Vulnerability & Patch Roundup — August 2026

WordPress Vulnerability Round-up - August 2026

If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.

To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.

For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.


Plugins


LiteSpeed Cache – Unauthenticated Stored Cross-Site Scripting via Comment Content

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content
CVE: CVE-2026-18978
Number of Installations: 7,000,000+
Affected Software: LiteSpeed Cache ≤ 7.8.1
Patched Versions: 7.9

Mitigation steps: Update to LiteSpeed Cache version 7.9 or greater.


LiteSpeed Cache – Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes
CVE: CVE-2026-3129
Number of Installations: 7,000,000+
Affected Software: LiteSpeed Cache ≤ 7.7
Patched Versions: 7.8

Mitigation steps: Update to LiteSpeed Cache version 7.8 or greater.


All-in-One WP Migration and Backup – Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
CVE: CVE-2026-19949
Number of Installations: 5,000,000+
Affected Software: All-in-One WP Migration and Backup ≤ 7.109
Patched Versions: 7.110

Mitigation steps: Update to All-in-One WP Migration and Backup version 7.110 or greater.


All-in-One WP Migration and Backup – Authenticated (Administrator+) Remote Code Execution

Security Risk: High
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Remote Code Execution
CVE: CVE-2026-17533
Number of Installations: 5,000,000+
Affected Software: All-in-One WP Migration and Backup < 7.108
Patched Versions: 7.108

Mitigation steps: Update to All-in-One WP Migration and Backup version 7.108 or greater.


Essential Addons for Elementor – Unauthenticated Privilege Escalation

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-18039
Number of Installations: 1,000,000+
Affected Software: Essential Addons for Elementor ≤ 6.7.1
Patched Versions: 6.7.2

Mitigation steps: Update to Essential Addons for Elementor version 6.7.2 or greater.


WP Fastest Cache – Unauthenticated Stored Cross-Site Scripting via HTTP Host Header

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via HTTP Host Header
CVE: CVE-2026-19760
Number of Installations: 1,000,000+
Affected Software: WP Fastest Cache ≤ 1.5.0
Patched Versions: 1.5.1

Mitigation steps: Update to WP Fastest Cache version 1.5.1 or greater.


ElementsKit Elementor Addons – Authenticated (Admin+) Remote Code Execution

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) Remote Code Execution
CVE: CVE-2026-13392
Number of Installations: 1,000,000+
Affected Software: ElementsKit Elementor Addons < 3.10.01
Patched Versions: 3.10.01

Mitigation steps: Update to ElementsKit Elementor Addons version 3.10.01 or greater.


MC4WP: Mailchimp for WordPress – Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages
CVE: CVE-2026-4561
Number of Installations: 1,000,000+
Affected Software: MC4WP: Mailchimp for WordPress ≤ 4.12.0
Patched Versions: 4.12.1

Mitigation steps: Update to MC4WP: Mailchimp for WordPress version 4.12.1 or greater.


EWWW Image Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘data-script’ Lazy Load Attribute in Post Content

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content
CVE: CVE-2026-15446
Number of Installations: 1,000,000+
Affected Software: EWWW Image Optimizer ≤ 8.7.3
Patched Versions: 8.7.4

Mitigation steps: Update to EWWW Image Optimizer version 8.7.4 or greater.


Speed Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes
CVE: CVE-2026-15421
Number of Installations: 1,000,000+
Affected Software: Speed Optimizer ≤ 7.8.0
Patched Versions: 7.8.1

Mitigation steps: Update to Speed Optimizer version 7.8.1 or greater.


Loco Translate – Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments

Security Risk: High
Exploitation Level: Requires Translator or higher level authentication.
Vulnerability: Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments
CVE: CVE-2026-15066
Number of Installations: 1,000,000+
Affected Software: Loco Translate ≤ 2.8.7
Patched Versions: 2.8.8

Mitigation steps: Update to Loco Translate version 2.8.8 or greater.


AI Agent by SiteGround – Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint
CVE: CVE-2026-17153
Number of Installations: 1,000,000+
Affected Software: AI Agent by SiteGround ≤ 1.2.7
Patched Versions: 1.2.8

Mitigation steps: Update to AI Agent by SiteGround version 1.2.8 or greater.


Smash Balloon Social Photo Feed – Reflected Cross-Site Scripting via REQUEST_URI Query String

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via REQUEST_URI Query String
CVE: CVE-2026-15452
Number of Installations: 1,000,000+
Affected Software: Smash Balloon Social Photo Feed ≤ 6.11.3
Patched Versions: 6.11.4

Mitigation steps: Update to Smash Balloon Social Photo Feed version 6.11.4 or greater.


W3 Total Cache – Unauthenticated Path Traversal

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Path Traversal
CVE: CVE-2026-18051
Number of Installations: 900,000+
Affected Software: W3 Total Cache < 2.10.5
Patched Versions: 2.10.5

Mitigation steps: Update to W3 Total Cache version 2.10.5 or greater.


WPvivid – Unauthenticated Path Traversal

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Path Traversal
CVE: CVE-2026-19725
Number of Installations: 900,000+
Affected Software: WPvivid < 0.9.131
Patched Versions: 0.9.131

Mitigation steps: Update to WPvivid version 0.9.131 or greater.


W3 Total Cache – Unauthenticated Stored Cross-Site Scripting via Comment Author Name

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Author Name
CVE: CVE-2026-18109
Number of Installations: 900,000+
Affected Software: W3 Total Cache ≤ 2.10.3
Patched Versions: 2.10.4

Mitigation steps: Update to W3 Total Cache version 2.10.4 or greater.


Smart Slider 3 – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘slider’ Block Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute
CVE: CVE-2026-15798
Number of Installations: 800,000+
Affected Software: Smart Slider 3 ≤ 3.5.1.38
Patched Versions: 3.5.1.39

Mitigation steps: Update to Smart Slider 3 version 3.5.1.39 or greater.


Fluent Forms – Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values
CVE: CVE-2026-18146
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.11
Patched Versions: 6.2.12

Mitigation steps: Update to Fluent Forms version 6.2.12 or greater.


Popup Maker – Unauthenticated Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-28177
Number of Installations: 700,000+
Affected Software: Popup Maker ≤ 1.23.0
Patched Versions: 1.24.0

Mitigation steps: Update to Popup Maker version 1.24.0 or greater.


Fluent Forms – Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion

Security Risk: High
Exploitation Level: Requires Form Manager or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion
CVE: CVE-2026-11578
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.4
Patched Versions: 6.2.5

Mitigation steps: Update to Fluent Forms version 6.2.5 or greater.


Fluent Forms – Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation
CVE: CVE-2026-11880
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.0
Patched Versions: 6.2.1

Mitigation steps: Update to Fluent Forms version 6.2.1 or greater.


Forminator Forms – Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
CVE: CVE-2026-15748
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.56.1
Patched Versions: 1.56.2

Mitigation steps: Update to Forminator Forms version 1.56.2 or greater.


Royal Addons for Elementor – Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget ‘webhook_url’ Setting

Security Risk: High
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting
CVE: CVE-2026-17123
Number of Installations: 600,000+
Affected Software: Royal Addons for Elementor ≤ 1.7.1064
Patched Versions: 1.7.1065

Mitigation steps: Update to Royal Addons for Elementor version 1.7.1065 or greater.


Forminator Forms – Authenticated (Contributor+) Privilege Escalation

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Privilege Escalation
CVE: CVE-2026-28111
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.56.0
Patched Versions: 1.56.0.1

Mitigation steps: Update to Forminator Forms version 1.56.0.1 or greater.


Forminator Forms – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-66583
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.0
Patched Versions: 1.57.1

Mitigation steps: Update to Forminator Forms version 1.57.1 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
CVE: CVE-2026-18324
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.0.1
Patched Versions: 1.57.0.2

Mitigation steps: Update to Forminator Forms version 1.57.0.2 or greater.


Forminator Forms – Unauthenticated DOM-Based Cross-Site Scripting via ‘error_description’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter
CVE: CVE-2026-18328
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.0
Patched Versions: 1.57.0.1

Mitigation steps: Update to Forminator Forms version 1.57.0.1 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)
CVE: CVE-2026-18323
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.0.2
Patched Versions: 1.57.0.3

Mitigation steps: Update to Forminator Forms version 1.57.0.3 or greater.


Royal Addons for Elementor – Authenticated (Administrator+) Remote Code Execution

Security Risk: High
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Remote Code Execution
CVE: CVE-2026-13405
Number of Installations: 600,000+
Affected Software: Royal Addons for Elementor < 1.7.1066
Patched Versions: 1.7.1066

Mitigation steps: Update to Royal Addons for Elementor version 1.7.1066 or greater.


WP Statistics – Unauthenticated Stored Cross-Site Scripting via ‘utm_campaign’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter
CVE: CVE-2026-15780
Number of Installations: 600,000+
Affected Software: WP Statistics ≤ 14.16.8
Patched Versions: 14.16.9

Mitigation steps: Update to WP Statistics version 14.16.9 or greater.


SiteGuard WP Plugin – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-61982
Number of Installations: 600,000+
Affected Software: SiteGuard WP Plugin ≤ 1.8.6
Patched Versions: 1.8.7

Mitigation steps: Update to SiteGuard WP Plugin version 1.8.7 or greater.


FluentSMTP – Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs
CVE: CVE-2026-16636
Number of Installations: 600,000+
Affected Software: FluentSMTP ≤ 2.2.95
Patched Versions: 2.3.0

Mitigation steps: Update to FluentSMTP version 2.3.0 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field
CVE: CVE-2026-18325
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.56.1
Patched Versions: 1.56.2

Mitigation steps: Update to Forminator Forms version 1.56.2 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-28143
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.56.0
Patched Versions: 1.56.1

Mitigation steps: Update to Forminator Forms version 1.56.1 or greater.


MetForm – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘mf_form_id’ Widget Setting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting
CVE: CVE-2026-18100
Number of Installations: 600,000+
Affected Software: MetForm ≤ 4.1.8
Patched Versions: 4.1.9

Mitigation steps: Update to MetForm version 4.1.9 or greater.


Royal Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-19217
Number of Installations: 600,000+
Affected Software: Royal Addons for Elementor ≤ 1.7.1064
Patched Versions: 1.7.1065

Mitigation steps: Update to Royal Addons for Elementor version 1.7.1065 or greater.


Forminator Forms – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via ‘draft’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter
CVE: CVE-2026-12998
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.55.0.2
Patched Versions: 1.55.1

Mitigation steps: Update to Forminator Forms version 1.55.1 or greater.


WP Statistics – Authenticated (Subscriber+) Information Exposure

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-16562
Number of Installations: 600,000+
Affected Software: WP Statistics ≤ 14.16.9
Patched Versions: 14.16.10

Mitigation steps: Update to WP Statistics version 14.16.10 or greater.


Kirki – Unauthenticated Remote Code Execution

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Remote Code Execution
CVE: CVE-2026-16747
Number of Installations: 500,000+
Affected Software: Kirki < 6.2.1
Patched Versions: 6.2.1

Mitigation steps: Update to Kirki version 6.2.1 or greater.


Broken Link Checker – Unauthenticated Remote Code Execution

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Remote Code Execution
CVE: CVE-2026-18937
Number of Installations: 500,000+
Affected Software: Broken Link Checker < 2.4.12
Patched Versions: 2.4.12

Mitigation steps: Update to Broken Link Checker version 2.4.12 or greater.


Kirki – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-12720
Number of Installations: 500,000+
Affected Software: Kirki < 6.0.13
Patched Versions: 6.0.13

Mitigation steps: Update to Kirki version 6.0.13 or greater.


Kirki – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66629
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.2.4
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Kirki – Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode
CVE: CVE-2026-16974
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.2.0
Patched Versions: 6.2.1

Mitigation steps: Update to Kirki version 6.2.1 or greater.


Slider, Gallery, and Carousel by MetaSlider – Authenticated (Author+) Stored Cross-Site Scripting via ‘delay’ Post Meta Setting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting
CVE: CVE-2026-18400
Number of Installations: 500,000+
Affected Software: Slider, Gallery, and Carousel by MetaSlider ≤ 3.111.0
Patched Versions: 3.111.1

Mitigation steps: Update to Slider, Gallery, and Carousel by MetaSlider version 3.111.1 or greater.


Kirki – Authenticated (Editor+) Path Traversal to Arbitrary File Read via ‘data’ Parameter

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter
CVE: CVE-2026-17604
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.1.1
Patched Versions: 6.2.0

Mitigation steps: Update to Kirki version 6.2.0 or greater.


Kirki – Authenticated (Editor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting
CVE: CVE-2026-74992
Number of Installations: 500,000+
Affected Software: Kirki < 6.2.3
Patched Versions: 6.2.3

Mitigation steps: Update to Kirki version 6.2.3 or greater.


Kirki – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via ‘context’ Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter
CVE: CVE-2026-18347
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.1.1
Patched Versions: 6.2.0

Mitigation steps: Update to Kirki version 6.2.0 or greater.


Meta Box – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-15248
Number of Installations: 500,000+
Affected Software: Meta Box < 5.13.1
Patched Versions: 5.13.1

Mitigation steps: Update to Meta Box version 5.13.1 or greater.


TranslatePress – Unauthenticated Account Takeover via Password Reset Link Disclosure

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Account Takeover via Password Reset Link Disclosure
CVE: CVE-2026-19632
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.3.1
Patched Versions: 3.3.2

Mitigation steps: Update to TranslatePress version 3.3.2 or greater.


TranslatePress – Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser
CVE: CVE-2026-76053
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.3.3
Patched Versions: 3.3.4

Mitigation steps: Update to TranslatePress version 3.3.4 or greater.


TranslatePress – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66582
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.3.2
Patched Versions: 3.3.3

Mitigation steps: Update to TranslatePress version 3.3.3 or greater.


TranslatePress – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-75981
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.2.5
Patched Versions: 3.2.6

Mitigation steps: Update to TranslatePress version 3.2.6 or greater.


TranslatePress – Unauthenticated Stored Cross-Site Scripting via Comment Content

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content
CVE: CVE-2026-18510
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.2.6
Patched Versions: 3.3

Mitigation steps: Update to TranslatePress version 3.3 or greater.


TranslatePress – Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor
CVE: CVE-2026-18512
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.2.6
Patched Versions: 3.3

Mitigation steps: Update to TranslatePress version 3.3 or greater.


TranslatePress – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-17505
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.2.5
Patched Versions: 3.2.6

Mitigation steps: Update to TranslatePress version 3.2.6 or greater.


Templately – Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch

Security Risk: High
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch
CVE: CVE-2026-18438
Number of Installations: 300,000+
Affected Software: Templately ≤ 3.7.1
Patched Versions: 3.7.2

Mitigation steps: Update to Templately version 3.7.2 or greater.


WP Go Maps – Unauthenticated SQL Injection

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-15381
Number of Installations: 300,000+
Affected Software: WP Go Maps < 10.1.04
Patched Versions: 10.1.04

Mitigation steps: Update to WP Go Maps version 10.1.04 or greater.


Formidable Forms – Unauthenticated Stored Cross-Site Scripting via ‘frm_user_id’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter
CVE: CVE-2026-18331
Number of Installations: 300,000+
Affected Software: Formidable Forms ≤ 6.33.1
Patched Versions: 6.34

Mitigation steps: Update to Formidable Forms version 6.34 or greater.


Templately – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66667
Number of Installations: 300,000+
Affected Software: Templately ≤ 3.7.1
Patched Versions: 3.7.2

Mitigation steps: Update to Templately version 3.7.2 or greater.


Photo Gallery, Sliders, Proofing and Themes – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-28141
Number of Installations: 300,000+
Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.2.3
Patched Versions: 4.2.4

Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.2.4 or greater.


Unlimited Elements For Elementor – Authenticated (Contributor+) Arbitrary File Download

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Arbitrary File Download
CVE: CVE-2026-28146
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.14
Patched Versions: 2.0.15

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.15 or greater.


Blocksy Companion – Authenticated (Author+) Stored Cross-Site Scripting via ‘tagName’ Block Attribute (blocksy/dynamic-data)

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data)
CVE: CVE-2026-18488
Number of Installations: 300,000+
Affected Software: Blocksy Companion ≤ 2.1.51
Patched Versions: 2.1.52

Mitigation steps: Update to Blocksy Companion version 2.1.52 or greater.


Breeze Cache – Missing Authorization to Unauthenticated Arbitrary Content Deletion

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Arbitrary Content Deletion
CVE: CVE-2026-73356
Number of Installations: 300,000+
Affected Software: Breeze Cache ≤ 2.5.12
Patched Versions: 2.5.13

Mitigation steps: Update to Breeze Cache version 2.5.13 or greater.


Ad Inserter – Missing Authorization to Block Visibility Bypass via ai_ajax

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Block Visibility Bypass via ai_ajax
CVE: CVE-2026-11983
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.16
Patched Versions: 2.8.17

Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.


Templately – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-15359
Number of Installations: 300,000+
Affected Software: Templately ≤ 3.7.0
Patched Versions: 3.7.1

Mitigation steps: Update to Templately version 3.7.1 or greater.


Password Protected – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-14943
Number of Installations: 300,000+
Affected Software: Password Protected ≤ 2.8.3
Patched Versions: 2.8.4

Mitigation steps: Update to Password Protected version 2.8.4 or greater.


Duplicate Post – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-19085
Number of Installations: 300,000+
Affected Software: Duplicate Post < 1.5.6
Patched Versions: 1.5.6

Mitigation steps: Update to Duplicate Post version 1.5.6 or greater.


Unlimited Elements For Elementor – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-28147
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.15
Patched Versions: 2.0.16

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.16 or greater.


Ultimate Member – Unauthenticated Privilege Escalation

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-12251
Number of Installations: 200,000+
Affected Software: Ultimate Member < 2.12.1
Patched Versions: 2.12.1

Mitigation steps: Update to Ultimate Member version 2.12.1 or greater.


Optimole – Unauthenticated Stored Cross-Site Scripting via ‘a’ (above_fold_images) Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter
CVE: CVE-2026-77365
Number of Installations: 200,000+
Affected Software: Optimole ≤ 4.2.10
Patched Versions: 4.2.11

Mitigation steps: Update to Optimole version 4.2.11 or greater.


Newsletter – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66596
Number of Installations: 200,000+
Affected Software: Newsletter ≤ 9.3.3
Patched Versions: 9.3.4

Mitigation steps: Update to Newsletter version 9.3.4 or greater.


Ultimate Member – Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute)

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute)
CVE: CVE-2026-18547
Number of Installations: 200,000+
Affected Software: Ultimate Member ≤ 2.12.1
Patched Versions: 2.13.0

Mitigation steps: Update to Ultimate Member version 2.13.0 or greater.


Admin and Site Enhancements (ASE) – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-19615
Number of Installations: 200,000+
Affected Software: Admin and Site Enhancements (ASE) < 9.0.1
Patched Versions: 9.0.1

Mitigation steps: Update to Admin and Site Enhancements (ASE) version 9.0.1 or greater.


Smash Balloon Social Post Feed – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘id’ Shortcode Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
CVE: CVE-2026-16775
Number of Installations: 200,000+
Affected Software: Smash Balloon Social Post Feed ≤ 4.9.0
Patched Versions: 4.10.0

Mitigation steps: Update to Smash Balloon Social Post Feed version 4.10.0 or greater.


Kadence Starter Templates – Unauthenticated Denial of Service

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-73997
Number of Installations: 200,000+
Affected Software: Kadence Starter Templates ≤ 2.3.3
Patched Versions: 2.3.4

Mitigation steps: Update to Kadence Starter Templates version 2.3.4 or greater.


Gutenberg Essential Blocks – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-13153
Number of Installations: 200,000+
Affected Software: Gutenberg Essential Blocks ≤ 6.3.0
Patched Versions: 6.4.0

Mitigation steps: Update to Gutenberg Essential Blocks version 6.4.0 or greater.


InfiniteWP Client – Authenticated (Administrator+) SQL Injection

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection
CVE: CVE-2026-74011
Number of Installations: 200,000+
Affected Software: InfiniteWP Client ≤ 1.13.9
Patched Versions: 1.13.10

Mitigation steps: Update to InfiniteWP Client version 1.13.10 or greater.


Mailchimp for WooCommerce – Authenticated (Administrator+) SQL Injection

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection
CVE: CVE-2026-73346
Number of Installations: 200,000+
Affected Software: Mailchimp for WooCommerce < 6.2
Patched Versions: 6.2

Mitigation steps: Update to Mailchimp for WooCommerce version 6.2 or greater.


PrettyLinks – Authenticated (Administrator+) SQL Injection via ‘s’ Parameter

Security Risk: Medium
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection via 's' Parameter
CVE: CVE-2026-5062
Number of Installations: 200,000+
Affected Software: PrettyLinks ≤ 3.6.20
Patched Versions: 3.6.21

Mitigation steps: Update to PrettyLinks version 3.6.21 or greater.


Post Duplicator – Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution
CVE: CVE-2026-4244
Number of Installations: 200,000+
Affected Software: Post Duplicator ≤ 3.0.11
Patched Versions: 3.0.12

Mitigation steps: Update to Post Duplicator version 3.0.12 or greater.


Post Duplicator – Authorization Bypass to Authenticated (Contributor+) Post Duplication

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authorization Bypass to Authenticated (Contributor+) Post Duplication
CVE: CVE-2026-4245
Number of Installations: 200,000+
Affected Software: Post Duplicator ≤ 3.0.11
Patched Versions: 3.0.12

Mitigation steps: Update to Post Duplicator version 3.0.12 or greater.


GiveWP – Unauthenticated PHP Object Injection to Remote Code Execution

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection to Remote Code Execution
CVE: CVE-2026-82222
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.7.1
Patched Versions: 4.16.7.2

Mitigation steps: Update to GiveWP version 4.16.7.2 or greater.


Pods – Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via ‘pods_admin’ AJAX Router

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
CVE: CVE-2026-19598
Number of Installations: 100,000+
Affected Software: Pods 2.8 - 2.8.23.3
Patched Versions: 3.3.9.1

Mitigation steps: Update to Pods version 3.3.9.1 or greater.


One User Avatar – Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter
CVE: CVE-2026-18983
Number of Installations: 100,000+
Affected Software: One User Avatar ≤ 2.5.4
Patched Versions: 2.5.5

Mitigation steps: Update to One User Avatar version 2.5.5 or greater.


ShopEngine Elementor WooCommerce Builder Addon – Authenticated (Shop Manager+) Privilege Escalation to WXR Import ‘<wp_option>’ Nodes

Security Risk: High
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes
CVE: CVE-2026-75971
Number of Installations: 100,000+
Affected Software: ShopEngine Elementor WooCommerce Builder Addon ≤ 4.9.4
Patched Versions: 4.9.5

Mitigation steps: Update to ShopEngine Elementor WooCommerce Builder Addon version 4.9.5 or greater.


Social Media Share Buttons & Social Sharing Icons – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66623
Number of Installations: 100,000+
Affected Software: Social Media Share Buttons & Social Sharing Icons ≤ 2.9.9
Patched Versions: 3.0.0

Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.0 or greater.


Download Manager – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-14292
Number of Installations: 100,000+
Affected Software: Download Manager < 3.3.66
Patched Versions: 3.3.66

Mitigation steps: Update to Download Manager version 3.3.66 or greater.


Independent Analytics – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-17506
Number of Installations: 100,000+
Affected Software: Independent Analytics ≤ 2.15.0
Patched Versions: 2.15.1

Mitigation steps: Update to Independent Analytics version 2.15.1 or greater.


EmbedPress – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-61961
Number of Installations: 100,000+
Affected Software: EmbedPress ≤ 4.5.6
Patched Versions: 4.6.0

Mitigation steps: Update to EmbedPress version 4.6.0 or greater.


Tutor LMS – Unauthenticated Remote Code Execution via ‘template’ and ‘data’ POST Parameters

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
CVE: CVE-2026-16759
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.5
Patched Versions: 4.0.6

Mitigation steps: Update to Tutor LMS version 4.0.6 or greater.


Relevanssi – Authenticated (Contributor+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) SQL Injection
CVE: CVE-2026-15941
Number of Installations: 100,000+
Affected Software: Relevanssi ≤ 4.27.1
Patched Versions: 4.27.2

Mitigation steps: Update to Relevanssi version 4.27.2 or greater.


Content Views – Authenticated (Subscriber+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) SQL Injection
CVE: CVE-2026-15361
Number of Installations: 100,000+
Affected Software: Content Views ≤ 4.4
Patched Versions: 4.5

Mitigation steps: Update to Content Views version 4.5 or greater.


AI Engine – Authenticated (Subscriber+) Arbitrary File Read

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Arbitrary File Read
CVE: CVE-2026-16955
Number of Installations: 100,000+
Affected Software: AI Engine ≤ 3.6.5
Patched Versions: 3.6.6

Mitigation steps: Update to AI Engine version 3.6.6 or greater.


GiveWP – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVE: CVE-2026-5510
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.14.4
Patched Versions: 4.14.5

Mitigation steps: Update to GiveWP version 4.14.5 or greater.


Envira Gallery – Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description
CVE: CVE-2026-3423
Number of Installations: 100,000+
Affected Software: Envira Gallery ≤ 1.12.4
Patched Versions: 1.12.5

Mitigation steps: Update to Envira Gallery version 1.12.5 or greater.


Beaver Builder Page Builder – Authenticated (Author+) Stored Cross-Site Scripting via Button Module ‘button’ Parameter

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter
CVE: CVE-2026-17090
Number of Installations: 100,000+
Affected Software: Beaver Builder Page Builder ≤ 2.10.2.2
Patched Versions: 2.10.3.2

Mitigation steps: Update to Beaver Builder Page Builder version 2.10.3.2 or greater.


ECS – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-14230
Number of Installations: 100,000+
Affected Software: ECS ≤ 4.3.7
Patched Versions: 4.3.8

Mitigation steps: Update to ECS version 4.3.8 or greater.


GiveWP – Authenticated (Donor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Donor or higher level authentication.
Vulnerability: Authenticated (Donor+) Stored Cross-Site Scripting
CVE: CVE-2026-73357
Number of Installations: 100,000+
Affected Software: GiveWP < 4.16.6
Patched Versions: 4.16.6

Mitigation steps: Update to GiveWP version 4.16.6 or greater.


Appointment Booking Plugin – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVE: CVE-2026-5391
Number of Installations: 100,000+
Affected Software: Appointment Booking Plugin ≤ 5.3.2
Patched Versions: 5.4.0

Mitigation steps: Update to Appointment Booking Plugin version 5.4.0 or greater.


Advanced File Manager – Reflected Cross-Site Scripting via postMessage ‘soundFile’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter
CVE: CVE-2026-15009
Number of Installations: 100,000+
Affected Software: Advanced File Manager ≤ 5.4.12
Patched Versions: 5.4.13

Mitigation steps: Update to Advanced File Manager version 5.4.13 or greater.


Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field
CVE: CVE-2026-18385
Number of Installations: 100,000+
Affected Software: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content ≤ 4.16.19
Patched Versions: 4.17.0

Mitigation steps: Update to Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content version 4.17.0 or greater.


GiveWP – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-73352
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.5.1
Patched Versions: 4.16.6

Mitigation steps: Update to GiveWP version 4.16.6 or greater.


ECS – Missing Authorization to Unauthenticated Private Content Disclosure

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Private Content Disclosure
CVE: CVE-2026-14229
Number of Installations: 100,000+
Affected Software: ECS ≤ 4.3.7
Patched Versions: 4.3.8

Mitigation steps: Update to ECS version 4.3.8 or greater.


GiveWP – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-73349
Number of Installations: 100,000+
Affected Software: GiveWP < 4.16.6
Patched Versions: 4.16.6

Mitigation steps: Update to GiveWP version 4.16.6 or greater.


Element Pack Addons for Elementor – Unauthenticated SMTP Header Injection

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SMTP Header Injection
CVE: CVE-2026-0673
Number of Installations: 100,000+
Affected Software: Element Pack Addons for Elementor ≤ 8.3.15
Patched Versions: 8.3.16

Mitigation steps: Update to Element Pack Addons for Elementor version 8.3.16 or greater.


CAPTCHA 4WP – CAPTCHA Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: CAPTCHA Bypass
CVE: CVE-2026-32469
Number of Installations: 100,000+
Affected Software: CAPTCHA 4WP ≤ 7.6.0
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Mercado Pago payments for WooCommerce – Unauthenticated Insecure Direct Object Reference

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-28180
Number of Installations: 100,000+
Affected Software: Mercado Pago payments for WooCommerce ≤ 8.9.0
Patched Versions: 8.9.1

Mitigation steps: Update to Mercado Pago payments for WooCommerce version 8.9.1 or greater.


WP Ghost (Hide My WP Ghost) – IP Spoofing to Protection Mechanism Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: IP Spoofing to Protection Mechanism Bypass
CVE: CVE-2026-11870
Number of Installations: 100,000+
Affected Software: WP Ghost (Hide My WP Ghost) < 7.0.05
Patched Versions: 7.0.05

Mitigation steps: Update to WP Ghost (Hide My WP Ghost) version 7.0.05 or greater.


GiveWP – Unauthenticated Payment Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Payment Bypass
CVE: CVE-2026-14317
Number of Installations: 100,000+
Affected Software: GiveWP < 4.16.3
Patched Versions: 4.16.3

Mitigation steps: Update to GiveWP version 4.16.3 or greater.


AI Engine – Insecure Direct Object Reference to Unauthenticated Cross-Session Chatbot File Deletion

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Insecure Direct Object Reference to Unauthenticated Cross-Session Chatbot File Deletion
CVE: CVE-2026-16953
Number of Installations: 100,000+
Affected Software: AI Engine ≤ 3.6.3
Patched Versions: 3.6.4

Mitigation steps: Update to AI Engine version 3.6.4 or greater.


AI Engine – Authenticated (Administrator+) Privilege Escalation

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Privilege Escalation
CVE: CVE-2026-75796
Number of Installations: 100,000+
Affected Software: AI Engine ≤ 3.6.0
Patched Versions: 3.6.1

Mitigation steps: Update to AI Engine version 3.6.1 or greater.


FiboSearch – Authenticated (Shop manager+) Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: Requires Shop manager or higher level authentication.
Vulnerability: Authenticated (Shop manager+) Stored Cross-Site Scripting
CVE: CVE-2026-28179
Number of Installations: 100,000+
Affected Software: FiboSearch ≤ 1.33.0
Patched Versions: 1.34.0

Mitigation steps: Update to FiboSearch version 1.34.0 or greater.


DTX – Authenticated (Editor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting
CVE: CVE-2026-5116
Number of Installations: 100,000+
Affected Software: DTX ≤ 5.0.5
Patched Versions: 5.0.6

Mitigation steps: Update to DTX version 5.0.6 or greater.


ECS – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-19613
Number of Installations: 100,000+
Affected Software: ECS < 4.3.10
Patched Versions: 4.3.10

Mitigation steps: Update to ECS version 4.3.10 or greater.


Advanced File Manager – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-11565
Number of Installations: 100,000+
Affected Software: Advanced File Manager ≤ 5.4.12
Patched Versions: 5.4.13

Mitigation steps: Update to Advanced File Manager version 5.4.13 or greater.


Kadence WooCommerce Email Designer – Unauthenticated Privilege Escalation

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-28005
Number of Installations: 90,000+
Affected Software: Kadence WooCommerce Email Designer ≤ 1.5.19
Patched Versions: 1.5.19.1

Mitigation steps: Update to Kadence WooCommerce Email Designer version 1.5.19.1 or greater.


Booking for Appointments and Events Calendar – Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission
CVE: CVE-2026-6286
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar ≤ 2.2
Patched Versions: 2.2.1

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.2.1 or greater.


OttoKit: All-in-One Automation Platform – Unauthenticated Server-Side Request Forgery

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Server-Side Request Forgery
CVE: CVE-2026-32553
Number of Installations: 90,000+
Affected Software: OttoKit: All-in-One Automation Platform ≤ 1.1.35
Patched Versions: 1.1.36

Mitigation steps: Update to OttoKit: All-in-One Automation Platform version 1.1.36 or greater.


ShopLentor – Authenticated (Administrator+) Arbitrary Function Execution via ‘callback’ Parameter via REST API

Security Risk: High
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
CVE: CVE-2026-6020
Number of Installations: 90,000+
Affected Software: ShopLentor ≤ 3.3.7
Patched Versions: 3.3.8

Mitigation steps: Update to ShopLentor version 3.3.8 or greater.


Everest Forms – Unauthenticated Server-Side Request Forgery via Upload Field ‘Previous Value’

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'
CVE: CVE-2026-5096
Number of Installations: 90,000+
Affected Software: Everest Forms ≤ 3.4.4
Patched Versions: 3.4.5

Mitigation steps: Update to Everest Forms version 3.4.5 or greater.


Event Tickets and Registration – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-14822
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration < 5.29.0.1
Patched Versions: 5.29.0.1

Mitigation steps: Update to Event Tickets and Registration version 5.29.0.1 or greater.


Everest Forms – Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints

Security Risk: Medium
Exploitation Level: Requires Delegated or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints
CVE: CVE-2026-13167
Number of Installations: 90,000+
Affected Software: Everest Forms ≤ 3.5.2
Patched Versions: 3.5.3

Mitigation steps: Update to Everest Forms version 3.5.3 or greater.


Booking for Appointments and Events Calendar – Authenticated (Provider+) Information Exposure

Security Risk: Medium
Exploitation Level: Requires Provider (custom role) or higher level authentication.
Vulnerability: Authenticated (Provider+) Information Exposure
CVE: CVE-2026-14213
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar < 2.4.6
Patched Versions: 2.4.6

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.6 or greater.


Booking for Appointments and Events Calendar – Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure

Security Risk: TBC
Exploitation Level: Requires Provider or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure
CVE: CVE-2026-14211
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar ≤ 9.6
Patched Versions: 9.7

Mitigation steps: Update to Booking for Appointments and Events Calendar version 9.7 or greater.


Advanced Custom Fields: Font Awesome Field – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-66678
Number of Installations: 90,000+
Affected Software: Advanced Custom Fields: Font Awesome Field ≤ 6.1.2
Patched Versions: 6.1.3

Mitigation steps: Update to Advanced Custom Fields: Font Awesome Field version 6.1.3 or greater.


Event Tickets and Registration – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-14823
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration < 5.29.0.1
Patched Versions: 5.29.0.1

Mitigation steps: Update to Event Tickets and Registration version 5.29.0.1 or greater.


Booking for Appointments and Events Calendar – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Manager (custom role) or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-14214
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar < 2.4.4
Patched Versions: 2.4.4

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.4 or greater.


Mailgun for WordPress – Unauthenticated Server-Side Request Forgery (SSRF) via ‘addresses’ Array Keys

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys
CVE: CVE-2026-78003
Number of Installations: 80,000+
Affected Software: Mailgun for WordPress ≤ 2.2.0
Patched Versions: 2.2.1

Mitigation steps: Update to Mailgun for WordPress version 2.2.1 or greater.


Ajax Search Lite – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-28139
Number of Installations: 80,000+
Affected Software: Ajax Search Lite ≤ 4.14.4
Patched Versions: 4.14.5

Mitigation steps: Update to Ajax Search Lite version 4.14.5 or greater.


Ajax Search Lite – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-16258
Number of Installations: 80,000+
Affected Software: Ajax Search Lite ≤ 4.14.4
Patched Versions: 4.14.5

Mitigation steps: Update to Ajax Search Lite version 4.14.5 or greater.


Depicter – Unauthenticated SQL Injection

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-66622
Number of Installations: 80,000+
Affected Software: Depicter ≤ 4.8.0
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Customer Reviews for WooCommerce – Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form
CVE: CVE-2026-6176
Number of Installations: 80,000+
Affected Software: Customer Reviews for WooCommerce ≤ 5.106.0
Patched Versions: 5.107.0

Mitigation steps: Update to Customer Reviews for WooCommerce version 5.107.0 or greater.


Depicter – Authenticated (Editor+) Arbitrary File Upload

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Arbitrary File Upload
CVE: CVE-2026-15049
Number of Installations: 80,000+
Affected Software: Depicter < 4.8.0
Patched Versions: 4.8.0

Mitigation steps: Update to Depicter version 4.8.0 or greater.


Backup Migration – Authenticated (Administrator+) OS Command Injection via ‘file’ Parameter

Security Risk: High
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) OS Command Injection via 'file' Parameter
CVE: CVE-2026-7693
Number of Installations: 80,000+
Affected Software: Backup Migration ≤ 2.1.1
Patched Versions: 2.1.5.2

Mitigation steps: Update to Backup Migration version 2.1.5.2 or greater.


Product Feed Manager for WooCommerce – Authenticated (Shop Manager+) Remote Code Execution

Security Risk: TBC
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) Remote Code Execution
CVE: CVE-2026-66709
Number of Installations: 80,000+
Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.42
Patched Versions: 6.6.43

Mitigation steps: Update to Product Feed Manager for WooCommerce version 6.6.43 or greater.


Stream – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API
CVE: CVE-2026-11907
Number of Installations: 80,000+
Affected Software: Stream ≤ 4.2.0
Patched Versions: 4.2.1

Mitigation steps: Update to Stream version 4.2.1 or greater.


GutenKit – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-19697
Number of Installations: 80,000+
Affected Software: GutenKit < 2.5.0
Patched Versions: 2.5.0

Mitigation steps: Update to GutenKit version 2.5.0 or greater.


SureCart – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-32548
Number of Installations: 80,000+
Affected Software: SureCart ≤ 4.6.2
Patched Versions: 4.6.3

Mitigation steps: Update to SureCart version 4.6.3 or greater.


JetFormBuilder – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-28140
Number of Installations: 80,000+
Affected Software: JetFormBuilder ≤ 3.6.4.1
Patched Versions: 3.6.4.2

Mitigation steps: Update to JetFormBuilder version 3.6.4.2 or greater.


Download Monitor – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-16608
Number of Installations: 80,000+
Affected Software: Download Monitor ≤ 5.2.5
Patched Versions: 5.2.6

Mitigation steps: Update to Download Monitor version 5.2.6 or greater.


Product Feed Manager for WooCommerce – Authenticated (Shop Manager+) Arbitrary File Downloaf

Security Risk: Medium
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) Arbitrary File Downloaf
CVE: CVE-2026-73383
Number of Installations: 80,000+
Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.46
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Advanced Excerpt – Authenticated (Administrator+) Stored Cross-Site Scripting

Security Risk: Minimal
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting
CVE: CVE-2026-13701
Number of Installations: 80,000+
Affected Software: Advanced Excerpt ≤ 4.4
Patched Versions: 4.5

Mitigation steps: Update to Advanced Excerpt version 4.5 or greater.


GutenKit – Authenticated (Contributor+) Information Exposure

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Information Exposure
CVE: CVE-2026-19699
Number of Installations: 80,000+
Affected Software: GutenKit ≤ 2.4.15
Patched Versions: 2.5.0

Mitigation steps: Update to GutenKit version 2.5.0 or greater.


Kubio AI Page Builder – Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action
CVE: CVE-2026-16779
Number of Installations: 80,000+
Affected Software: Kubio AI Page Builder ≤ 2.8.5
Patched Versions: 2.8.6

Mitigation steps: Update to Kubio AI Page Builder version 2.8.6 or greater.


Customer Reviews for WooCommerce – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-14941
Number of Installations: 80,000+
Affected Software: Customer Reviews for WooCommerce ≤ 5.115.0
Patched Versions: 5.116.0

Mitigation steps: Update to Customer Reviews for WooCommerce version 5.116.0 or greater.


Media Library Assistant – Authenticated (Author+) Arbitrary File Upload

Security Risk: High
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Arbitrary File Upload
CVE: CVE-2026-66600
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.39
Patched Versions: 3.40

Mitigation steps: Update to Media Library Assistant version 3.40 or greater.


Events Manager – Unauthenticated Privilege Escalation

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-18366
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.4.0
Patched Versions: 7.4.1

Mitigation steps: Update to Events Manager version 7.4.1 or greater.


wpDataTables – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66597
Number of Installations: 70,000+
Affected Software: wpDataTables ≤ 6.5.1.4
Patched Versions: 6.5.1.5

Mitigation steps: Update to wpDataTables version 6.5.1.5 or greater.


10Web Booster – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-14287
Number of Installations: 70,000+
Affected Software: 10Web Booster ≤ 2.33.4
Patched Versions: 2.33.5

Mitigation steps: Update to 10Web Booster version 2.33.5 or greater.


Media Library Assistant – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-61963
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.38
Patched Versions: 3.39

Mitigation steps: Update to Media Library Assistant version 3.39 or greater.


Events Manager – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66457
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.4.2
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Ninja Tables – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-61964
Number of Installations: 70,000+
Affected Software: Ninja Tables ≤ 5.2.9
Patched Versions: 5.2.10

Mitigation steps: Update to Ninja Tables version 5.2.10 or greater.


Events Manager – Authenticated (Administrator+) Local File Inclusion via ‘dbem_data[updates]’ Array Keys

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys
CVE: CVE-2026-14280
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.3.7.4
Patched Versions: 7.4

Mitigation steps: Update to Events Manager version 7.4 or greater.


Events Manager – Authenticated (Contributor+) SQL Injection via ‘meta_key’ Parameter in Event/Location Duplicate Action

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action
CVE: CVE-2026-15023
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.4.0
Patched Versions: 7.4.1

Mitigation steps: Update to Events Manager version 7.4.1 or greater.


Media Library Assistant – Authenticated (Author+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) SQL Injection
CVE: CVE-2026-16959
Number of Installations: 70,000+
Affected Software: Media Library Assistant < 3.40
Patched Versions: 3.40

Mitigation steps: Update to Media Library Assistant version 3.40 or greater.


Events Manager – Authenticated (Subscriber+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) SQL Injection
CVE: CVE-2026-18057
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.4.0
Patched Versions: 7.4.1

Mitigation steps: Update to Events Manager version 7.4.1 or greater.


Greenshift – Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI
CVE: CVE-2026-5092
Number of Installations: 70,000+
Affected Software: Greenshift ≤ 12.8.9
Patched Versions: 12.9.0

Mitigation steps: Update to Greenshift version 12.9.0 or greater.


Media Library Assistant – Authenticated (Subscriber+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE: CVE-2026-66601
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.39
Patched Versions: 3.40

Mitigation steps: Update to Media Library Assistant version 3.40 or greater.


Media Library Assistant – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-66591
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.39
Patched Versions: 3.40

Mitigation steps: Update to Media Library Assistant version 3.40 or greater.


Featured Image from URL (FIFU) – Authenticated (Contributor+) Stored Cross-site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-site Scripting
CVE: CVE-2026-73340
Number of Installations: 70,000+
Affected Software: Featured Image from URL (FIFU) ≤ 5.3.3
Patched Versions: 6.0.0

Mitigation steps: Update to Featured Image from URL (FIFU) version 6.0.0 or greater.


Easy Accordion – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘accordionTitleTag’ Block Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute
CVE: CVE-2026-18988
Number of Installations: 70,000+
Affected Software: Easy Accordion ≤ 3.1.8
Patched Versions: 3.1.9

Mitigation steps: Update to Easy Accordion version 3.1.9 or greater.


LearnPress – Authenticated (Instructor+) Server-Side Request Forgery

Security Risk: Low
Exploitation Level: Requires Instructor or higher level authentication.
Vulnerability: Authenticated (Instructor+) Server-Side Request Forgery
CVE: CVE-2026-12971
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.3
Patched Versions: 4.4.4

Mitigation steps: Update to LearnPress version 4.4.4 or greater.


Events Manager – Reflected Cross-Site Scripting via ‘header_format’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'header_format' Parameter
CVE: CVE-2026-17089
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.4.0.1
Patched Versions: 7.4.1

Mitigation steps: Update to Events Manager version 7.4.1 or greater.


Events Manager – Missing Authorization to Unauthenticated Sensitive Information Disclosure via ‘status’, ‘private’, and ‘private_only’ Parameters

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters
CVE: CVE-2026-10627
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.4.0
Patched Versions: 7.4.1

Mitigation steps: Update to Events Manager version 7.4.1 or greater.


kk Star Ratings – Unauthenticated Arbitrary Shortcode Execution via ‘payload’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter
CVE: CVE-2026-3424
Number of Installations: 70,000+
Affected Software: kk Star Ratings ≤ 5.4.10.3
Patched Versions: 5.4.10.4

Mitigation steps: Update to kk Star Ratings version 5.4.10.4 or greater.


LearnPress – Authenticated (Administrator+) SQL Injection via ‘orderby’ Parameter

Security Risk: Medium
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVE: CVE-2026-77823
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.4
Patched Versions: 4.4.5

Mitigation steps: Update to LearnPress version 4.4.5 or greater.


LearnPress – Missing Authorization to Authenticated (Editor+) Limited Option Update via ‘field_name’ Parameter

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter
CVE: CVE-2026-75982
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.4
Patched Versions: 4.4.5

Mitigation steps: Update to LearnPress version 4.4.5 or greater.


Greenshift – Authenticated (Contributor+) Theme Settings Modification via ‘gspb_update_global_wp_settings’

Security Risk: Low
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings'
CVE: CVE-2026-5093
Number of Installations: 70,000+
Affected Software: Greenshift ≤ 12.8.9
Patched Versions: 12.9.0

Mitigation steps: Update to Greenshift version 12.9.0 or greater.


LearnPress – Authenticated (Subscriber+) Information Exposure

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-12976
Number of Installations: 70,000+
Affected Software: LearnPress < 4.4.4
Patched Versions: 4.4.4

Mitigation steps: Update to LearnPress version 4.4.4 or greater.


Slim SEO – Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Meta Disclosure

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Meta Disclosure
CVE: CVE-2026-16957
Number of Installations: 70,000+
Affected Software: Slim SEO ≤ 4.9.10
Patched Versions: 4.9.11

Mitigation steps: Update to Slim SEO version 4.9.11 or greater.


Brizy – Authenticated (Contributor+) Information Exposure

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Information Exposure
CVE: CVE-2026-14195
Number of Installations: 70,000+
Affected Software: Brizy < 2.8.18
Patched Versions: 2.8.18

Mitigation steps: Update to Brizy version 2.8.18 or greater.


Drag and Drop Multiple File Upload for Contact Form 7 – Unauthenticated Remote Code Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Remote Code Execution
CVE: CVE-2026-18781
Number of Installations: 60,000+
Affected Software: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9
Patched Versions: 1.3.9.9

Mitigation steps: Update to Drag and Drop Multiple File Upload for Contact Form 7 version 1.3.9.9 or greater.


Online Scheduling and Appointment Booking System – Unauthenticated SQL Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-13395
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System < 27.8
Patched Versions: 27.8

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 27.8 or greater.


Ultimate Dashboard – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66621
Number of Installations: 60,000+
Affected Software: Ultimate Dashboard ≤ 3.11.2
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Online Scheduling and Appointment Booking System – Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action
CVE: CVE-2026-13424
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 27.7
Patched Versions: 28.0

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.0 or greater.


Site Reviews – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-73382
Number of Installations: 60,000+
Affected Software: Site Reviews ≤ 8.2.0
Patched Versions: 8.2.1

Mitigation steps: Update to Site Reviews version 8.2.1 or greater.


Simply Schedule Appointments – Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure
CVE: CVE-2026-13358
Number of Installations: 60,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.10
Patched Versions: 1.6.12.11

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.11 or greater.


WP Maps – Authenticated (Subscriber+) Denial of Service

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Denial of Service
CVE: CVE-2026-16265
Number of Installations: 60,000+
Affected Software: WP Maps ≤ 4.9.6
Patched Versions: 4.9.7

Mitigation steps: Update to WP Maps version 4.9.7 or greater.


Ultra Addons for Contact Form 7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes
CVE: CVE-2026-12801
Number of Installations: 60,000+
Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.43
Patched Versions: 3.5.44

Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.44 or greater.


Simply Schedule Appointments – Unauthenticated Insecure Direct Object Reference

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-16540
Number of Installations: 60,000+
Affected Software: Simply Schedule Appointments < 1.6.12.6
Patched Versions: 1.6.12.6

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.6 or greater.


Drag and Drop Multiple File Upload for Contact Form 7 – Authenticated (Administrator+) Stored Cross-Site Scripting

Security Risk: Minimal
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting
CVE: CVE-2026-14325
Number of Installations: 60,000+
Affected Software: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9
Patched Versions: 1.3.9.9

Mitigation steps: Update to Drag and Drop Multiple File Upload for Contact Form 7 version 1.3.9.9 or greater.


WP Maps – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-18466
Number of Installations: 60,000+
Affected Software: WP Maps < 4.9.8
Patched Versions: 4.9.8

Mitigation steps: Update to WP Maps version 4.9.8 or greater.


Online Scheduling and Appointment Booking System – Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via ‘params[id]’ Parameter

Security Risk: Medium
Exploitation Level: Requires Staff or higher level authentication.
Vulnerability: Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter
CVE: CVE-2026-12905
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 27.7
Patched Versions: 28.0

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.0 or greater.


Advanced Product Fields (Product Addons) for WooCommerce – Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request
CVE: CVE-2026-2996
Number of Installations: 50,000+
Affected Software: Advanced Product Fields (Product Addons) for WooCommerce ≤ 1.6.21
Patched Versions: 1.6.22

Mitigation steps: Update to Advanced Product Fields (Product Addons) for WooCommerce version 1.6.22 or greater.


Advanced AJAX Product Filters – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-66439
Number of Installations: 50,000+
Affected Software: Advanced AJAX Product Filters ≤ 3.2.0.3
Patched Versions: 3.2.1

Mitigation steps: Update to Advanced AJAX Product Filters version 3.2.1 or greater.


OptionTree – Authenticated (Editor+) PHP Object Injection

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) PHP Object Injection
CVE: CVE-2026-66620
Number of Installations: 50,000+
Affected Software: OptionTree ≤ 2.7.3
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels – Authenticated (Subscriber+) Arbitrary File Read via ‘customer_note’ Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter
CVE: CVE-2026-18027
Number of Installations: 50,000+
Affected Software: WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels ≤ 4.9.8
Patched Versions: 5.0.0

Mitigation steps: Update to WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels version 5.0.0 or greater.


Exclusive Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘exad_infobox_image’

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image'
CVE: CVE-2026-12231
Number of Installations: 50,000+
Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.8
Patched Versions: 2.7.9.9

Mitigation steps: Update to Exclusive Addons for Elementor version 2.7.9.9 or greater.


Seraphinite Accelerator – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-17532
Number of Installations: 50,000+
Affected Software: Seraphinite Accelerator ≤ 2.29.18
Patched Versions: 2.29.19

Mitigation steps: Update to Seraphinite Accelerator version 2.29.19 or greater.


Total Upkeep – Unauthenticated Information Exposure

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-16253
Number of Installations: 50,000+
Affected Software: Total Upkeep < 1.17.3
Patched Versions: 1.17.3

Mitigation steps: Update to Total Upkeep version 1.17.3 or greater.


User Registration & Membership – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-73403
Number of Installations: 50,000+
Affected Software: User Registration & Membership ≤ 5.2.6
Patched Versions: 5.2.7

Mitigation steps: Update to User Registration & Membership version 5.2.7 or greater.


Total Upkeep – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-66708
Number of Installations: 50,000+
Affected Software: Total Upkeep ≤ 1.17.2
Patched Versions: 1.17.3

Mitigation steps: Update to Total Upkeep version 1.17.3 or greater.


Clearfy Cache – Authenticated (Subscriber+) Information Exposure

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-16295
Number of Installations: 50,000+
Affected Software: Clearfy Cache < 2.4.3
Patched Versions: 2.4.3

Mitigation steps: Update to Clearfy Cache version 2.4.3 or greater.


Update your website software to reduce risk. Users unable to upgrade to the latest version are advised to implement a web application firewall, which can virtually patch known vulnerabilities and safeguard their website.

Chat with Sucuri

You May Also Like