1 vulnerability across 1 product scored HIGH or above on October 02, 2026.

  • 🟠 HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-09-28 bulletin.
  • [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-09-26 bulletin.

🟠 [HIGH] webrehab/super_forms_–drag&_drop_form_builder

1 CVE | CVSS 3.1: 9.1 | AAS 9.4

  • cpe:2.3:a:webrehab:super_forms_drag_drop_form_builder:*:*:*:*:*:*:*:* (< 6.3.317)

WEBREHAB SUPER FORMS – DRAG & DROP FORM BUILDER

One high-severity vulnerability (CVSS 9.1) affects the Super Forms – Drag & Drop Form Builder plugin for WordPress in all versions through 6.3.316. An unauthenticated directory traversal flaw in the parse_request function allows remote attackers to read arbitrary files from the server, potentially exposing sensitive configuration data, credentials, and other critical information. The default configuration is vulnerable because the optional file_upload_auth setting is empty, requiring no authentication.

WordPress administrators using this plugin should immediately update to a patched version by reviewing the vendor’s pull request at the linked GitHub advisory. As a temporary mitigation, enabling the file_upload_auth setting can restrict unauthenticated access. Given that this vulnerability is exploitable without authentication and can expose sensitive server-side files, remediation should be treated as urgent.

Vendor Advisory