<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
  <title>Exploit-DB.ai — Latest CVE intelligence</title>
  <link>https://exploit-db.ai/cve</link>
  <description>AI-scored CVE &amp; exploit intelligence. Data: NVD. Analysis: local $0 model.</description>
  <lastBuildDate>Wed, 30 Sep 2026 09:29:55 GMT</lastBuildDate>
  <item>
    <title>CVE-2026-97150 — HIGH 7.2</title>
    <link>https://exploit-db.ai/cve/CVE-2026-97150</link>
    <guid isPermaLink="false">CVE-2026-97150</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:36 GMT</pubDate>
    <description>When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes &quot;config.php&quot; from the addon, which means the PHP code in the file is executed.
Arbitrary files on the system may be read or deleted by an administrative user.</description>
  </item>
  <item>
    <title>CVE-2026-93464 — MEDIUM 5.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-93464</link>
    <guid isPermaLink="false">CVE-2026-93464</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:36 GMT</pubDate>
    <description>Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user&apos;s web browser may be caused.</description>
  </item>
  <item>
    <title>CVE-2026-93463 — MEDIUM 5.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-93463</link>
    <guid isPermaLink="false">CVE-2026-93463</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user&apos;s web browser may be caused.</description>
  </item>
  <item>
    <title>CVE-2026-93462 — MEDIUM 5.3</title>
    <link>https://exploit-db.ai/cve/CVE-2026-93462</link>
    <guid isPermaLink="false">CVE-2026-93462</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained.</description>
  </item>
  <item>
    <title>CVE-2026-93460 — MEDIUM 5.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-93460</link>
    <guid isPermaLink="false">CVE-2026-93460</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user&apos;s web browser may be caused.</description>
  </item>
  <item>
    <title>CVE-2026-92873 — HIGH 7.3</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92873</link>
    <guid isPermaLink="false">CVE-2026-92873</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.</description>
  </item>
  <item>
    <title>CVE-2026-92872 — MEDIUM 4.3</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92872</link>
    <guid isPermaLink="false">CVE-2026-92872</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.</description>
  </item>
  <item>
    <title>CVE-2026-92871 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92871</link>
    <guid isPermaLink="false">CVE-2026-92871</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.</description>
  </item>
  <item>
    <title>CVE-2026-92870 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92870</link>
    <guid isPermaLink="false">CVE-2026-92870</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:35 GMT</pubDate>
    <description>A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.</description>
  </item>
  <item>
    <title>CVE-2026-92869 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92869</link>
    <guid isPermaLink="false">CVE-2026-92869</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:34 GMT</pubDate>
    <description>An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.</description>
  </item>
  <item>
    <title>CVE-2026-92868 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92868</link>
    <guid isPermaLink="false">CVE-2026-92868</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:34 GMT</pubDate>
    <description>An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.</description>
  </item>
  <item>
    <title>CVE-2026-92867 — HIGH 8.8</title>
    <link>https://exploit-db.ai/cve/CVE-2026-92867</link>
    <guid isPermaLink="false">CVE-2026-92867</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:34 GMT</pubDate>
    <description>An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.</description>
  </item>
  <item>
    <title>CVE-2026-88037 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-88037</link>
    <guid isPermaLink="false">CVE-2026-88037</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:34 GMT</pubDate>
    <description>The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes i</description>
  </item>
  <item>
    <title>CVE-2026-6806 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-6806</link>
    <guid isPermaLink="false">CVE-2026-6806</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:34 GMT</pubDate>
    <description>The Motors – Car Dealership &amp; Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the &apos;stm_lat/stm_lng&apos; parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati</description>
  </item>
  <item>
    <title>CVE-2026-6173 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-6173</link>
    <guid isPermaLink="false">CVE-2026-6173</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:33 GMT</pubDate>
    <description>The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &apos;background_image&apos; parameter of the plugin&apos;s bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. Thi</description>
  </item>
  <item>
    <title>CVE-2026-6172 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-6172</link>
    <guid isPermaLink="false">CVE-2026-6172</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:33 GMT</pubDate>
    <description>The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &apos;caption&apos; parameter of the plugin&apos;s bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it </description>
  </item>
  <item>
    <title>CVE-2026-6171 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-6171</link>
    <guid isPermaLink="false">CVE-2026-6171</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:33 GMT</pubDate>
    <description>The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &apos;target&apos; parameter of the plugin&apos;s bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it po</description>
  </item>
  <item>
    <title>CVE-2026-6170 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-6170</link>
    <guid isPermaLink="false">CVE-2026-6170</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:33 GMT</pubDate>
    <description>The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &apos;images&apos; parameter of the plugin&apos;s bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This m</description>
  </item>
  <item>
    <title>CVE-2026-16596 — MEDIUM 6.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-16596</link>
    <guid isPermaLink="false">CVE-2026-16596</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:32 GMT</pubDate>
    <description>The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the &apos;data_fields_list&apos; parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po</description>
  </item>
  <item>
    <title>CVE-2026-14876 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-14876</link>
    <guid isPermaLink="false">CVE-2026-14876</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:32 GMT</pubDate>
    <description>The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &apos;data-href&apos; parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acc</description>
  </item>
  <item>
    <title>CVE-2026-11895 — MEDIUM 6.4</title>
    <link>https://exploit-db.ai/cve/CVE-2026-11895</link>
    <guid isPermaLink="false">CVE-2026-11895</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:32 GMT</pubDate>
    <description>The HT Mega Addons for Elementor – Elementor Widgets &amp; Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table &apos;display_options&apos; Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it pos</description>
  </item>
  <item>
    <title>CVE-2026-102508 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-102508</link>
    <guid isPermaLink="false">CVE-2026-102508</guid>
    <pubDate>Wed, 30 Sep 2026 12:16:31 GMT</pubDate>
    <description>Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user cr</description>
  </item>
  <item>
    <title>CVE-2026-97196 — CRITICAL 9.1</title>
    <link>https://exploit-db.ai/cve/CVE-2026-97196</link>
    <guid isPermaLink="false">CVE-2026-97196</guid>
    <pubDate>Wed, 30 Sep 2026 11:16:31 GMT</pubDate>
    <description>This vulnerability allows for authentication bypass due to improper validation of unsafe equivalence in input, impacting GiveWP versions from n/a through 4.16.9.</description>
  </item>
  <item>
    <title>CVE-2026-89294 — HIGH 7.5</title>
    <link>https://exploit-db.ai/cve/CVE-2026-89294</link>
    <guid isPermaLink="false">CVE-2026-89294</guid>
    <pubDate>Wed, 30 Sep 2026 11:16:30 GMT</pubDate>
    <description>The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the &apos;ssa_locale&apos; parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arb</description>
  </item>
  <item>
    <title>CVE-2026-97316 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-97316</link>
    <guid isPermaLink="false">CVE-2026-97316</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:11 GMT</pubDate>
    <description>The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.</description>
  </item>
  <item>
    <title>CVE-2026-96886 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-96886</link>
    <guid isPermaLink="false">CVE-2026-96886</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:10 GMT</pubDate>
    <description>The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course.</description>
  </item>
  <item>
    <title>CVE-2026-94297 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-94297</link>
    <guid isPermaLink="false">CVE-2026-94297</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:10 GMT</pubDate>
    <description>The Media Library Organizer  WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy&apos;s management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the </description>
  </item>
  <item>
    <title>CVE-2026-94274 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-94274</link>
    <guid isPermaLink="false">CVE-2026-94274</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:10 GMT</pubDate>
    <description>The YayReviews  WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers&apos; email addresses and other non-public review content.</description>
  </item>
  <item>
    <title>CVE-2026-93580 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-93580</link>
    <guid isPermaLink="false">CVE-2026-93580</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:10 GMT</pubDate>
    <description>The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order&apos;s parcel tracking number to forge its shipment </description>
  </item>
  <item>
    <title>CVE-2026-92994 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-92994</link>
    <guid isPermaLink="false">CVE-2026-92994</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:09 GMT</pubDate>
    <description>The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript tha</description>
  </item>
  <item>
    <title>CVE-2026-92424 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-92424</link>
    <guid isPermaLink="false">CVE-2026-92424</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:09 GMT</pubDate>
    <description>The Content Egg  WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author&apos;s identity before creating the resulting post, allowing users with contributor-level access and above</description>
  </item>
  <item>
    <title>CVE-2026-91832 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-91832</link>
    <guid isPermaLink="false">CVE-2026-91832</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:09 GMT</pubDate>
    <description>The WP Mobile Menu  WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu  WordPress plugin before 2.9 settings through a cross-site request in an administrator&apos;s session, and the imported values are then output une</description>
  </item>
  <item>
    <title>CVE-2026-91072 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-91072</link>
    <guid isPermaLink="false">CVE-2026-91072</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:09 GMT</pubDate>
    <description>The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site&apos;s own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a </description>
  </item>
  <item>
    <title>CVE-2026-91051 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-91051</link>
    <guid isPermaLink="false">CVE-2026-91051</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:09 GMT</pubDate>
    <description>The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code </description>
  </item>
  <item>
    <title>CVE-2026-90953 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-90953</link>
    <guid isPermaLink="false">CVE-2026-90953</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:08 GMT</pubDate>
    <description>The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.</description>
  </item>
  <item>
    <title>CVE-2026-89193 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-89193</link>
    <guid isPermaLink="false">CVE-2026-89193</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:08 GMT</pubDate>
    <description>The Robin Image Optimizer  WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting </description>
  </item>
  <item>
    <title>CVE-2026-89190 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-89190</link>
    <guid isPermaLink="false">CVE-2026-89190</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:08 GMT</pubDate>
    <description>The Robin Image Optimizer  WordPress plugin before 2.0.8 does not check the user&apos;s capabilities before dispatching one of its bundled admin framework&apos;s request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer  WordPress plugin before 2.0.8 pages and</description>
  </item>
  <item>
    <title>CVE-2026-88797 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-88797</link>
    <guid isPermaLink="false">CVE-2026-88797</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:07 GMT</pubDate>
    <description>The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any  hosted on the WordPress.org repository.</description>
  </item>
  <item>
    <title>CVE-2026-88791 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-88791</link>
    <guid isPermaLink="false">CVE-2026-88791</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:07 GMT</pubDate>
    <description>The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.</description>
  </item>
  <item>
    <title>CVE-2026-87777 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-87777</link>
    <guid isPermaLink="false">CVE-2026-87777</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:07 GMT</pubDate>
    <description>The Hostinger Reach  WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens t</description>
  </item>
  <item>
    <title>CVE-2026-86789 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-86789</link>
    <guid isPermaLink="false">CVE-2026-86789</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:07 GMT</pubDate>
    <description>The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending mod</description>
  </item>
  <item>
    <title>CVE-2026-85576 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-85576</link>
    <guid isPermaLink="false">CVE-2026-85576</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:06 GMT</pubDate>
    <description>The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.</description>
  </item>
  <item>
    <title>CVE-2026-85573 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-85573</link>
    <guid isPermaLink="false">CVE-2026-85573</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:06 GMT</pubDate>
    <description>The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site&apos;s allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site&apos;s origin</description>
  </item>
  <item>
    <title>CVE-2026-85415 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-85415</link>
    <guid isPermaLink="false">CVE-2026-85415</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:06 GMT</pubDate>
    <description>The Audio Player Block  WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as a</description>
  </item>
  <item>
    <title>CVE-2026-85001 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-85001</link>
    <guid isPermaLink="false">CVE-2026-85001</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:05 GMT</pubDate>
    <description>The EmbedPress  WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.</description>
  </item>
  <item>
    <title>CVE-2026-83560 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-83560</link>
    <guid isPermaLink="false">CVE-2026-83560</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:05 GMT</pubDate>
    <description>The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered use</description>
  </item>
  <item>
    <title>CVE-2026-82127 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-82127</link>
    <guid isPermaLink="false">CVE-2026-82127</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:05 GMT</pubDate>
    <description>The Schema &amp; Structured Data for WP &amp; AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged</description>
  </item>
  <item>
    <title>CVE-2026-80333 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-80333</link>
    <guid isPermaLink="false">CVE-2026-80333</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:05 GMT</pubDate>
    <description>The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.</description>
  </item>
  <item>
    <title>CVE-2026-75873 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-75873</link>
    <guid isPermaLink="false">CVE-2026-75873</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:04 GMT</pubDate>
    <description>The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.</description>
  </item>
  <item>
    <title>CVE-2026-75824 — UNSCORED </title>
    <link>https://exploit-db.ai/cve/CVE-2026-75824</link>
    <guid isPermaLink="false">CVE-2026-75824</guid>
    <pubDate>Wed, 30 Sep 2026 10:17:04 GMT</pubDate>
    <description>The User Frontend  WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.

The created account receives the site&apos;s default role.</description>
  </item>
</channel></rss>
