerce up to 5.122.0 with image attachments enabled.
    • Immediate Action: Disable review image uploads if possible.
    • Mitigation: Patch and inspect recent reviews.
  • CVE-2026-96567: MW WP Form stored XSS
    • Impact: Form submissions can store script payloads.
    • Affected Systems: MW WP Form up to 5.1.7.
    • Immediate Action: Review public forms and reset suspicious double-submit cookies.
    • Mitigation: Update and harden CSRF handling.
  • CVE-2026-102772: CMB2 textarea_code stored XSS
    • Impact: Public form fields can store malicious script.
    • Affected Systems: CMB2 up to 2.13.1 with public CMB2 forms.
    • Immediate Action: Remove exposed CMB2 forms until patched.
    • Mitigation: Update and escape rendered textarea content.
  • CVE-2026-87920: W3 Total Cache stored XSS
    • Impact: Cached content rewriting can turn comments into script execution.
    • Affected Systems: W3 Total Cache up to 2.10.6 with query-string stripping enabled.
    • Immediate Action: Disable the risky option now if enabled.
    • Mitigation: Patch and purge all caches.
  • CVE-2026-100182: Download Monitor admin-editor XSS
    • Impact: An admin can be tricked into storing malicious content.
    • Affected Systems: Download Monitor up to 5.2.10.
    • Immediate Action: Warn admins not to open untrusted edit screens.
    • Mitigation: Update and restrict cross-origin messaging.
  • CVE-2026-96578: GSpeech TTS stored XSS
    • Impact: Comment payloads can become active script at render time.
    • Affected Systems: GSpeech TTS up to 3.22.0.
    • Immediate Action: Suspend public comments where feasible.
    • Mitigation: Patch and clear rendered caches.
  • CVE-2026-103766: ClipBucket SQL injection
    • Impact: Authenticated attackers can extract or alter database records.
    • Affected Systems: ClipBucket v5 through 5.5.3-#197 with ad_manager_access.
    • Immediate Action: Review admin-role assignments immediately.
    • Mitigation: Patch and monitor ads-manager queries.
  • CVE-2026-100107: Kubio AI Page Builder stored XSS
    • Impact: Public comment fields can inject scripts.
    • Affected Systems: Kubio AI Page Builder up to 2.9.2.
    • Immediate Action: Inspect public pages using Kubio comment blocks.
    • Mitigation: Update and sanitize frontend inputs.
  • CVE-2026-102565: BA Book Everything stored XSS
    • Impact: Malicious booking data can run in admin order views.
    • Affected Systems: BA Book Everything up to 1.8.28.
    • Immediate Action: Review recent booking records for suspicious values.
    • Mitigation: Patch and limit order-management access.
  • CVE-2026-90438: Ninja Forms Paragraph Text RTE stored XSS
    • Impact: Rich-text form submissions can execute scripts.
    • Affected Systems: Ninja Forms up to 3.15.4 with RTE enabled.
    • Immediate Action: Disable RTE on public forms now.
    • Mitigation: Update and revalidate field sanitization.
  • CVE-2026-93367: Visitors Traffic Real Time Statistics Pro stored XSS
    • Impact: Unauthenticated input can execute in admin dashboards.
    • Affected Systems: Visitors Traffic Real Time Statistics Pro up to 11.22.
    • Immediate Action: Restrict dashboard access and inspect recent traffic-title entries.
    • Mitigation: Patch and purge malicious rows.

Previously Alerted

What to Do Now

  1. Patch or disable the highest-risk WordPress plugins and exposed services first, especially anything with unauthenticated admin takeover or file access.
  2. Rotate credentials for administrators, API keys, cookies, and reset links if any affected system was exposed.
  3. Restrict access to WHM, LDAP, metadata servers, and plugin admin panels to trusted networks only.
  4. Review logs for suspicious auth events, unexpected file reads, unusual SQL errors, and admin-page script injection indicators.
  5. Purge caches and transient stores after remediation to remove cached malicious or sensitive content.

Verification steps: confirm plugin versions, check whether risky features are enabled, and validate that no exposed endpoint still accepts unauthenticated requests. Search for recent admin logins, password-reset activity, and unexpected changes to form submissions, comments, reviews, or traffic logs.

Monitoring recommendations: alert on new admin sessions, outbound requests to unknown domains, sudden changes in plugin settings, and repeated requests to sensitive endpoints such as /wp-json/, /wp-admin/, LDAP StartTLS flows, and metadata handlers.

Related Resources

  • Internal blog post: WordPress Plugin Triage for Active Exploitation (coming soon)
  • Internal blog post: Fast Response Playbook for Admin Session Theft (coming soon)
  • Official vendor advisories: WordPress plugin repositories, cPanel/WHM security notices, 389-ds-base release notes, and Mooncake project security updates

Keep reading