Updated CVEs

IDDescriptionSeverityUpdated
CVE-2026-96838Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.
high
2026-09-30
CVE-2026-96837Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
high
2026-09-30
CVE-2026-96836Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.
high
2026-09-30
CVE-2026-96835Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.
medium
2026-09-30
CVE-2026-96834Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
medium
2026-09-30
CVE-2026-96833Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
high
2026-09-30
CVE-2026-96832Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
high
2026-09-30
CVE-2026-96831Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
high
2026-09-30
CVE-2026-96830Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
high
2026-09-30
CVE-2026-96829Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.
medium
2026-09-30
CVE-2026-96828Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
high
2026-09-30
CVE-2026-96827Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
high
2026-09-30
CVE-2026-96825Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
medium
2026-09-30
CVE-2026-96824Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
medium
2026-09-30
CVE-2026-96823Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
high
2026-09-30
CVE-2026-96822Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
critical
2026-09-30
CVE-2026-96821Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.
medium
2026-09-30
CVE-2026-96820Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
high
2026-09-30
CVE-2026-96819Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.
high
2026-09-30
CVE-2026-96818Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
high
2026-09-30
CVE-2026-96817Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
high
2026-09-30
CVE-2026-96816Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
high
2026-09-30
CVE-2026-96815Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
high
2026-09-30
CVE-2026-96814Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
high
2026-09-30
CVE-2026-96740A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.
medium
2026-09-30
CVE-2026-96649The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.
high
2026-09-30
CVE-2026-96538WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
high
2026-09-30
CVE-2026-96450Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
medium
2026-09-30
CVE-2026-96440Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.
high
2026-09-30
CVE-2026-96352Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
high
2026-09-30
CVE-2026-96351Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
high
2026-09-30
CVE-2026-96350Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
critical
2026-09-30
CVE-2026-96349Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
critical
2026-09-30
CVE-2026-96348Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
high
2026-09-30
CVE-2026-96347Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
medium
2026-09-30
CVE-2026-96346Author SQL Injection in WP ERP <= 1.17.9 versions.
high
2026-09-30
CVE-2026-96345Administrator SQL Injection in Estatik <= 4.3.5 versions.
high
2026-09-30
CVE-2026-96344Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
high
2026-09-30
CVE-2026-96343Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
high
2026-09-30
CVE-2026-96342Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
medium
2026-09-30
CVE-2026-96338Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
medium
2026-09-30
CVE-2026-96326The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
high
2026-09-30
CVE-2026-96281On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
medium
2026-09-30
CVE-2026-95616An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
high
2026-09-30
CVE-2026-95587Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
high
2026-09-30
CVE-2026-95531Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
high
2026-09-30
CVE-2026-95509Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.
high
2026-09-30
CVE-2026-95371Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
medium
2026-09-30
CVE-2026-95359Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
low
2026-09-30
CVE-2026-95357Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
critical
2026-09-30