PatchSiren cyber security CVE debrief
CVE-2026-93949 Omegathemes CVE debrief
CVE-2026-93949: WordPress Grocery Shopping Store theme versions up to and including 1.3.3 are vulnerable to an Authentication Bypass Using an Alternate Path or Channel, allowing for Password Recovery Exploitation. This high-severity vulnerability, with a CVSS score of 7.1, affects Grocery Shopping Store by Omegathemes. Defenders should verify versions in use, assess exposure, and update to a secure version if necessary. The CVE record, published on 2026-10-10T07:00:34.180Z, provides details on the vulnerability. Limited information is available on exploitation or specific impacts, emphasizing the need for verification and potential updates. Security teams should prioritize this to
- Vendor
- Omegathemes
- Product
- Grocery Shopping Store
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations, particularly those using the Grocery Shopping Store theme, should assess exposure and verify versions in use. This vulnerability could allow for unauthorized access, making it a priority for security teams to address.
Why it matters
CVE-2026-93949 is a high-severity vulnerability in the Grocery Shopping Store WordPress theme, allowing for authentication bypass and potential unauthorized access. Defenders should prioritize verifying versions, assessing exposure, and updating to a secure version if necessary.
- Potential unauthorized access to WordPress installations using Grocery Shopping Store theme versions up to 1.3.3.
- Possible exploitation of password recovery functionality.
- Need for verification of Grocery Shopping Store versions in use.
- Priority for updating Grocery Shopping Store to a secure version.
Technical summary
The Grocery Shopping Store theme for WordPress, versions up to and including 1.3.3, is vulnerable to an Authentication Bypass Using an Alternate Path or Channel. This allows for Password Recovery Exploitation. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity.
Defensive priority
Defenders should prioritize verifying the version of Grocery Shopping Store in use and assessing exposure, as this vulnerability could allow for unauthorized access.
Recommended defensive actions
- Verify the version of Grocery Shopping Store in use and assess exposure.
- Review and update Grocery Shopping Store to a version beyond 1.3.3 if possible.
- Monitor for any unauthorized access attempts or suspicious activity related to Grocery Shopping Store.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its CVSS score of 7.1 and HIGH severity. However, there is limited information on exploitation or specific impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93949 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93949
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93949 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93949
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93949.json
cve_program_cvelist_v5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.