Daily High-Risk Vuln Digest 2026-10-09 (5)
Daily High-Risk Vulnerability Digest · 2026-10-09
5 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-103646 —
9.8— The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and i… - CVE-2026-103692 —
9.8— The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the requ… - CVE-2026-85097 —
9.8— The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 't… - CVE-2026-107780 —
9.8— Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers c… - CVE-2026-17609 —
9.1— The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient valida…
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.