4 vulnerabilities across 4 products scored HIGH or above on October 10, 2026.

  • 🟠 HIGH: 4

🟠 [HIGH] inilerm/advanced_ip_blocker

1 CVE | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:inilerm:advanced_ip_blocker:*:*:*:*:*:*:*:* (< 8.13.14)

Advanced IP Blocker by inilerm, a WordPress plugin, is affected by one critical authentication bypass vulnerability (CVE-2026-104732, CVSS 9.8 HIGH). The flaw allows attackers to skip password authentication entirely and proceed directly to the second-factor TOTP step for any user ID, effectively bypassing two-factor authentication and gaining unauthorized access to administrative accounts. WordPress site administrators running Advanced IP Blocker version 8.13.13 or earlier should update immediately to a patched release or deactivate the plugin until a fix is available, and review access logs for signs of unauthorized login activity.

Vendor Advisory


🟠 [HIGH] creativethemeshq/blocksy_companion

1 CVE | CVSS 3.1: 9.1 | AAS 9.9

  • cpe:2.3:a:creativethemeshq:blocksy_companion:*:*:*:*:*:*:*:* (< 2.1.59)

Blocksy Companion by CreativeThemesHQ, a widely used WordPress plugin, is affected by one critical privilege escalation vulnerability (CVE-2026-107645, CVSS 9.1 HIGH). The flaw exists in the user registration AJAX handler, which deliberately disables nonce verification and trusts attacker-supplied role values during account creation, allowing unauthenticated attackers to register themselves with elevated privileges such as shop manager or administrator. WordPress site administrators running Blocksy Companion version 2.1.58 or earlier should update to the latest patched release immediately, audit existing user accounts for any unauthorized role assignments, and remove any suspicious accounts.

Vendor Advisory


🟠 [HIGH] themefusion/avada_(fusion)_builder

1 CVE | CVSS 3.1: 9.1 | AAS 9.4

  • cpe:2.3:a:themefusion:avada_fusion_builder:*:*:*:*:*:*:*:* (< 7.16.2)

Avada (Fusion) Builder by ThemeFusion, one of the most popular premium WordPress page builder plugins, is affected by one critical authorization bypass vulnerability (CVE-2026-97670, CVSS 9.1 HIGH). The flaw allows attackers to trigger arbitrary WordPress action hooks by supplying a crafted form-field value through the plugin’s notification and dynamic-data token system, bypassing the intended authorization gate which only inspects a narrow subset of request parameters. WordPress site administrators running Avada Builder version 7.16.1 or earlier should update to version 7.16.2 or later immediately and review server logs for unusual form submissions or unexpected action hook executions that may indicate exploitation attempts.

Vendor Advisory


🟠 [HIGH] jetbrains/exposed

1 CVE | CVSS 3.1: 9.8 | AAS 9.1

  • cpe:2.3:a:jetbrains:exposed:*:*:*:*:*:*:*:*

JetBrains Exposed, an open-source Kotlin SQL framework widely used in JVM-based applications, is affected by one critical SQL injection vulnerability (CVE-2026-108474, CVSS 9.8 HIGH). The flaw stems from several SQL functions failing to properly escape string arguments, allowing attackers to inject arbitrary SQL commands and potentially gain full access to the underlying database. Development teams using Exposed versions prior to 1.5.1 should upgrade immediately and audit their applications for any SQL functions that may pass unsanitized user input through the affected code paths.

Vendor Advisory