Security Digest: October 10, 2026 - 61 Critical Vulnerabilities

Today’s threat picture is severe: 61 critical and high-severity vulnerabilities span WordPress plugins, authentication bypasses, remote code execution, file upload, SQL injection, and widespread stored XSS. Several issues allow unauthenticated site takeover or server-side code execution, especially where vulnerable plugins are public-facing and widely deployed.

· 25 min read

Executive Summary

Today’s threat picture is severe: 61 critical and high-severity vulnerabilities span WordPress plugins, authentication bypasses, remote code execution, file upload, SQL injection, and widespread stored XSS. Several issues allow unauthenticated site takeover or server-side code execution, especially where vulnerable plugins are public-facing and widely deployed.

Act now: disable or remove exposed vulnerable plugins, apply vendor patches immediately, and assume compromise if any of the authentication-bypass or remote-code-execution flaws are present on internet-facing sites.

Critical Vulnerabilities

Note: The following list is grouped for speed. Many of today’s issues affect WordPress plugins and require urgent patching or temporary deactivation if updates are not yet available.

  • CVE-2026-93927: Axiomthemes Veto object injection
    Impact: Possible object injection and code execution.
    Affected Systems: Veto through 1.6.0.
    Immediate Action: Remove or disable the plugin until patched.
    Mitigation: Update as soon as the vendor releases a fixed version.
  • CVE-2026-93945: Axiomthemes Balance object injection
    Impact: Possible object injection and code execution.
    Affected Systems: Balance through 1.12.0.
    Immediate Action: Disable the plugin on exposed sites.
    Mitigation: Patch immediately when available.
  • CVE-2026-93933: ThemeREX Rosalinda object injection
    Impact: Potential full compromise through unsafe deserialization.
    Affected Systems: Rosalinda through 1.2.4.
    Immediate Action: Remove from production if not essential.
    Mitigation: Upgrade to a fixed release.
  • CVE-2026-93936: ThemeREX IPharm object injection
    Impact: Object injection may lead to code execution.
    Affected Systems: IPharm through 1.2.4.
    Immediate Action: Disable until patched.
    Mitigation: Apply vendor update.
  • CVE-2026-93940: ThemeREX Greeny object injection
    Impact: Potential remote compromise.
    Affected Systems: Greeny through 2.10.0.
    Immediate Action: Treat as high risk and remove if unused.
    Mitigation: Patch immediately.
  • CVE-2026-93931: ThemeREX Smash object injection
    Impact: Unsafe deserialization can enable takeover.
    Affected Systems: Smash through 1.12.0.
    Immediate Action: Disable public exposure where possible.
    Mitigation: Update to fixed version.
  • CVE-2026-93934: ThemeREX Partiso object injection
    Impact: Object injection risk.
    Affected Systems: Partiso through 1.1.13.
    Immediate Action: Remove or patch now.
    Mitigation: Vendor fix required.
  • CVE-2026-93943: ThemeREX Convex object injection
    Impact: Potential code execution via deserialization.
    Affected Systems: Convex through 1.16.0.
    Immediate Action: Disable until updated.
    Mitigation: Upgrade immediately.
  • CVE-2026-93944: ThemeREX Camelia object injection
    Impact: Unsafe deserialization risk.
    Affected Systems: Camelia through 1.2.15.
    Immediate Action: Take offline if not needed.
    Mitigation: Patch as soon as released.
  • CVE-2026-93937: ThemeREX Hygia object injection
    Impact: Possible full site compromise.
    Affected Systems: Hygia through 1.21.0.
    Immediate Action: Disable plugin on production sites.
    Mitigation: Update to fixed build.
  • CVE-2026-93929: ThemeREX Travesia object injection
    Impact: Unsafe deserialization can lead to RCE.
    Affected Systems: Travesia through 1.1.16.
    Immediate Action: Remove from internet-facing sites.
    Mitigation: Patch immediately.
  • CVE-2026-93932: ThemeREX Smart Casa object injection
    Impact: Possible object injection and takeover.
    Affected Systems: Smart Casa through 1.0.12.
    Immediate Action: Disable now if present.
    Mitigation: Apply vendor update.
  • CVE-2026-104732: Advanced IP Blocker authentication bypass
    Impact: Unauthenticated attackers can bypass 2FA and log in as administrators.
    Affected Systems: Advanced IP Blocker through 8.13.13.
    Immediate Action: Disable the plugin or remove 2FA reliance until patched.
    Mitigation: Update immediately; review admin logins and rotate credentials.
  • CVE-2026-94589: Extensions For CF7 arbitrary file upload
    Impact: Unauthenticated attackers may upload executable files and gain RCE.
    Affected Systems: Extensions For CF7 through 3.4.5.
    Immediate Action: Disable file upload functionality or the plugin entirely.
    Mitigation: Patch and restrict uploads at the web server.
  • CVE-2026-103889: 3D Product configurator for WooCommerce RCE
    Impact: Unauthenticated code execution on the server.
    Affected Systems: 3D Product configurator through 2.16.2.
    Immediate Action: Take the endpoint offline or disable the plugin.
    Mitigation: Upgrade immediately and validate no abuse occurred.
  • CVE-2026-93935: ThemeREX Let’s Play object injection
    Impact: Potential code execution.
    Affected Systems: Let’s Play through 1.1.15.
    Immediate Action: Disable if installed.
    Mitigation: Patch promptly.
  • CVE-2026-93938: ThemeREX Hogwords object injection
    Impact: Unsafe deserialization risk.
    Affected Systems: Hogwords through 1.2.7.
    Immediate Action: Remove or isolate the plugin.
    Mitigation: Update immediately.
  • CVE-2026-93942: ThemeREX Dwell object injection
    Impact: Potential takeover via object injection.
    Affected Systems: Dwell through 1.16.0.
    Immediate Action: Disable on public sites.
    Mitigation: Patch as soon as possible.
  • CVE-2026-93941: ThemeREX Edema object injection
    Impact: Unsafe deserialization may lead to RCE.
    Affected Systems: Edema through 1.2.2.2.
    Immediate Action: Remove or patch now.
    Mitigation: Vendor update required.
  • CVE-2026-62045: ThemeREX Booklovers object injection
    Impact: Possible code execution.
    Affected Systems: Booklovers through 2.13.0.
    Immediate Action: Disable until fixed.
    Mitigation: Upgrade immediately.
  • CVE-2026-104803: WPCOM Member authentication bypass
    Impact: Attackers can log in as other users, including administrators.
    Affected Systems: WPCOM Member through 1.7.27.
    Immediate Action: Turn off the social-login flow if possible.
    Mitigation: Patch immediately and audit all sessions.
  • CVE-2026-62046: ThemeREX Gutentype object injection
    Impact: Potential remote code execution.
    Affected Systems: Gutentype through 2.1.12.
    Immediate Action: Disable plugin.
    Mitigation: Update to fixed version.
  • CVE-2026-93930: ThemeREX Tantra object injection
    Impact: Unsafe deserialization risk.
    Affected Systems: Tantra through 2.9.0.
    Immediate Action: Remove if exposed publicly.
    Mitigation: Patch as soon as available.
  • CVE-2026-97670: Avada Builder authorization bypass
    Impact: Unauthenticated attackers can trigger dangerous WordPress hooks and destroy content.
    Affected Systems: Avada Builder through 7.16.1.
    Immediate Action: Disable public form submissions where possible.
    Mitigation: Update immediately and review for deleted content.
  • CVE-2026-104801: PPOM arbitrary file deletion
    Impact: Attackers can delete arbitrary files, potentially leading to RCE and data exposure.
    Affected Systems: PPOM through 34.0.10.
    Immediate Action: Remove plugin or block access to file-handling endpoints.
    Mitigation: Patch immediately; verify wp-config.php and uploads integrity.
  • CVE-2026-107645: Blocksy Companion privilege escalation
    Impact: Attackers can create seller accounts and gain elevated access.
    Affected Systems: Blocksy Companion through 2.1.58.
    Immediate Action: Disable vendor-registration integrations until patched.
    Mitigation: Update immediately and review newly created accounts.
  • CVE-2026-104725: Groundhogg privilege escalation
    Impact: Authenticated users can pivot to administrator via contact reassignment and auto-login.
    Affected Systems: Groundhogg through 4.9.
    Immediate Action: Restrict edit_contacts access now.
    Mitigation: Patch and audit contact ownership changes.
  • CVE-2026-77183: FooSales account takeover
    Impact: Low-privilege users can change admin email and reset passwords.
    Affected Systems: FooSales through 1.43.0.
    Immediate Action: Suspend cashier-level access if not required.
    Mitigation: Update immediately and reset impacted passwords.
  • CVE-2026-83526: FV Player file upload race condition
    Impact: Authenticated attackers may upload executable files for RCE.
    Affected Systems: FV Player 8 through 8.1.7.
    Immediate Action: Disable new player creation for non-admins.
    Mitigation: Patch and inspect uploads directory.
  • CVE-2026-104766: LatePoint privilege escalation
    Impact: Agents or custom roles can create new customers as administrators.
    Affected Systems: LatePoint through 5.7.3.
    Immediate Action: Remove settings__edit from non-admin roles now.
    Mitigation: Patch and verify default role settings.
  • CVE-2026-104797: Advanced Form Integration password change abuse
    Impact: Unauthenticated attackers can reset any user password through misconfigured form workflows.
    Affected Systems: Advanced Form Integration through 2.9.0.
    Immediate Action: Disable public form mappings to sensitive fields.
    Mitigation: Patch and review all CF7 integrations.
  • CVE-2026-92975: Groundhogg support-user promotion
    Impact: A matching account can be promoted to admin or super admin.
    Affected Systems: Groundhogg through 4.8.3.
    Immediate Action: Disable support-access features until patched.
    Mitigation: Update and audit privileged user creation.
  • CVE-2026-94538: WP File Download authorization bypass
    Impact: Authenticated users can delete, move, publish, or unpublish files they should not control.
    Affected Systems: WP File Download through 6.3.9.
    Immediate Action: Restrict subscriber-level access where feasible.
    Mitigation: Patch immediately and review file integrity.
  • CVE-2026-104759: WPO365 OIDC nonce replay
    Impact: Replayed ID tokens can authenticate as another user, including admins.
    Affected Systems: WPO365 through 44.1 with use_id_token_parser_v2 enabled.
    Immediate Action: Disable the affected parser option now.
    Mitigation: Patch and invalidate sessions/tokens.
  • CVE-2026-104899: GeoDirectory local file inclusion
    Impact: Unauthenticated attackers may include and execute arbitrary PHP files.
    Affected Systems: GeoDirectory through 2.8.187.
    Immediate Action: Remove public exposure or disable the plugin.
    Mitigation: Patch and rotate credentials if compromise is suspected.
  • CVE-2026-93950: Motors missing authorization
    Impact: Attackers can abuse weak access control and perform unauthorized actions.
    Affected Systems: Motors through 1.4.108.
    Immediate Action: Review access control and disable risky endpoints.
    Mitigation: Update to a secure version.
  • CVE-2026-89301: rtMedia limited file deletion
    Impact: Unauthenticated attackers can delete arbitrary safe files.
    Affected Systems: rtMedia through 4.7.13.
    Immediate Action: Disable public upload features if possible.
    Mitigation: Patch and monitor file deletions.
  • CVE-2026-91136: Divi Plus arbitrary file read
    Impact: Attackers can read arbitrary files and may reach code execution.
    Affected Systems: Divi Plus through 2.4.0.
    Immediate Action: Block the REST endpoint at the edge if possible.
    Mitigation: Upgrade immediately.
  • CVE-2026-93746: WebToffee PDF Invoices IDOR
    Impact: Guest users can access other customers’ invoices and shipping data.
    Affected Systems: WebToffee PDF Invoices through 5.0.2 when guest access is enabled.
    Immediate Action: Turn off guest document access now.
    Mitigation: Patch and review document access logs.
  • CVE-2026-96662: LatePoint SQL injection
    Impact: Attackers can extract sensitive database data.
    Affected Systems: LatePoint through 5.7.2.
    Immediate Action: Restrict exposure of booking endpoints.
    Mitigation: Patch immediately and review database logs.
  • CVE-2026-96840: PostX stored XSS
    Impact: Attackers can run scripts in visitors’ browsers.
    Affected Systems: PostX through 5.1.0.
    Immediate Action: Sanitize user profiles and limit Subscriber registration.
    Mitigation: Patch and clear cached pages.
  • CVE-2026-96765: WPO365 stored XSS
    Impact: Malicious script can execute when an admin visits the wizard page.
    Affected Systems: WPO365 through 44.1.
    Immediate Action: Review and clear plugin error transients.
    Mitigation: Patch immediately.
  • CVE-2026-106606: YITH WooCommerce Affiliates object injection
    Impact: Potential code execution.
    Affected Systems: YITH WooCommerce Affiliates through 3.31.0.
    Immediate Action: Disable if not required.
    Mitigation: Patch immediately.
  • CVE-2026-96278: WP Photo Album Plus stored XSS
    Impact: Browser-based attacks against site visitors.
    Affected Systems: WP Photo Album Plus through 9.3.03.002.
    Immediate Action: Clear any injected session-history content.
    Mitigation: Update and purge caches.
  • CVE-2026-107657: HivePress stored XSS
    Impact: Malicious scripts can run in user profiles.
    Affected Systems: HivePress through 1.7.31.
    Immediate Action: Review custom user attribute templates now.
    Mitigation: Patch and revalidate profile rendering.
  • CVE-2026-104021: Fastcache code injection
    Impact: Admins can be tricked into injecting arbitrary Apache directives, enabling code execution.
    Affected Systems: Fastcache through 1.7.4.
    Immediate Action: Restrict admin access and inspect .htaccess immediately.
    Mitigation: Patch and restore any tampered configuration.
  • CVE-2026-14335: Easy Digital Downloads stored XSS
    Impact: Malicious scripts can execute in storefront or admin views.
    Affected Systems: EDD through 3.6.9.
    Immediate Action: Review PayPal IPN handling and patch now.
    Mitigation: Update and clear affected records.
  • CVE-2026-96667: Real Estate Manager stored XSS
    Impact: Browser script execution on affected pages.
    Affected Systems: Real Estate Manager through 7.3.
    Immediate Action: Block unauthenticated submissions if possible.
    Mitigation: Patch and review form inputs.
  • CVE-2026-96682: Presto Player stored XSS
    Impact: Script execution after comment approval.
    Affected Systems: Presto Player through 4.5.1.
    Immediate Action: Tighten comment moderation now.
    Mitigation: Patch and purge suspicious comments.
  • CVE-2026-93775: Podlove Podcast Publisher stored XSS
    Impact: Malicious payloads can be stored via webhook logs.
    Affected Systems: Podlove Podcast Publisher through 4.5.6.
    Immediate Action: Disable Auphonic webhook exposure if possible.
    Mitigation: Patch and review logs for injected content.
  • CVE-2026-100161: Photo Reviews for WooCommerce stored DOM XSS
    Impact: Attackers can inject scripts into reviews.
    Affected Systems: Photo Reviews for WooCommerce through 1.2.30.
    Immediate Action: Review review-form nonce handling and patch.
    Mitigation: Update and inspect comment meta.
  • CVE-2026-95684: VikBooking stored XSS
    Impact: Browser script execution through attachment names.
    Affected Systems: VikBooking through 1.8.15.
    Immediate Action: Sanitize booking attachments and patch now.
    Mitigation: Upgrade and clear cached pages.
  • CVE-2026-100196: LazyLoad Plugin stored XSS
    Impact: Malicious scripts can execute after comment approval.
    Affected Systems: LazyLoad Plugin through 2.4.0.
    Immediate Action: Review approved comments and patch.
    Mitigation: Update and purge rendered content.
  • CVE-2026-96558: QSM stored DOM XSS
    Impact: Script execution through audit-trail content.
    Affected Systems: QSM through 11.2.6.
    Immediate Action: Inspect audit tables for injected payloads.
    Mitigation: Patch immediately.
  • CVE-2026-107742: 10Web Booster stored XSS
    Impact: Script execution through comment author rendering.
    Affected Systems: 10Web Booster through 2.34.8.
    Immediate Action: Review comment author data and patch.
    Mitigation: Update and clear caches.
  • CVE-2026-96572: WP Meteor stored XSS
    Impact: Malicious script execution after moderation approval.
    Affected Systems: WP Meteor through 3.4.18.
    Immediate Action: Tighten comment moderation and patch.
    Mitigation: Upgrade and monitor for injected comments.
  • CVE-2026-100178: WPAdverts stored XSS
    Impact: Browser script execution on classifieds pages.
    Affected Systems: WPAdverts through 2.3.4.
    Immediate Action: Review ad submission fields immediately.
    Mitigation: Patch and sanitize stored listings.
  • CVE-2026-100147: FunnelKit stored XSS
    Impact: Malicious scripts can execute during checkout or admin review.
    Affected Systems: FunnelKit through 3.16.0.5.
    Immediate Action: Inspect checkout field handling and patch.
    Mitigation: Update and purge cached checkout pages.
  • CVE-2026-101920: Molongui Authorship stored DOM XSS
    Impact: Script execution through rewritten author links.
    Affected Systems: Molongui Authorship through 5.2.12.
    Immediate Action: Review author-box templates now.
    Mitigation: Patch and validate rendered href attributes.
  • CVE-2026-93949: Grocery Shopping Store authentication bypass
    Impact: Password recovery flow can be abused to gain access.
    Affected Systems: Grocery Shopping Store through 1.3.3.
    Immediate Action: Disable password recovery if possible.
    Mitigation: Patch immediately and reset exposed accounts.
  • CVE-2026-93951: Zeinet reflected XSS
    Impact: Attackers can run scripts in victims’ browsers via crafted links.
    Affected Systems: Zeinet through 1.0.0.
    Immediate Action: Block suspicious inbound links and patch.
    Mitigation: Update and sanitize request parameters.

Previously Alerted

What to Do Now

  1. Patch or disable every affected plugin listed above, starting with authentication bypass, file upload, and RCE issues.
  2. Inventory WordPress sites for these plugin names and versions; remove any unused or abandoned plugins immediately.
  3. Assume compromise if any public site had one of the RCE, authentication-bypass, or file-deletion flaws exposed.
  4. Rotate credentials and invalidate sessions for admins and privileged users on affected systems.

Verification steps: confirm installed versions, check for unexpected admin accounts, inspect .htaccess, uploads, logs, and recent file changes, and review authentication events around plugin update windows.

Monitoring recommendations: watch for new admin logins, unusual outbound requests, modified plugin files, webshell indicators, deleted content, and spikes in 4xx/5xx responses on plugin endpoints.

Related Resources

  • Internal blog post: WordPress Plugin Emergency Triage Guide (to be published)
  • Internal blog post: How to Verify Plugin Exposure at Scale (to be published)
  • Official vendor advisories: monitor each plugin vendor’s security page and WordPress.org plugin changelogs for fixed releases.

Keep reading