1 vulnerability across 1 product scored HIGH or above on October 03, 2026.

  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 13.4 (HIGH โ†’ CRITICAL). Originally in 2026-09-30 bulletin.
  • [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) โ€” F1: exploitable โ†’ functional, AAS: 9.2 โ†’ 11.2 (HIGH โ†’ HIGH). Originally in 2026-09-28 bulletin.
  • [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-09-26 bulletin.

๐ŸŸ  [HIGH] beaverbuilder/beaver_builder_page_builder_โ€“_drag_and_drop_website_builder

1 CVE | CVSS 3.1: 9.1 | AAS 9.9

  • cpe:2.3:a:beaverbuilder:beaver_builder_page_builder_drag_and_drop_website_builder:*:*:*:*:*:*:*:*

Beaver Builder Page Builder, a popular drag-and-drop WordPress website builder plugin, is affected by one critical-severity vulnerability (CVE-2026-92084, CVSS 9.1). The flaw allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation in the Sidebar module rendering path, potentially leading to full site compromise on any WordPress site running Beaver Builder versions up to and including 2.11.0.5 that contain a page with the Sidebar module.

WordPress administrators using Beaver Builder should immediately check for an updated version from the plugin vendor and apply it as soon as available. Sites that cannot be patched right away should consider temporarily removing or disabling the Sidebar module from any published Beaver Builder pages to reduce the attack surface. Given the unauthenticated nature of this exploit, any internet-facing WordPress site running an affected version should treat remediation as urgent.

Vendor Advisory