Security Digest: October 6, 2026 - 113 Critical Vulnerabilities

Today’s alert is severe: 113 critical vulnerabilities were disclosed across WordPress plugins/themes, Node.js libraries, network devices, and application frameworks. The fastest path to compromise is still the same: unauthenticated file upload, SQL injection, remote code execution, and privilege escalation.

· 25 min read

Executive Summary

Today’s alert is severe: 113 critical vulnerabilities were disclosed across WordPress plugins/themes, Node.js libraries, network devices, and application frameworks. The fastest path to compromise is still the same: unauthenticated file upload, SQL injection, remote code execution, and privilege escalation. Patch exposed internet-facing systems first, then move to internal services and developer dependencies.

Immediate priority: update or disable affected products now, remove risky allowlists and unsafe custom arguments, and assume exposed admin panels, upload handlers, and sandbox bridges are high-risk until verified.

Critical Vulnerabilities

  • CVE-2026-32579: Kognetiks Chatbot arbitrary file upload
    Impact: Remote attackers can upload files without authentication, creating a likely path to code execution or webshell placement.
    Affected Systems: Kognetiks Chatbot for WordPress <= 2.4.9.
    Immediate Action: Disable the plugin or remove public access until patched.
    Mitigation: Apply the vendor fix as soon as available; restrict upload endpoints at the web server/WAF.
  • CVE-2026-39770: Doctreat arbitrary file upload
    Impact: Unauthenticated file upload can lead to server compromise.
    Affected Systems: Doctreat <= 1.7.0.
    Immediate Action: Patch or take the site offline if the plugin is exposed publicly.
    Mitigation: Upgrade immediately; block upload routes and review for unexpected files.
  • CVE-2026-39773: Doctreat Core privilege escalation
    Impact: Attackers can gain elevated access without proper authorization.
    Affected Systems: Doctreat Core <= 1.7.0.
    Immediate Action: Remove public exposure and force updates across all instances.
    Mitigation: Apply the fixed version and audit admin accounts.
  • CVE-2026-105484: TOTOLINK X6000R command injection
    Impact: Remote attackers can execute OS commands through firmware upload handling.
    Affected Systems: TOTOLINK X6000R 9.4.0cu.652_B20230116.
    Immediate Action: Isolate affected routers from the internet now.
    Mitigation: Replace or update firmware; restrict management access to trusted networks only.
  • CVE-2026-39759: Workreap Core arbitrary file upload
    Impact: File upload abuse may allow code execution or data theft.
    Affected Systems: Workreap Core <= 3.4.5.
    Immediate Action: Patch immediately and inspect recent uploads.
    Mitigation: Upgrade and enforce file type/size restrictions.
  • CVE-2026-39755: WP Duplicate arbitrary file upload
    Impact: Unauthenticated attackers can upload malicious files.
    Affected Systems: WP Duplicate <= 1.1.11.
    Immediate Action: Disable or update the plugin now.
    Mitigation: Apply the vendor patch and review upload permissions.
  • CVE-2026-105778: Tenda AC5 stack-based buffer overflow
    Impact: Remote attackers may crash or potentially control the device.
    Affected Systems: Tenda AC5 02.03.01.111_multi.
    Immediate Action: Remove from public exposure and update firmware.
    Mitigation: Segment the device and block WAN management.
  • CVE-2026-39757: Taskbot arbitrary file upload
    Impact: Malicious file upload can lead to full site compromise.
    Affected Systems: Taskbot <= 6.6.
    Immediate Action: Patch immediately.
    Mitigation: Disable upload features until fixed.
  • CVE-2026-32568: WooCommerce Designer Pro RCE
    Impact: Subscriber-level attackers can execute code on the server.
    Affected Systems: WooCommerce Designer Pro <= 1.9.33.
    Immediate Action: Update or disable the plugin immediately.
    Mitigation: Restrict subscriber access and review for compromise.
  • CVE-2026-94293: Asset Administration Shell data modification and disclosure
    Impact: Unauthenticated attackers can change submodel data and read exposed data.
    Affected Systems: AAS implementations exposing the vulnerable PATCH/GET endpoints.
    Immediate Action: Restrict network access to the API now.
    Mitigation: Patch and add authentication/authorization checks.
  • CVE-2026-39761: Meta Box AIO privilege escalation
    Impact: Attackers can gain elevated privileges without authorization.
    Affected Systems: Meta Box AIO <= 3.7.1.
    Immediate Action: Update immediately.
    Mitigation: Review roles and administrator accounts.
  • CVE-2026-39797: GDPR Framework PHP object injection
    Impact: Object injection can lead to code execution or data compromise.
    Affected Systems: GDPR Framework By Data443 <= 2.5.0.
    Immediate Action: Patch now and inspect logs for suspicious payloads.
    Mitigation: Upgrade and disable unsafe deserialization paths.
  • CVE-2026-104846: seroval thenable-assimilation bypass
    Impact: Deserialized promises can trigger unintended callable execution inside the host process.
    Affected Systems: seroval 0.12.0 through 1.6.0.
    Immediate Action: Upgrade immediately and stop deserializing untrusted JSON.
    Mitigation: Apply the upstream fix and retest plugin-capable paths.
  • CVE-2026-105763: Twenty CRM credential exposure
    Impact: Workspace members can read other users’ IMAP, SMTP, and CalDAV passwords.
    Affected Systems: Twenty 1.20.10 through 2.7.0.
    Immediate Action: Upgrade and rotate exposed credentials now.
    Mitigation: Patch to 2.7.0 and review account visibility settings.
  • CVE-2026-32557: WooCommerce Appointments SQL injection
    Impact: Remote attackers can read or modify database content.
    Affected Systems: WooCommerce Appointments <= 5.3.2.
    Immediate Action: Patch immediately and review database activity.
    Mitigation: Apply vendor update; add query monitoring.
  • CVE-2026-41555: Newsletter Subscription Form SQL injection
    Impact: Database compromise via unauthenticated injection.
    Affected Systems: Newsletter Subscription Form <= 1.5.9.
    Immediate Action: Update now and block public form abuse.
    Mitigation: Patch and inspect for dumped data.
  • CVE-2026-42417: ARMember Premium SQL injection
    Impact: Attackers can extract or alter data through SQL injection.
    Affected Systems: ARMember Premium <= 7.8.
    Immediate Action: Upgrade immediately.
    Mitigation: Restrict access and validate all inputs.
  • CVE-2026-39795: SendPress Newsletters SQL injection
    Impact: Unauthenticated database compromise is possible.
    Affected Systems: SendPress Newsletters <= 1.26.1.20.
    Immediate Action: Patch now.
    Mitigation: Rotate database credentials if exposed.
  • CVE-2026-39785: Gmedia Photo Gallery SQL injection
    Impact: Attackers can query or modify backend data.
    Affected Systems: Gmedia Photo Gallery <= 1.25.1.
    Immediate Action: Update immediately.
    Mitigation: Add WAF rules for SQLi patterns.
  • CVE-2026-42415: Porto Theme functionality SQL injection
    Impact: Database compromise from unauthenticated requests.
    Affected Systems: Porto Theme - Functionality <= 3.9.3.
    Immediate Action: Patch now.
    Mitigation: Review logs for injection attempts.
  • CVE-2026-39746: Booknetic SQL injection
    Impact: Attackers can access or alter sensitive booking data.
    Affected Systems: Booknetic <= 4.8.5.
    Immediate Action: Upgrade immediately.
    Mitigation: Block vulnerable endpoints until fixed.
  • CVE-2026-39764: Radius Booking SQL injection
    Impact: Remote database compromise is possible.
    Affected Systems: Radius Booking <= 1.0.19.
    Immediate Action: Patch and monitor database access.
    Mitigation: Apply vendor update and review credentials.
  • CVE-2026-90711: proxy-addr trust-subnet bypass
    Impact: Attackers can spoof client IPs and bypass IP-based controls.
    Affected Systems: npm proxy-addr in Express-style deployments using malformed IPv4-mapped IPv6 trust ranges.
    Immediate Action: Audit trust proxy settings now.
    Mitigation: Upgrade to 2.0.8 and use plain IPv4 notation or full mapped prefixes.
  • CVE-2026-39774: Tourfic Pro privilege escalation
    Impact: Unauthenticated attackers can gain higher privileges.
    Affected Systems: Tourfic Pro <= 1.17.3.
    Immediate Action: Update immediately.
    Mitigation: Review administrator and shop-manager accounts.
  • CVE-2026-39793: Simple JWT Login broken authentication
    Impact: Authentication controls can be bypassed.
    Affected Systems: Simple JWT Login 4.0.0.
    Immediate Action: Disable or patch the plugin now.
    Mitigation: Rotate tokens and review login logs.
  • CVE-2026-39725: Content Visibility for Divi Builder RCE
    Impact: Contributor-level users can execute code.
    Affected Systems: Content Visibility for Divi Builder <= 5.03.
    Immediate Action: Patch immediately and limit contributor access.
    Mitigation: Remove the plugin if not required.
  • CVE-2026-105070: Salon booking system privilege escalation
    Impact: Remote attackers can escalate privileges.
    Affected Systems: Salon booking system <= 10.31.7.
    Immediate Action: Update now.
    Mitigation: Audit roles and permissions.
  • CVE-2026-105701: ACPT Premium RCE via Twig rendering
    Impact: Subscriber-level attackers can execute server-side code.
    Affected Systems: ACPT Premium <= 2.0.66.
    Immediate Action: Disable REST form creation and patch immediately.
    Mitigation: Upgrade and verify no malicious forms exist.
  • CVE-2026-39775: JobZilla privilege escalation
    Impact: Subscribers can gain elevated privileges.
    Affected Systems: JobZilla <= 2.2.
    Immediate Action: Patch now.
    Mitigation: Review user roles and recent changes.
  • CVE-2026-105058: WP User Profiles privilege escalation
    Impact: Users can escalate privileges.
    Affected Systems: WP User Profiles <= 2.7.3.
    Immediate Action: Update immediately.
    Mitigation: Recheck role mappings.
  • CVE-2026-100723: vm2 zlib host-buffer isolation bypass
    Impact: Sandbox code can read and modify neighboring host memory when zlib is allowlisted, breaking isolation boundaries.
    Affected Systems: npm vm2 3.11.8 / tested revision 91034466bfb7f56b95fd48083ec6ca36d058f164 when NodeVM exposes zlib.
    Immediate Action: Remove zlib from builtin allowlists or stop using vm2 for untrusted code until patched.
    Mitigation: Apply an owned-copy fix for returned Buffers and add regression tests for pooled-buffer exposure.
  • CVE-2026-100722: vm2 construct-path rejected Promise crash
    Impact: Untrusted sandbox code can crash the host process by returning a rejected native Promise through a constructable host function.
    Affected Systems: npm vm2 3.11.8 / revision 91034466bfb7f56b95fd48083ec6ca36d058f164 under strict unhandled-rejection handling.
    Immediate Action: Stop exposing constructable host APIs to sandboxed code and upgrade vm2 immediately.
    Mitigation: Mark host Promises handled in the construct path and add crash-regression tests.
  • CVE-2026-102827: simple-git unsafe flag bypass
    Impact: Attackers can bypass command-safety checks and execute injected git options in push flows.
    Affected Systems: npm simple-git.
    Immediate Action: Stop passing attacker-controlled git args into push workflows.
    Mitigation: Canonicalize abbreviations before matching and upgrade when fixed.
  • CVE-2026-102826: simple-git clone config-injection RCE
    Impact: Attacker-controlled git config can trigger arbitrary command execution during clone.
    Affected Systems: npm simple-git 3.36.0 and related pending fix surface.
    Immediate Action: Remove attacker influence over customArgs and git.env() now.
    Mitigation: Reject unsafe config flags or upgrade to the patched release.
  • CVE-2026-105783: Joplin Web Clipper token theft
    Impact: A malicious website can steal the permanent API token and gain ongoing note access.
    Affected Systems: Joplin Desktop <= 3.7.12 with Web Clipper enabled.
    Immediate Action: Disable the Web Clipper server or update immediately.
    Mitigation: Patch to 3.7.13 and revoke exposed tokens.
  • CVE-2026-39776: Tabs editor RCE
    Impact: Editor access can lead to server-side code execution.
    Affected Systems: Tabs <= 2.5.
    Immediate Action: Patch now.
    Mitigation: Restrict editor roles until updated.
  • CVE-2026-105782: Scrapy Referrer-Policy import execution
    Impact: Malicious pages can cause a crawler to import and execute a callable such as sys.exit, creating a denial of service.
    Affected Systems: Scrapy 1.4.0 through 2.14.1.
    Immediate Action: Upgrade crawlers immediately.
    Mitigation: Patch to 2.14.2 and sanitize response headers.
  • CVE-2026-39723: Morning for WooCommerce broken access control
    Impact: Unauthenticated attackers can reach restricted actions.
    Affected Systems: Morning for WooCommerce <= 2.4.1.
    Immediate Action: Patch now.
    Mitigation: Review access rules and endpoints.
  • CVE-2026-39794: WooCommerce Multivendor Marketplace REST API access control bypass
    Impact: Attackers can abuse REST endpoints without proper authorization.
    Affected Systems: WooCommerce Multivendor Marketplace – REST API <= 1.6.3.
    Immediate Action: Disable public API access until patched.
    Mitigation: Update and audit API permissions.
  • CVE-2026-105071: SiteVault sensitive data exposure
    Impact: Backup, restore, migration, or cloning data may be exposed.
    Affected Systems: SiteVault <= 1.5.17.
    Immediate Action: Patch and rotate any exposed secrets.
    Mitigation: Restrict backup artifacts and access controls.
  • CVE-2026-32580: WooCommerce Lottery SQL injection
    Impact: Remote attackers can manipulate backend data.
    Affected Systems: WooCommerce Lottery <= 2.2.9.
    Immediate Action: Patch immediately.
    Mitigation: Monitor database queries for anomalies.
  • CVE-2026-39751: PayPlug for WooCommerce broken access control
    Impact: Unauthorized users can reach restricted functionality.
    Affected Systems: PayPlug for WooCommerce (Official) <= 3.1.0.
    Immediate Action: Update now.
    Mitigation: Verify merchant and admin permissions.
  • CVE-2026-41559: SafeSnap sensitive data exposure
    Impact: Backup and restore data may be exposed to unauthorized users.
    Affected Systems: SafeSnap <= 2.1.2.
    Immediate Action: Patch immediately.
    Mitigation: Restrict access to backup endpoints.
  • CVE-2026-41561: Museder RestoreOne sensitive data exposure
    Impact: Sensitive restore data can be exposed.
    Affected Systems: Museder RestoreOne <= 2.7.276.
    Immediate Action: Update now.
    Mitigation: Lock down restore workflows.
  • CVE-2026-42413: Snapshotify sensitive data exposure
    Impact: Backup and migration data may be disclosed.
    Affected Systems: Snapshotify <= 1.3.2.
    Immediate Action: Patch immediately.
    Mitigation: Restrict access and rotate exposed secrets.
  • CVE-2026-42638: Easy Digital Downloads broken access control
    Impact: Attackers can access restricted application functions.
    Affected Systems: Easy Digital Downloads <= 3.7.1.
    Immediate Action: Patch now.
    Mitigation: Review API and role permissions.
  • CVE-2026-87776: compression zlib memory leak DoS
    Impact: Repeated client disconnects can exhaust memory and crash services.
    Affected Systems: npm compression < 1.8.2.
    Immediate Action: Upgrade immediately.
    Mitigation: Apply 1.8.2 and watch for aborted compressed responses.
  • CVE-2026-102600: @socket.io/cluster-engine prototype pollution / client lookup flaw
    Impact: Attackers may crash clustered Socket.IO deployments by abusing special session IDs.
    Affected Systems: npm @socket.io/cluster-engine 0.1.0.
    Immediate Action: Upgrade to 0.1.1 now.
    Mitigation: Sanitize session IDs and monitor clustered workers.
  • CVE-2026-104845: seroval typed-array deserialization DoS
    Impact: Tiny payloads can trigger large allocations and event-loop starvation.
    Affected Systems: npm seroval deserializers handling untrusted JSON.
    Immediate Action: Stop accepting untrusted Seroval JSON until patched.
    Mitigation: Upgrade and enforce size limits.
  • CVE-2026-105762: Dify remote file retrieval / SSRF
    Impact: Attackers can pivot into internal services or cloud metadata endpoints.
    Affected Systems: Dify prior to 1.13.0.
    Immediate Action: Patch now and block outbound metadata access.
    Mitigation: Upgrade to 1.13.0 and restrict egress.
  • CVE-2026-104405: GiveWP privilege escalation
    Impact: Attackers can gain elevated privileges.
    Affected Systems: GiveWP <= 4.17.0.
    Immediate Action: Update immediately.
    Mitigation: Review roles and admin sessions.

Note: The remaining high-volume WordPress XSS and SQL injection findings in today’s set should be treated as urgent exposure items even when they are “only” XSS; in admin or authenticated contexts they often become account takeover or stored payload delivery. Patch every affected plugin/theme listed below without delay.

  • Additional critical/high-risk items to patch today: CVE-2026-39747, CVE-2026-39771, CVE-2026-25434, CVE-2026-42414, CVE-2026-105317, CVE-2026-96749, CVE-2026-105762, CVE-2026-104757, CVE-2026-75962, CVE-2026-48197, CVE-2026-39765, CVE-2026-104672, CVE-2026-105761, CVE-2026-32574, CVE-2026-39724, CVE-2026-39745, CVE-2026-104394, CVE-2026-39778, CVE-2026-39781, CVE-2026-39726, CVE-2026-40807, CVE-2026-39720, CVE-2026-42634, CVE-2026-32581, CVE-2026-32577, CVE-2026-39760, CVE-2026-32569, CVE-2026-42636, CVE-2026-103346, CVE-2026-25302, CVE-2026-104395, CVE-2026-104670, CVE-2026-42635, CVE-2026-39790, CVE-2026-32570, CVE-2026-32572, CVE-2026-32578, CVE-2026-39722, CVE-2026-39731, CVE-2026-39750, CVE-2026-39748, CVE-2026-39758, CVE-2026-39784, CVE-2026-39768, CVE-2026-39766, CVE-2026-39780, CVE-2026-32575, CVE-2026-40806, CVE-2026-105061, CVE-2026-42418, CVE-2026-94675, CVE-2026-104814.

Previously Alerted

What to Do Now

  1. Patch or disable exposed products today. Prioritize internet-facing WordPress plugins/themes, network appliances, and any service that accepts uploads, authentication, or custom arguments.
  2. Remove risky features temporarily. Disable public upload endpoints, sandbox allowlists like zlib, unsafe git custom arguments, and exposed clipper/API servers until fixed.
  3. Verify versions and exposure. Confirm every instance against the affected ranges and inventory all plugins, containers, and developer libraries.
  4. Rotate credentials and tokens if exposure is possible. This includes database credentials, API tokens, SMTP/IMAP secrets, and admin sessions.
  5. Review logs for abuse. Look for file uploads, SQL error bursts, unexpected outbound requests, command-injection markers, and process crashes.

Verification steps: run a full software inventory, compare installed versions to the affected ranges above, and test whether public endpoints are still reachable. Validate that patched services reject unauthenticated uploads, block unsafe config flags, and no longer expose sensitive data or host memory.

Monitoring recommendations: alert on new files in upload directories, unusual child processes from web workers, repeated 4xx/5xx spikes on admin routes, unexpected outbound DNS/HTTP requests, and Node process exits tied to unhandled rejections or memory growth.

Related Resources

  • Internal: A follow-up blog post on today’s WordPress plugin exposure patterns is planned.
  • Internal: A technical note on sandbox isolation failures and host-builtin hardening is planned.
  • Official advisories: Review vendor release notes and security advisories for each product listed above; prioritize npm package advisories, WordPress plugin changelogs, and device firmware bulletins.

Keep reading