# Bulletin de veille CVE web : 10 octobre 2026

- Page canonique : https://kreomnisvigie.com/bulletins/2026-10-11
- Établi le 11 octobre 2026 · fenêtre du 10 octobre 2026 au 10 octobre 2026
- 1 advisory, 18 CVE, 0 au CISA KEV, 0 exploitée(s)

## 1. WordPress ecosystem : Vulnérabilités critiques dans des plugins et thèmes WordPress touchant PHP, injection d’objets PHP, exécution distante de code et authentification bypass

Sur plusieurs plugins et thèmes WordPress, des vulnérabilités critiques (RCE, injection PHP d’objets, bypass d’authentification, et délétion arbitraire de fichiers) permettent à des attaquants non authentifiés ou disposant d’un niveau faible d’obtenir un contrôle étendu du serveur ou d’exécuter du code à distance. Les CVE listées ci-dessous démontrent une exposition massive dans l’écosystème WordPress côté web.

- Statut : priorité
- Vecteur : surface web, requêtes HTTP/POST sur endpoints vulnérables, absence ou échec de contrôles d’authentification et de validation des entrées
- CVE-2026-104732 (WordPress - Advanced IP Blocker) · CVSS 9.8 : authentification bypass (bug de gestion des sessions et nonces) · https://github.com/advisories/GHSA-pw6h-rjh8-7grw
- CVE-2026-94589 (WordPress - Extensions For CF7) · CVSS 9.8 : Arbitrary File Upload · https://github.com/advisories/GHSA-fjhx-3cm7-whvf
- CVE-2026-103889 (WooCommerce - 3D Product configurator) · CVSS 9.8 : Remote Code Execution · https://github.com/advisories/GHSA-m7vx-2p8f-r357
- CVE-2026-104803 (WPCOM Member) · CVSS 9.8 : Authentication Bypass · https://github.com/advisories/GHSA-gj32-ffvm-frj6
- CVE-2026-81797 (Buzz Stone Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-jgqp-7548-mqg8
- CVE-2026-78529 (Alliance Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-hj6g-q8vx-x324
- CVE-2026-66563 (Windsor Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-vfx8-984f-hxhg
- CVE-2026-78535 (Photolia Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-rfhw-cf7w-cjpq
- CVE-2026-78531 (Jacqueline Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-5568-p4h7-h6jx
- CVE-2026-66567 (Anesta Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-xm2p-xf7g-7qxp
- CVE-2026-66569 (Kicker Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-67gf-mq47-63m5
- CVE-2026-66483 (Education Center Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-4mc9-h8qv-hj9w
- CVE-2026-66482 (Drone Media Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-rg79-c57x-j75x
- CVE-2026-62125 (Asia Garden Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-gfr5-mr4f-j8gp
- CVE-2026-62120 (Law Office Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-5mqj-g4vh-q3mp
- CVE-2026-62124 (N7 - Golf Club Sports & Events Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-pf73-6px2-cj3r
- CVE-2026-62090 (WineShop Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-pmpg-93xx-xvrg
- CVE-2026-62123 (Invetex Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection · https://github.com/advisories/GHSA-mjr4-xvvg-63x3

Systèmes impactés :

- WordPress + plugins WordPress PHP : Advanced IP Blocker (WordPress) ; Extensions For CF7 (WordPress) ; 3D Product configurator for WooCommerce ; WPCOM Member (WordPress) ; Buzz Stone | Magazine & Viral Blog WordPress Theme ; Alliance Theme ; Windsor Theme ; Photolia Theme ; Jacqueline Theme ; Anesta Theme ; Kicker Theme ; ShiftCV Theme ; FC United Theme ; Qwery Theme ; Education Center Theme ; Original Theme ; Drone Media Theme ; Asia Garden Theme ; Law Office Theme ; N7 | Golf Club Sports & Events Theme ; WineShop Theme ; Splendour Theme ; Tipsy Theme ; Stargaze Theme ;  Booster for WooCommerce (plugin) ; CleanSkin Theme ; Dynamic User Directory ; Payever - WooCommerce Gateway ; PPOM – Product Addons & Custom Fields for WooCommerce ; LifterLMS (WP LMS) ; Blocksy Companion (WP)

Correctif : voir l'avis de l'éditeur

Action : Mettre à jour immédiatement les plugins et thèmes WordPress affectés vers les dernières versions sûres ou appliquer les correctifs fournis par les éditeurs; vérifier les journaux et restaurer les fichiers si nécessaire

Recommandations :

- Mettre à jour vers les versions non vulnérables des plugins et thèmes WordPress référencés dès que disponibles.
- Effectuer une revue des journaux d’accès et d’erreurs et surveiller les tentatives d’exploitation sensibles.
- Mener un inventaire des plugins et thèmes actifs et désactiver ceux qui ne sont pas nécessaires ou maintenus.

Sources :

- [GitHub Advisory – WordPress plugins](https://github.com/advisories)
- [NVD – Vulnérabilités associées](https://nvd.nist.gov/vuln/search)

## Sources du bulletin

- [CERT-FR — avis et alertes](https://www.cert.ssi.gouv.fr/avis/)
- [NIST — National Vulnerability Database](https://nvd.nist.gov/vuln/search)
- [GitHub — Security Advisories](https://github.com/advisories)
- [CISA — Known Exploited Vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

Source : Kreomnis Vigie, https://kreomnisvigie.com/bulletins/2026-10-11. Bulletin établi depuis CERT-FR, NVD, GitHub Security Advisories et CISA KEV.
