Security Digest: October 3, 2026 - 32 Critical Vulnerabilities
Today’s disclosures include multiple critical remote code execution issues, unauthenticated server breakouts, and widespread WordPress plugin flaws that can expose data, delete files, or hijack admin sessions. The most urgent priorities are to patch exposed systems now, disable or isolate vulnerable services, and review any shared runner, web admin, or public-facing plugin deployments for signs of abuse.
· 19 min read
Today’s Security Alert: 32 High-Risk Flaws Demand Immediate Action
Executive Summary: Today’s disclosures include multiple critical remote code execution issues, unauthenticated server breakouts, and widespread WordPress plugin flaws that can expose data, delete files, or hijack admin sessions. The most urgent priorities are to patch exposed systems now, disable or isolate vulnerable services, and review any shared runner, web admin, or public-facing plugin deployments for signs of abuse.
Do not wait for exploitation reports. Several of these bugs require no authentication and can be triggered with a single request or a crafted workflow. If you operate shared CI runners, RouterOS web management, or public WordPress sites, treat this as an active incident window.
Critical Vulnerabilities
- CVE-2026-73802: act_runner workflow breakout via container options
- Impact: Remote workflow authors can escape the job container, enter host namespaces, and run commands as root on the runner host.
- Affected Systems:
gitea.com/gitea/runnerwith Docker-backed shared runners. - Immediate Action: Disable untrusted workflow execution on shared runners immediately; move to single-tenant or locked-down runners.
- Mitigation: Patch when available; strip or reject dangerous
container.optionsflags and keep runners isolated.
- CVE-2026-105080: ConvertX recipe file execution
- Impact: Malicious
.recipeor.downloaded_recipefiles can reach Calibre’sebook-convertand execute attacker-controlled code. - Affected Systems: ConvertX before 0.19.0.
- Immediate Action: Block untrusted recipe uploads and remove exposure to public file submission paths.
- Mitigation: Upgrade to 0.19.0 or later.
- Impact: Malicious
- CVE-2026-84411: RouterOS web management pre-auth RCE
- Impact: An unauthenticated attacker can trigger arbitrary code execution as root or cause a DoS with one crafted request.
- Affected Systems: Affected MikroTik RouterOS versions with web management enabled.
- Immediate Action: Disable WAN exposure of web management now and restrict admin access to trusted networks only.
- Mitigation: Apply the vendor fix as soon as it is available; monitor for unexpected reboots or web service crashes.
- CVE-2026-92084: Beaver Builder arbitrary shortcode execution
- Impact: Unauthenticated attackers can execute arbitrary shortcodes on sites with the right widget setup.
- Affected Systems: Beaver Builder Page Builder up to 2.11.0.5.
- Immediate Action: Remove exposed sidebar/widget combinations that accept attacker-controlled text.
- Mitigation: Update beyond 2.11.0.5 and review pages using the Sidebar module.
- CVE-2026-87115: VikAppointments arbitrary file deletion
- Impact: Attackers can delete arbitrary files, potentially leading to full site compromise if key files are removed.
- Affected Systems: VikAppointments up to 1.2.21.
- Immediate Action: Disable the affected confirmation-page shortcode and restrict public access to booking flows.
- Mitigation: Patch immediately; verify integrity of
wp-config.phpand related files.
- CVE-2026-92536: ProfilePress sensitive data exposure
- Impact: Attackers can extract email addresses, usernames, and registration dates; some paths are reachable by unauthenticated users.
- Affected Systems: ProfilePress up to 4.17.4.
- Immediate Action: Restrict member directory access and disable public registration if not required.
- Mitigation: Update and audit shortcode usage that exposes profile fields.
- CVE-2026-18443: Smart Manager SQL injection
- Impact: Authenticated users can inject SQL and extract database data under certain admin-configured privilege settings.
- Affected Systems: Smart Manager up to 8.97.0.
- Immediate Action: Review role-based access privilege settings and disable the vulnerable handler if possible.
- Mitigation: Upgrade and verify deny-list configuration.
- CVE-2026-97644: Groundhogg contact rebinding to administrator
- Impact: Attackers can rebind contacts to admin IDs and potentially obtain authenticated admin sessions.
- Affected Systems: Groundhogg up to 4.9.
- Immediate Action: Restrict Sales Representative capability and review contact records for suspicious user_id changes.
- Mitigation: Patch immediately and invalidate suspicious email-test links.
- CVE-2026-71416: Headroom WebSocket origin bypass
- Impact: Malicious browser-based clients can issue arbitrary LLM requests and potentially abuse tools such as shell access.
- Affected Systems:
headroom-ai. - Immediate Action: Do not expose the proxy to untrusted browser networks; remove
OPENAI_API_KEYfrom shared environments where possible. - Mitigation: Add strict Origin checks and update the package.
- CVE-2026-101923: Photo Reviews arbitrary content deletion
- Impact: Later deletion of a malicious review can delete arbitrary posts, pages, products, or media.
- Affected Systems: Photo Reviews for WooCommerce up to 1.2.30.
- Immediate Action: Suspend review deletion workflows and inspect stored review image IDs.
- Mitigation: Upgrade and purge malicious review metadata.
- CVE-2026-94505: Nelio Content authorization bypass
- Impact: Contributors can delete reusable social messages belonging to higher-privileged users.
- Affected Systems: Nelio Content up to 4.5.0.
- Immediate Action: Limit contributor access until patched.
- Mitigation: Update and review reusable social content.
- CVE-2026-19481: @fastify/busboy multipart parser crash
- Impact: A crafted multipart request can crash the process or trigger a DoS.
- Affected Systems:
@fastify/busboy1.0.0 through 3.2.0. - Immediate Action: Upgrade immediately and ensure error handlers are in place.
- Mitigation: Move to 3.2.1.
- CVE-2026-74904: SiYuan block data disclosure
- Impact: Anonymous users can retrieve block text, structure, and existence data from published workspaces.
- Affected Systems:
github.com/siyuan-note/siyuan/kernelat current HEAD. - Immediate Action: Restrict public exposure of published workspaces.
- Mitigation: Apply a fix that adds authorization checks to all affected block handlers.
- CVE-2026-19484: @fastify/busboy boundary loop DoS
- Impact: A crafted multipart boundary can pin the Node.js event loop at 100% CPU.
- Affected Systems:
@fastify/busboy3.1.0 and earlier. - Immediate Action: Reject abnormal multipart boundaries at the edge.
- Mitigation: Upgrade to 3.2.1.
- CVE-2026-93428: Ultimate Member privacy bypass
- Impact: Anonymous users can view privacy-restricted profile fields.
- Affected Systems: Ultimate Member up to 2.13.1.
- Immediate Action: Treat public member directory exposure as unsafe until patched.
- Mitigation: Update and review all AJAX endpoints.
- CVE-2026-103913: GeoDirectory SQL injection via coordinates
- Impact: Attackers can inject SQL through stored listing coordinates and extract database data.
- Affected Systems: GeoDirectory up to 2.8.186.
- Immediate Action: Audit pending listings and public widget endpoints.
- Mitigation: Upgrade and validate numeric coordinate input.
- CVE-2026-97337: Simple Membership email hijack
- Impact: Attackers can redirect activation and registration emails, then activate accounts without consent.
- Affected Systems: Simple Membership up to 4.8.3.
- Immediate Action: Pause self-service registration if possible.
- Mitigation: Patch and rotate exposed registration workflows.
- CVE-2026-75028: WPCafe local file inclusion
- Impact: Authenticated users can include and execute arbitrary PHP files.
- Affected Systems: WPCafe up to 3.0.18.
- Immediate Action: Restrict contributor access and audit template-scope usage.
- Mitigation: Upgrade and remove risky file inclusion paths.
- CVE-2026-104861: probe-image-size SVG parser DoS
- Impact: Crafted SVG input can monopolize CPU and block the event loop.
- Affected Systems:
probe-image-sizein sync, stream, and URL paths. - Immediate Action: Rate-limit image validation and cap untrusted SVG input.
- Mitigation: Patch and avoid parsing attacker-supplied SVG without limits.
- CVE-2026-96267: WP Visitor Statistics second-order SQL injection
- Impact: A crafted referrer can become SQL injection when an admin views the dashboard.
- Affected Systems: WP Visitor Statistics up to 8.7.
- Immediate Action: Review traffic-source dashboards and block suspicious referrer logging.
- Mitigation: Update and sanitize stored analytics data.
- CVE-2026-96650: Strong Testimonials stored XSS
- Impact: Attackers can inject scripts into public testimonial pages.
- Affected Systems: Strong Testimonials up to 3.3.11.
- Immediate Action: Disable public submission forms with custom platform fields.
- Mitigation: Patch and re-sanitize stored testimonials.
- CVE-2026-93430: GD Rating System stored XSS
- Impact: Attackers can inject script through public AJAX rating data.
- Affected Systems: GD Rating System up to 3.7.1.
- Immediate Action: Treat the public rating endpoint as untrusted until patched.
- Mitigation: Update and verify nonce handling is not publicly exposed.
- CVE-2026-96564: SEOPress author-name XSS
- Impact: Public content can inject script into analytics tracking output.
- Affected Systems: SEOPress up to 10.2.
- Immediate Action: Audit author display names on public content sources.
- Mitigation: Upgrade and sanitize tracking script output.
- CVE-2026-97660: WPC Product Options multipart-field XSS
- Impact: Guest checkout can store script payloads in order metadata.
- Affected Systems: WPC Product Options for WooCommerce up to 4.0.5.
- Immediate Action: Review guest checkout submissions and order-item metadata.
- Mitigation: Patch and validate multipart field names.
- CVE-2026-92977: Real Cookie Banner comment XSS
- Impact: Comment content can become executable script when rendered.
- Affected Systems: Real Cookie Banner up to 5.3.5.
- Immediate Action: Tighten comment moderation and inspect affected pages.
- Mitigation: Upgrade and review render-time regex behavior.
- CVE-2026-96270: Ultimate Member form_id stored XSS
- Impact: A malicious registration payload can execute in wp-admin.
- Affected Systems: Ultimate Member up to 2.13.1.
- Immediate Action: Review pending registrations and admin user views.
- Mitigation: Patch and sanitize stored usermeta.
- CVE-2026-93889: WP Mail Catcher mail-failure XSS
- Impact: Failed mail content can carry script into admin logs.
- Affected Systems: WP Mail Catcher up to 2.1.12.
- Immediate Action: Treat mail-failure logs as untrusted input.
- Mitigation: Update and limit plugins that feed user input into mail fields.
- CVE-2026-87091: Welcart IPN stored XSS
- Impact: Unauthenticated settlement notifications can store script in admin logs.
- Affected Systems: Welcart e-Commerce up to 2.12.2.
- Immediate Action: Restrict public IPN access and inspect settlement logs.
- Mitigation: Patch and require signature verification.
- CVE-2026-96575: Transliterator comment-content XSS
- Impact: Comment content can render attacker script on public pages.
- Affected Systems: Transliterator up to 2.5.8.
- Immediate Action: Audit public comments and disable risky placeholder use.
- Mitigation: Upgrade and harden output escaping.
- CVE-2026-97341: Visitor Traffic X-Real-IP stored DOM XSS
- Impact: Forged headers can store script that later executes in admin views.
- Affected Systems: Visitor Traffic Real Time Statistics up to 8.16.
- Immediate Action: Block header spoofing at the edge and review traffic logs.
- Mitigation: Patch and stop trusting client-supplied IP headers.
- CVE-2026-101928: Magic Tooltips author parameter XSS
- Impact: Entity-encoded payloads can be decoded into live HTML in admin pages.
- Affected Systems: Magic Tooltips For Contact Form 7 up to 1.0.34.
- Immediate Action: Review comment author fields for encoded payloads.
- Mitigation: Update and remove unsafe HTML-decoding filters.
- CVE-2026-104478: Formwork path traversal in backup controller
- Impact: Authenticated panel users can read or delete arbitrary files.
- Affected Systems: Formwork before 2.3.13.
- Immediate Action: Restrict backup download/delete permissions immediately.
- Mitigation: Upgrade and verify filesystem access controls.
What to Do Now
- Patch or disable exposed systems first. Prioritize RouterOS web management, shared CI runners, and public WordPress plugins that are directly internet-facing.
- Contain before you remediate. If you cannot patch immediately, remove public access, restrict source IPs, or disable the vulnerable feature path.
- Assume exploitation may already have happened. Review admin logins, unexpected file changes, new shortcodes, suspicious workflow runs, and unusual outbound traffic.
- Verify versions and package locks. Check deployed plugin/package versions against the vulnerable ranges, not just the latest source tree.
- Invalidate risky credentials. Rotate API keys, WordPress admin sessions, runner secrets, and any tokens exposed through affected services.
Verification steps:
- Inventory all exposed WordPress plugins and compare against the vulnerable version list.
- Check CI runners for shared tenancy and any workflow use of untrusted container options.
- Confirm RouterOS web management is not reachable from the internet.
- Search logs for crafted multipart requests, unusual shortcodes, and suspicious WebSocket origins.
Monitoring recommendations: Watch for new admin accounts, unexpected file deletions, outbound requests from runners or CMS hosts, repeated multipart upload errors, and spikes in CPU on Node.js services. Alert on changes to login behavior, contact/user rebindings, and any sudden growth in failed mail or comment-render events.
Related Resources
- Internal: Add your organization’s incident note or remediation blog post here once published.
- Official vendor advisories: Review vendor notices for Gitea Runner, MikroTik RouterOS, Calibre/ConvertX, Fastify, SiYuan, and each affected WordPress plugin before applying updates.