Security Digest: October 10, 2026 - 61 Critical Vulnerabilities
Today’s threat picture is severe: 61 critical and high-severity vulnerabilities span WordPress plugins, authentication bypasses, remote code execution, file upload, SQL injection, and widespread stored XSS. Several issues allow unauthenticated site takeover or server-side code execution, especially where vulnerable plugins are public-facing and widely deployed.
· 25 min read
Executive Summary
Today’s threat picture is severe: 61 critical and high-severity vulnerabilities span WordPress plugins, authentication bypasses, remote code execution, file upload, SQL injection, and widespread stored XSS. Several issues allow unauthenticated site takeover or server-side code execution, especially where vulnerable plugins are public-facing and widely deployed.
Act now: disable or remove exposed vulnerable plugins, apply vendor patches immediately, and assume compromise if any of the authentication-bypass or remote-code-execution flaws are present on internet-facing sites.
Critical Vulnerabilities
Note: The following list is grouped for speed. Many of today’s issues affect WordPress plugins and require urgent patching or temporary deactivation if updates are not yet available.
- CVE-2026-93927: Axiomthemes Veto object injection
Impact: Possible object injection and code execution.
Affected Systems: Veto through 1.6.0.
Immediate Action: Remove or disable the plugin until patched.
Mitigation: Update as soon as the vendor releases a fixed version. - CVE-2026-93945: Axiomthemes Balance object injection
Impact: Possible object injection and code execution.
Affected Systems: Balance through 1.12.0.
Immediate Action: Disable the plugin on exposed sites.
Mitigation: Patch immediately when available. - CVE-2026-93933: ThemeREX Rosalinda object injection
Impact: Potential full compromise through unsafe deserialization.
Affected Systems: Rosalinda through 1.2.4.
Immediate Action: Remove from production if not essential.
Mitigation: Upgrade to a fixed release. - CVE-2026-93936: ThemeREX IPharm object injection
Impact: Object injection may lead to code execution.
Affected Systems: IPharm through 1.2.4.
Immediate Action: Disable until patched.
Mitigation: Apply vendor update. - CVE-2026-93940: ThemeREX Greeny object injection
Impact: Potential remote compromise.
Affected Systems: Greeny through 2.10.0.
Immediate Action: Treat as high risk and remove if unused.
Mitigation: Patch immediately. - CVE-2026-93931: ThemeREX Smash object injection
Impact: Unsafe deserialization can enable takeover.
Affected Systems: Smash through 1.12.0.
Immediate Action: Disable public exposure where possible.
Mitigation: Update to fixed version. - CVE-2026-93934: ThemeREX Partiso object injection
Impact: Object injection risk.
Affected Systems: Partiso through 1.1.13.
Immediate Action: Remove or patch now.
Mitigation: Vendor fix required. - CVE-2026-93943: ThemeREX Convex object injection
Impact: Potential code execution via deserialization.
Affected Systems: Convex through 1.16.0.
Immediate Action: Disable until updated.
Mitigation: Upgrade immediately. - CVE-2026-93944: ThemeREX Camelia object injection
Impact: Unsafe deserialization risk.
Affected Systems: Camelia through 1.2.15.
Immediate Action: Take offline if not needed.
Mitigation: Patch as soon as released. - CVE-2026-93937: ThemeREX Hygia object injection
Impact: Possible full site compromise.
Affected Systems: Hygia through 1.21.0.
Immediate Action: Disable plugin on production sites.
Mitigation: Update to fixed build. - CVE-2026-93929: ThemeREX Travesia object injection
Impact: Unsafe deserialization can lead to RCE.
Affected Systems: Travesia through 1.1.16.
Immediate Action: Remove from internet-facing sites.
Mitigation: Patch immediately. - CVE-2026-93932: ThemeREX Smart Casa object injection
Impact: Possible object injection and takeover.
Affected Systems: Smart Casa through 1.0.12.
Immediate Action: Disable now if present.
Mitigation: Apply vendor update. - CVE-2026-104732: Advanced IP Blocker authentication bypass
Impact: Unauthenticated attackers can bypass 2FA and log in as administrators.
Affected Systems: Advanced IP Blocker through 8.13.13.
Immediate Action: Disable the plugin or remove 2FA reliance until patched.
Mitigation: Update immediately; review admin logins and rotate credentials. - CVE-2026-94589: Extensions For CF7 arbitrary file upload
Impact: Unauthenticated attackers may upload executable files and gain RCE.
Affected Systems: Extensions For CF7 through 3.4.5.
Immediate Action: Disable file upload functionality or the plugin entirely.
Mitigation: Patch and restrict uploads at the web server. - CVE-2026-103889: 3D Product configurator for WooCommerce RCE
Impact: Unauthenticated code execution on the server.
Affected Systems: 3D Product configurator through 2.16.2.
Immediate Action: Take the endpoint offline or disable the plugin.
Mitigation: Upgrade immediately and validate no abuse occurred. - CVE-2026-93935: ThemeREX Let’s Play object injection
Impact: Potential code execution.
Affected Systems: Let’s Play through 1.1.15.
Immediate Action: Disable if installed.
Mitigation: Patch promptly. - CVE-2026-93938: ThemeREX Hogwords object injection
Impact: Unsafe deserialization risk.
Affected Systems: Hogwords through 1.2.7.
Immediate Action: Remove or isolate the plugin.
Mitigation: Update immediately. - CVE-2026-93942: ThemeREX Dwell object injection
Impact: Potential takeover via object injection.
Affected Systems: Dwell through 1.16.0.
Immediate Action: Disable on public sites.
Mitigation: Patch as soon as possible. - CVE-2026-93941: ThemeREX Edema object injection
Impact: Unsafe deserialization may lead to RCE.
Affected Systems: Edema through 1.2.2.2.
Immediate Action: Remove or patch now.
Mitigation: Vendor update required. - CVE-2026-62045: ThemeREX Booklovers object injection
Impact: Possible code execution.
Affected Systems: Booklovers through 2.13.0.
Immediate Action: Disable until fixed.
Mitigation: Upgrade immediately. - CVE-2026-104803: WPCOM Member authentication bypass
Impact: Attackers can log in as other users, including administrators.
Affected Systems: WPCOM Member through 1.7.27.
Immediate Action: Turn off the social-login flow if possible.
Mitigation: Patch immediately and audit all sessions. - CVE-2026-62046: ThemeREX Gutentype object injection
Impact: Potential remote code execution.
Affected Systems: Gutentype through 2.1.12.
Immediate Action: Disable plugin.
Mitigation: Update to fixed version. - CVE-2026-93930: ThemeREX Tantra object injection
Impact: Unsafe deserialization risk.
Affected Systems: Tantra through 2.9.0.
Immediate Action: Remove if exposed publicly.
Mitigation: Patch as soon as available. - CVE-2026-97670: Avada Builder authorization bypass
Impact: Unauthenticated attackers can trigger dangerous WordPress hooks and destroy content.
Affected Systems: Avada Builder through 7.16.1.
Immediate Action: Disable public form submissions where possible.
Mitigation: Update immediately and review for deleted content. - CVE-2026-104801: PPOM arbitrary file deletion
Impact: Attackers can delete arbitrary files, potentially leading to RCE and data exposure.
Affected Systems: PPOM through 34.0.10.
Immediate Action: Remove plugin or block access to file-handling endpoints.
Mitigation: Patch immediately; verify wp-config.php and uploads integrity. - CVE-2026-107645: Blocksy Companion privilege escalation
Impact: Attackers can create seller accounts and gain elevated access.
Affected Systems: Blocksy Companion through 2.1.58.
Immediate Action: Disable vendor-registration integrations until patched.
Mitigation: Update immediately and review newly created accounts. - CVE-2026-104725: Groundhogg privilege escalation
Impact: Authenticated users can pivot to administrator via contact reassignment and auto-login.
Affected Systems: Groundhogg through 4.9.
Immediate Action: Restrict edit_contacts access now.
Mitigation: Patch and audit contact ownership changes. - CVE-2026-77183: FooSales account takeover
Impact: Low-privilege users can change admin email and reset passwords.
Affected Systems: FooSales through 1.43.0.
Immediate Action: Suspend cashier-level access if not required.
Mitigation: Update immediately and reset impacted passwords. - CVE-2026-83526: FV Player file upload race condition
Impact: Authenticated attackers may upload executable files for RCE.
Affected Systems: FV Player 8 through 8.1.7.
Immediate Action: Disable new player creation for non-admins.
Mitigation: Patch and inspect uploads directory. - CVE-2026-104766: LatePoint privilege escalation
Impact: Agents or custom roles can create new customers as administrators.
Affected Systems: LatePoint through 5.7.3.
Immediate Action: Remove settings__edit from non-admin roles now.
Mitigation: Patch and verify default role settings. - CVE-2026-104797: Advanced Form Integration password change abuse
Impact: Unauthenticated attackers can reset any user password through misconfigured form workflows.
Affected Systems: Advanced Form Integration through 2.9.0.
Immediate Action: Disable public form mappings to sensitive fields.
Mitigation: Patch and review all CF7 integrations. - CVE-2026-92975: Groundhogg support-user promotion
Impact: A matching account can be promoted to admin or super admin.
Affected Systems: Groundhogg through 4.8.3.
Immediate Action: Disable support-access features until patched.
Mitigation: Update and audit privileged user creation. - CVE-2026-94538: WP File Download authorization bypass
Impact: Authenticated users can delete, move, publish, or unpublish files they should not control.
Affected Systems: WP File Download through 6.3.9.
Immediate Action: Restrict subscriber-level access where feasible.
Mitigation: Patch immediately and review file integrity. - CVE-2026-104759: WPO365 OIDC nonce replay
Impact: Replayed ID tokens can authenticate as another user, including admins.
Affected Systems: WPO365 through 44.1 withuse_id_token_parser_v2enabled.
Immediate Action: Disable the affected parser option now.
Mitigation: Patch and invalidate sessions/tokens. - CVE-2026-104899: GeoDirectory local file inclusion
Impact: Unauthenticated attackers may include and execute arbitrary PHP files.
Affected Systems: GeoDirectory through 2.8.187.
Immediate Action: Remove public exposure or disable the plugin.
Mitigation: Patch and rotate credentials if compromise is suspected. - CVE-2026-93950: Motors missing authorization
Impact: Attackers can abuse weak access control and perform unauthorized actions.
Affected Systems: Motors through 1.4.108.
Immediate Action: Review access control and disable risky endpoints.
Mitigation: Update to a secure version. - CVE-2026-89301: rtMedia limited file deletion
Impact: Unauthenticated attackers can delete arbitrary safe files.
Affected Systems: rtMedia through 4.7.13.
Immediate Action: Disable public upload features if possible.
Mitigation: Patch and monitor file deletions. - CVE-2026-91136: Divi Plus arbitrary file read
Impact: Attackers can read arbitrary files and may reach code execution.
Affected Systems: Divi Plus through 2.4.0.
Immediate Action: Block the REST endpoint at the edge if possible.
Mitigation: Upgrade immediately. - CVE-2026-93746: WebToffee PDF Invoices IDOR
Impact: Guest users can access other customers’ invoices and shipping data.
Affected Systems: WebToffee PDF Invoices through 5.0.2 when guest access is enabled.
Immediate Action: Turn off guest document access now.
Mitigation: Patch and review document access logs. - CVE-2026-96662: LatePoint SQL injection
Impact: Attackers can extract sensitive database data.
Affected Systems: LatePoint through 5.7.2.
Immediate Action: Restrict exposure of booking endpoints.
Mitigation: Patch immediately and review database logs. - CVE-2026-96840: PostX stored XSS
Impact: Attackers can run scripts in visitors’ browsers.
Affected Systems: PostX through 5.1.0.
Immediate Action: Sanitize user profiles and limit Subscriber registration.
Mitigation: Patch and clear cached pages. - CVE-2026-96765: WPO365 stored XSS
Impact: Malicious script can execute when an admin visits the wizard page.
Affected Systems: WPO365 through 44.1.
Immediate Action: Review and clear plugin error transients.
Mitigation: Patch immediately. - CVE-2026-106606: YITH WooCommerce Affiliates object injection
Impact: Potential code execution.
Affected Systems: YITH WooCommerce Affiliates through 3.31.0.
Immediate Action: Disable if not required.
Mitigation: Patch immediately. - CVE-2026-96278: WP Photo Album Plus stored XSS
Impact: Browser-based attacks against site visitors.
Affected Systems: WP Photo Album Plus through 9.3.03.002.
Immediate Action: Clear any injected session-history content.
Mitigation: Update and purge caches. - CVE-2026-107657: HivePress stored XSS
Impact: Malicious scripts can run in user profiles.
Affected Systems: HivePress through 1.7.31.
Immediate Action: Review custom user attribute templates now.
Mitigation: Patch and revalidate profile rendering. - CVE-2026-104021: Fastcache code injection
Impact: Admins can be tricked into injecting arbitrary Apache directives, enabling code execution.
Affected Systems: Fastcache through 1.7.4.
Immediate Action: Restrict admin access and inspect.htaccessimmediately.
Mitigation: Patch and restore any tampered configuration. - CVE-2026-14335: Easy Digital Downloads stored XSS
Impact: Malicious scripts can execute in storefront or admin views.
Affected Systems: EDD through 3.6.9.
Immediate Action: Review PayPal IPN handling and patch now.
Mitigation: Update and clear affected records. - CVE-2026-96667: Real Estate Manager stored XSS
Impact: Browser script execution on affected pages.
Affected Systems: Real Estate Manager through 7.3.
Immediate Action: Block unauthenticated submissions if possible.
Mitigation: Patch and review form inputs. - CVE-2026-96682: Presto Player stored XSS
Impact: Script execution after comment approval.
Affected Systems: Presto Player through 4.5.1.
Immediate Action: Tighten comment moderation now.
Mitigation: Patch and purge suspicious comments. - CVE-2026-93775: Podlove Podcast Publisher stored XSS
Impact: Malicious payloads can be stored via webhook logs.
Affected Systems: Podlove Podcast Publisher through 4.5.6.
Immediate Action: Disable Auphonic webhook exposure if possible.
Mitigation: Patch and review logs for injected content. - CVE-2026-100161: Photo Reviews for WooCommerce stored DOM XSS
Impact: Attackers can inject scripts into reviews.
Affected Systems: Photo Reviews for WooCommerce through 1.2.30.
Immediate Action: Review review-form nonce handling and patch.
Mitigation: Update and inspect comment meta. - CVE-2026-95684: VikBooking stored XSS
Impact: Browser script execution through attachment names.
Affected Systems: VikBooking through 1.8.15.
Immediate Action: Sanitize booking attachments and patch now.
Mitigation: Upgrade and clear cached pages. - CVE-2026-100196: LazyLoad Plugin stored XSS
Impact: Malicious scripts can execute after comment approval.
Affected Systems: LazyLoad Plugin through 2.4.0.
Immediate Action: Review approved comments and patch.
Mitigation: Update and purge rendered content. - CVE-2026-96558: QSM stored DOM XSS
Impact: Script execution through audit-trail content.
Affected Systems: QSM through 11.2.6.
Immediate Action: Inspect audit tables for injected payloads.
Mitigation: Patch immediately. - CVE-2026-107742: 10Web Booster stored XSS
Impact: Script execution through comment author rendering.
Affected Systems: 10Web Booster through 2.34.8.
Immediate Action: Review comment author data and patch.
Mitigation: Update and clear caches. - CVE-2026-96572: WP Meteor stored XSS
Impact: Malicious script execution after moderation approval.
Affected Systems: WP Meteor through 3.4.18.
Immediate Action: Tighten comment moderation and patch.
Mitigation: Upgrade and monitor for injected comments. - CVE-2026-100178: WPAdverts stored XSS
Impact: Browser script execution on classifieds pages.
Affected Systems: WPAdverts through 2.3.4.
Immediate Action: Review ad submission fields immediately.
Mitigation: Patch and sanitize stored listings. - CVE-2026-100147: FunnelKit stored XSS
Impact: Malicious scripts can execute during checkout or admin review.
Affected Systems: FunnelKit through 3.16.0.5.
Immediate Action: Inspect checkout field handling and patch.
Mitigation: Update and purge cached checkout pages. - CVE-2026-101920: Molongui Authorship stored DOM XSS
Impact: Script execution through rewritten author links.
Affected Systems: Molongui Authorship through 5.2.12.
Immediate Action: Review author-box templates now.
Mitigation: Patch and validate rendered href attributes. - CVE-2026-93949: Grocery Shopping Store authentication bypass
Impact: Password recovery flow can be abused to gain access.
Affected Systems: Grocery Shopping Store through 1.3.3.
Immediate Action: Disable password recovery if possible.
Mitigation: Patch immediately and reset exposed accounts. - CVE-2026-93951: Zeinet reflected XSS
Impact: Attackers can run scripts in victims’ browsers via crafted links.
Affected Systems: Zeinet through 1.0.0.
Immediate Action: Block suspicious inbound links and patch.
Mitigation: Update and sanitize request parameters.
Previously Alerted
- CVE-2026-108474: CVE-2026-108474 Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch or disable every affected plugin listed above, starting with authentication bypass, file upload, and RCE issues.
- Inventory WordPress sites for these plugin names and versions; remove any unused or abandoned plugins immediately.
- Assume compromise if any public site had one of the RCE, authentication-bypass, or file-deletion flaws exposed.
- Rotate credentials and invalidate sessions for admins and privileged users on affected systems.
Verification steps: confirm installed versions, check for unexpected admin accounts, inspect .htaccess, uploads, logs, and recent file changes, and review authentication events around plugin update windows.
Monitoring recommendations: watch for new admin logins, unusual outbound requests, modified plugin files, webshell indicators, deleted content, and spikes in 4xx/5xx responses on plugin endpoints.
Related Resources
- Internal blog post: WordPress Plugin Emergency Triage Guide (to be published)
- Internal blog post: How to Verify Plugin Exposure at Scale (to be published)
- Official vendor advisories: monitor each plugin vendor’s security page and WordPress.org plugin changelogs for fixed releases.