[vulnfeed] 2 critical CVEs — 2026-09-26 20:00 UTC
vulnfeed
Critical alert — 2026-09-26 23:04 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-85984CRITICAL
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authenticat
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.
CVSS 9.8
CVE-2026-82901CRITICAL
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insuffi
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions u
CVSS 9.8
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: