PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93949 Omegathemes CVE debrief

CVE-2026-93949: WordPress Grocery Shopping Store theme versions up to and including 1.3.3 are vulnerable to an Authentication Bypass Using an Alternate Path or Channel, allowing for Password Recovery Exploitation. This high-severity vulnerability, with a CVSS score of 7.1, affects Grocery Shopping Store by Omegathemes. Defenders should verify versions in use, assess exposure, and update to a secure version if necessary. The CVE record, published on 2026-10-10T07:00:34.180Z, provides details on the vulnerability. Limited information is available on exploitation or specific impacts, emphasizing the need for verification and potential updates. Security teams should prioritize this to

Vendor
Omegathemes
Product
Grocery Shopping Store
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations, particularly those using the Grocery Shopping Store theme, should assess exposure and verify versions in use. This vulnerability could allow for unauthorized access, making it a priority for security teams to address.

Why it matters

CVE-2026-93949 is a high-severity vulnerability in the Grocery Shopping Store WordPress theme, allowing for authentication bypass and potential unauthorized access. Defenders should prioritize verifying versions, assessing exposure, and updating to a secure version if necessary.

  • Potential unauthorized access to WordPress installations using Grocery Shopping Store theme versions up to 1.3.3.
  • Possible exploitation of password recovery functionality.
  • Need for verification of Grocery Shopping Store versions in use.
  • Priority for updating Grocery Shopping Store to a secure version.

Technical summary

The Grocery Shopping Store theme for WordPress, versions up to and including 1.3.3, is vulnerable to an Authentication Bypass Using an Alternate Path or Channel. This allows for Password Recovery Exploitation. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity.

Defensive priority

Defenders should prioritize verifying the version of Grocery Shopping Store in use and assessing exposure, as this vulnerability could allow for unauthorized access.

Recommended defensive actions

  • Verify the version of Grocery Shopping Store in use and assess exposure.
  • Review and update Grocery Shopping Store to a version beyond 1.3.3 if possible.
  • Monitor for any unauthorized access attempts or suspicious activity related to Grocery Shopping Store.

Evidence notes

The CVE record and source item provide details on the vulnerability, including its CVSS score of 7.1 and HIGH severity. However, there is limited information on exploitation or specific impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93949 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93949

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93949 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93949

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.