Security Digest: October 4, 2026 - 8 Critical Vulnerabilities

Today’s alerts include a CVSS 10 code injection in InternLM MindSearch, a critical SQL injection in Unlimited Elements for Elementor, and multiple high-severity web app flaws that can lead to remote code execution, authentication bypass, and cross-site scripting. If you run any affected products, patch or remove exposure now, then verify internet-facing systems and review logs for exploitation.

· 8 min read

Urgent Security Digest: Eight Critical Vulnerabilities Demand Immediate Action

Executive Summary

Today’s alerts include a CVSS 10 code injection in InternLM MindSearch, a critical SQL injection in Unlimited Elements for Elementor, and multiple high-severity web app flaws that can lead to remote code execution, authentication bypass, and cross-site scripting. If you run any affected products, patch or remove exposure now, then verify internet-facing systems and review logs for exploitation.

Critical Vulnerabilities

CVE-2026-105135: InternLM MindSearch code injection in Planner Agent

Impact: Remote attackers can inject code through the Planner Agent’s execution path, potentially leading to full compromise of the application environment.

Affected Systems: InternLM MindSearch 0.1.0

Immediate Action: Take the service offline or restrict access immediately if MindSearch is exposed. Disable untrusted inputs to the Planner Agent and block remote access until a fixed release is available.

Mitigation: Apply a vendor patch as soon as one is released; if no fix exists, isolate the instance, rotate credentials, and treat the environment as potentially compromised. Public exploit disclosure increases urgency.

CVE-2026-103355: Unlimited Elements for Elementor blind SQL injection

Impact: Attackers may extract data from the database, bypass controls, or pivot into the WordPress environment.

Affected Systems: Unlimited Elements For Elementor up to 2.0.20

Immediate Action: Update this plugin immediately or disable it if you cannot patch today. Review all sites using Elementor add-ons, especially public-facing WordPress installs.

Mitigation: Upgrade to a fixed version from the vendor. Until then, limit admin access, monitor database error logs, and watch for unusual query patterns.

CVE-2026-105123: wcms authenticated file write leading to remote code execution

Impact: Authenticated editors can upload arbitrary files, including PHP, and execute code on the server.

Affected Systems: vincent-peugnet/wcms through 3.18.0

Immediate Action: Remove editor access where possible, restrict upload endpoints, and inspect media upload paths for suspicious files. Assume compromise if untrusted editors exist.

Mitigation: Patch to a fixed version when available. As a workaround, block PHP execution in upload directories and review for path traversal abuse and unexpected file deletions.

CVE-2026-105133: AhsayCBS improper authentication via API

Impact: Remote attackers may bypass authentication and gain unauthorized access to API functions.

Affected Systems: Ahsay AhsayCBS up to 10.3.2

Immediate Action: Upgrade now to 10.3.4 or later. Restrict API exposure to trusted networks until patching is complete.

Mitigation: Apply the vendor-recommended update. Review authentication logs for unusual access attempts and rotate any exposed secrets.

CVE-2026-97276: WP Statistics reflected XSS

Impact: Attackers can run malicious script in a victim’s browser, potentially stealing sessions or performing admin actions.

Affected Systems: WP Statistics up to 14.16.14

Immediate Action: Update the plugin immediately and warn administrators not to click suspicious links into analytics pages.

Mitigation: Install the vendor fix, clear cached pages, and review admin activity for signs of session abuse.

CVE-2026-103062: TranslatePress stored XSS

Impact: Malicious content can persist in the site and execute in admin or visitor browsers.

Affected Systems: TranslatePress up to 3.3.6

Immediate Action: Patch now and review multilingual content, forms, and translation inputs for injected scripts.

Mitigation: Upgrade to a fixed version and inspect user-generated content, translation fields, and recent edits for suspicious payloads.

CVE-2026-103354: Kadence Blocks stored XSS

Impact: Stored script injection can compromise admin sessions or alter site behavior for visitors.

Affected Systems: Gutenberg Blocks by Kadence Blocks up to 3.7.11.1

Immediate Action: Update immediately on any WordPress site using Kadence Blocks.

Mitigation: Apply the vendor patch, review block content created recently, and monitor for unauthorized admin actions.

CVE-2026-103344: Unlimited Elements for Elementor reflected XSS

Impact: Attackers can trick users into executing malicious script through crafted requests or links.

Affected Systems: Unlimited Elements For Elementor up to 2.0.20

Immediate Action: Patch alongside CVE-2026-103355 and reduce exposure of plugin-driven pages.

Mitigation: Upgrade to the fixed release, validate admin workflows, and monitor for suspicious referrers and request parameters.

Previously Alerted

What to Do Now

  1. Patch or disable exposed instances today, starting with InternLM MindSearch, Unlimited Elements for Elementor, AhsayCBS, TranslatePress, Kadence Blocks, WP Statistics, and wcms.
  2. Restrict internet exposure for admin panels, upload endpoints, and APIs until updates are confirmed.
  3. Assume possible compromise where public exploit code exists; rotate credentials and API keys used by affected systems.
  4. Review logs immediately for suspicious uploads, SQL errors, unexpected admin actions, and unusual authentication attempts.
  5. Verify versions across all environments, including staging and customer-facing WordPress sites.

Verification steps: confirm installed plugin and application versions, check whether any affected service is publicly reachable, and search for webshells, unexpected PHP files, or recent admin accounts. If you cannot verify patch status, treat the asset as at risk.

Monitoring recommendations: alert on file writes in web directories, repeated failed logins, abnormal SQL error spikes, new translation or block content edits, and outbound connections from application servers. Keep heightened monitoring in place for at least 72 hours after remediation.

Related Resources

  • Internal blog posts: add links to your organization’s patch guidance and incident-response playbooks when available.
  • Official vendor advisories: monitor vendor security pages for InternLM, Unlimited Elements, Ahsay, WP Statistics, TranslatePress, Kadence Blocks, and wcms for fixed releases and workarounds.

Keep reading