Daily High-Risk Vuln Digest 2026-10-11 (9)
Daily High-Risk Vulnerability Digest · 2026-10-11
9 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-104732 —
9.8— The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists becausehandle_login_action()performs no server-side check — v… - CVE-2026-94589 —
9.8— The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function.… - CVE-2026-103889 —
9.8— The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authent… - CVE-2026-104803 —
9.8— The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via theuuidandcodeparameters of the social-login callback handler registered on theinit… - CVE-2026-105892 —
9.8— Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia … - CVE-2026-81797 —
9.8— Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions. - CVE-2026-107645 —
9.1— The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-… - CVE-2026-97670 —
9.1— The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a Word… - CVE-2026-104801 —
9.1— The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and inc…
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.