If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.
To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.
For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.
Plugins
LiteSpeed Cache – Unauthenticated Stored Cross-Site Scripting via Comment Content
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-18978 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.8.1 Patched Versions: 7.9
Mitigation steps: Update to LiteSpeed Cache version 7.9 or greater.
LiteSpeed Cache – Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes CVE: CVE-2026-3129 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.7 Patched Versions: 7.8
Mitigation steps: Update to LiteSpeed Cache version 7.8 or greater.
All-in-One WP Migration and Backup – Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution CVE: CVE-2026-19949 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.109 Patched Versions: 7.110
Mitigation steps: Update to All-in-One WP Migration and Backup version 7.110 or greater.
All-in-One WP Migration and Backup – Authenticated (Administrator+) Remote Code Execution
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Remote Code Execution CVE: CVE-2026-17533 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup < 7.108 Patched Versions: 7.108
Mitigation steps: Update to All-in-One WP Migration and Backup version 7.108 or greater.
Essential Addons for Elementor – Unauthenticated Privilege Escalation
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-18039 Number of Installations: 1,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.7.1 Patched Versions: 6.7.2
Mitigation steps: Update to Essential Addons for Elementor version 6.7.2 or greater.
WP Fastest Cache – Unauthenticated Stored Cross-Site Scripting via HTTP Host Header
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via HTTP Host Header CVE: CVE-2026-19760 Number of Installations: 1,000,000+ Affected Software: WP Fastest Cache ≤ 1.5.0 Patched Versions: 1.5.1
Mitigation steps: Update to WP Fastest Cache version 1.5.1 or greater.
ElementsKit Elementor Addons – Authenticated (Admin+) Remote Code Execution
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Remote Code Execution CVE: CVE-2026-13392 Number of Installations: 1,000,000+ Affected Software: ElementsKit Elementor Addons < 3.10.01 Patched Versions: 3.10.01
Mitigation steps: Update to ElementsKit Elementor Addons version 3.10.01 or greater.
MC4WP: Mailchimp for WordPress – Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages CVE: CVE-2026-4561 Number of Installations: 1,000,000+ Affected Software: MC4WP: Mailchimp for WordPress ≤ 4.12.0 Patched Versions: 4.12.1
Mitigation steps: Update to MC4WP: Mailchimp for WordPress version 4.12.1 or greater.
EWWW Image Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘data-script’ Lazy Load Attribute in Post Content
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content CVE: CVE-2026-15446 Number of Installations: 1,000,000+ Affected Software: EWWW Image Optimizer ≤ 8.7.3 Patched Versions: 8.7.4
Mitigation steps: Update to EWWW Image Optimizer version 8.7.4 or greater.
Speed Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes CVE: CVE-2026-15421 Number of Installations: 1,000,000+ Affected Software: Speed Optimizer ≤ 7.8.0 Patched Versions: 7.8.1
Mitigation steps: Update to Speed Optimizer version 7.8.1 or greater.
Loco Translate – Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments
Security Risk: High Exploitation Level: Requires Translator or higher level authentication. Vulnerability: Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments CVE: CVE-2026-15066 Number of Installations: 1,000,000+ Affected Software: Loco Translate ≤ 2.8.7 Patched Versions: 2.8.8
Mitigation steps: Update to Loco Translate version 2.8.8 or greater.
AI Agent by SiteGround – Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint CVE: CVE-2026-17153 Number of Installations: 1,000,000+ Affected Software: AI Agent by SiteGround ≤ 1.2.7 Patched Versions: 1.2.8
Mitigation steps: Update to AI Agent by SiteGround version 1.2.8 or greater.
Smash Balloon Social Photo Feed – Reflected Cross-Site Scripting via REQUEST_URI Query String
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via REQUEST_URI Query String CVE: CVE-2026-15452 Number of Installations: 1,000,000+ Affected Software: Smash Balloon Social Photo Feed ≤ 6.11.3 Patched Versions: 6.11.4
Mitigation steps: Update to Smash Balloon Social Photo Feed version 6.11.4 or greater.
W3 Total Cache – Unauthenticated Path Traversal
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Path Traversal CVE: CVE-2026-18051 Number of Installations: 900,000+ Affected Software: W3 Total Cache < 2.10.5 Patched Versions: 2.10.5
Mitigation steps: Update to W3 Total Cache version 2.10.5 or greater.
WPvivid – Unauthenticated Path Traversal
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Path Traversal CVE: CVE-2026-19725 Number of Installations: 900,000+ Affected Software: WPvivid < 0.9.131 Patched Versions: 0.9.131
Mitigation steps: Update to WPvivid version 0.9.131 or greater.
W3 Total Cache – Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Author Name CVE: CVE-2026-18109 Number of Installations: 900,000+ Affected Software: W3 Total Cache ≤ 2.10.3 Patched Versions: 2.10.4
Mitigation steps: Update to W3 Total Cache version 2.10.4 or greater.
Smart Slider 3 – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘slider’ Block Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute CVE: CVE-2026-15798 Number of Installations: 800,000+ Affected Software: Smart Slider 3 ≤ 3.5.1.38 Patched Versions: 3.5.1.39
Mitigation steps: Update to Smart Slider 3 version 3.5.1.39 or greater.
Fluent Forms – Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values CVE: CVE-2026-18146 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.11 Patched Versions: 6.2.12
Mitigation steps: Update to Fluent Forms version 6.2.12 or greater.
Popup Maker – Unauthenticated Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-28177 Number of Installations: 700,000+ Affected Software: Popup Maker ≤ 1.23.0 Patched Versions: 1.24.0
Mitigation steps: Update to Popup Maker version 1.24.0 or greater.
Fluent Forms – Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion
Security Risk: High Exploitation Level: Requires Form Manager or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion CVE: CVE-2026-11578 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.4 Patched Versions: 6.2.5
Mitigation steps: Update to Fluent Forms version 6.2.5 or greater.
Fluent Forms – Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation CVE: CVE-2026-11880 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.0 Patched Versions: 6.2.1
Mitigation steps: Update to Fluent Forms version 6.2.1 or greater.
Forminator Forms – Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration CVE: CVE-2026-15748 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.1 Patched Versions: 1.56.2
Mitigation steps: Update to Forminator Forms version 1.56.2 or greater.
Royal Addons for Elementor – Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget ‘webhook_url’ Setting
Security Risk: High Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting CVE: CVE-2026-17123 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor ≤ 1.7.1064 Patched Versions: 1.7.1065
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1065 or greater.
Forminator Forms – Authenticated (Contributor+) Privilege Escalation
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Privilege Escalation CVE: CVE-2026-28111 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.0 Patched Versions: 1.56.0.1
Mitigation steps: Update to Forminator Forms version 1.56.0.1 or greater.
Forminator Forms – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-66583 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0 Patched Versions: 1.57.1
Mitigation steps: Update to Forminator Forms version 1.57.1 or greater.
Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field CVE: CVE-2026-18324 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0.1 Patched Versions: 1.57.0.2
Mitigation steps: Update to Forminator Forms version 1.57.0.2 or greater.
Forminator Forms – Unauthenticated DOM-Based Cross-Site Scripting via ‘error_description’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter CVE: CVE-2026-18328 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0 Patched Versions: 1.57.0.1
Mitigation steps: Update to Forminator Forms version 1.57.0.1 or greater.
Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) CVE: CVE-2026-18323 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0.2 Patched Versions: 1.57.0.3
Mitigation steps: Update to Forminator Forms version 1.57.0.3 or greater.
Royal Addons for Elementor – Authenticated (Administrator+) Remote Code Execution
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Remote Code Execution CVE: CVE-2026-13405 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor < 1.7.1066 Patched Versions: 1.7.1066
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1066 or greater.
WP Statistics – Unauthenticated Stored Cross-Site Scripting via ‘utm_campaign’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter CVE: CVE-2026-15780 Number of Installations: 600,000+ Affected Software: WP Statistics ≤ 14.16.8 Patched Versions: 14.16.9
Mitigation steps: Update to WP Statistics version 14.16.9 or greater.
SiteGuard WP Plugin – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61982 Number of Installations: 600,000+ Affected Software: SiteGuard WP Plugin ≤ 1.8.6 Patched Versions: 1.8.7
Mitigation steps: Update to SiteGuard WP Plugin version 1.8.7 or greater.
FluentSMTP – Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs CVE: CVE-2026-16636 Number of Installations: 600,000+ Affected Software: FluentSMTP ≤ 2.2.95 Patched Versions: 2.3.0
Mitigation steps: Update to FluentSMTP version 2.3.0 or greater.
Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field CVE: CVE-2026-18325 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.1 Patched Versions: 1.56.2
Mitigation steps: Update to Forminator Forms version 1.56.2 or greater.
Forminator Forms – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-28143 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.0 Patched Versions: 1.56.1
Mitigation steps: Update to Forminator Forms version 1.56.1 or greater.
MetForm – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘mf_form_id’ Widget Setting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting CVE: CVE-2026-18100 Number of Installations: 600,000+ Affected Software: MetForm ≤ 4.1.8 Patched Versions: 4.1.9
Mitigation steps: Update to MetForm version 4.1.9 or greater.
Royal Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-19217 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor ≤ 1.7.1064 Patched Versions: 1.7.1065
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1065 or greater.
Forminator Forms – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via ‘draft’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter CVE: CVE-2026-12998 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.55.0.2 Patched Versions: 1.55.1
Mitigation steps: Update to Forminator Forms version 1.55.1 or greater.
WP Statistics – Authenticated (Subscriber+) Information Exposure
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-16562 Number of Installations: 600,000+ Affected Software: WP Statistics ≤ 14.16.9 Patched Versions: 14.16.10
Mitigation steps: Update to WP Statistics version 14.16.10 or greater.
Kirki – Unauthenticated Remote Code Execution
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution CVE: CVE-2026-16747 Number of Installations: 500,000+ Affected Software: Kirki < 6.2.1 Patched Versions: 6.2.1
Mitigation steps: Update to Kirki version 6.2.1 or greater.
Broken Link Checker – Unauthenticated Remote Code Execution
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution CVE: CVE-2026-18937 Number of Installations: 500,000+ Affected Software: Broken Link Checker < 2.4.12 Patched Versions: 2.4.12
Mitigation steps: Update to Broken Link Checker version 2.4.12 or greater.
Kirki – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-12720 Number of Installations: 500,000+ Affected Software: Kirki < 6.0.13 Patched Versions: 6.0.13
Mitigation steps: Update to Kirki version 6.0.13 or greater.
Kirki – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66629 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.2.4 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Kirki – Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode CVE: CVE-2026-16974 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.2.0 Patched Versions: 6.2.1
Mitigation steps: Update to Kirki version 6.2.1 or greater.
Slider, Gallery, and Carousel by MetaSlider – Authenticated (Author+) Stored Cross-Site Scripting via ‘delay’ Post Meta Setting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting CVE: CVE-2026-18400 Number of Installations: 500,000+ Affected Software: Slider, Gallery, and Carousel by MetaSlider ≤ 3.111.0 Patched Versions: 3.111.1
Mitigation steps: Update to Slider, Gallery, and Carousel by MetaSlider version 3.111.1 or greater.
Kirki – Authenticated (Editor+) Path Traversal to Arbitrary File Read via ‘data’ Parameter
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter CVE: CVE-2026-17604 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.1.1 Patched Versions: 6.2.0
Mitigation steps: Update to Kirki version 6.2.0 or greater.
Kirki – Authenticated (Editor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting CVE: CVE-2026-74992 Number of Installations: 500,000+ Affected Software: Kirki < 6.2.3 Patched Versions: 6.2.3
Mitigation steps: Update to Kirki version 6.2.3 or greater.
Kirki – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via ‘context’ Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter CVE: CVE-2026-18347 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.1.1 Patched Versions: 6.2.0
Mitigation steps: Update to Kirki version 6.2.0 or greater.
Meta Box – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-15248 Number of Installations: 500,000+ Affected Software: Meta Box < 5.13.1 Patched Versions: 5.13.1
Mitigation steps: Update to Meta Box version 5.13.1 or greater.
TranslatePress – Unauthenticated Account Takeover via Password Reset Link Disclosure
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Account Takeover via Password Reset Link Disclosure CVE: CVE-2026-19632 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.1 Patched Versions: 3.3.2
Mitigation steps: Update to TranslatePress version 3.3.2 or greater.
TranslatePress – Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser CVE: CVE-2026-76053 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.3 Patched Versions: 3.3.4
Mitigation steps: Update to TranslatePress version 3.3.4 or greater.
TranslatePress – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66582 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.2 Patched Versions: 3.3.3
Mitigation steps: Update to TranslatePress version 3.3.3 or greater.
TranslatePress – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-75981 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.5 Patched Versions: 3.2.6
Mitigation steps: Update to TranslatePress version 3.2.6 or greater.
TranslatePress – Unauthenticated Stored Cross-Site Scripting via Comment Content
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-18510 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.6 Patched Versions: 3.3
Mitigation steps: Update to TranslatePress version 3.3 or greater.
TranslatePress – Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor CVE: CVE-2026-18512 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.6 Patched Versions: 3.3
Mitigation steps: Update to TranslatePress version 3.3 or greater.
TranslatePress – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-17505 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.5 Patched Versions: 3.2.6
Mitigation steps: Update to TranslatePress version 3.2.6 or greater.
Templately – Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch
Security Risk: High Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch CVE: CVE-2026-18438 Number of Installations: 300,000+ Affected Software: Templately ≤ 3.7.1 Patched Versions: 3.7.2
Mitigation steps: Update to Templately version 3.7.2 or greater.
WP Go Maps – Unauthenticated SQL Injection
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-15381 Number of Installations: 300,000+ Affected Software: WP Go Maps < 10.1.04 Patched Versions: 10.1.04
Mitigation steps: Update to WP Go Maps version 10.1.04 or greater.
Formidable Forms – Unauthenticated Stored Cross-Site Scripting via ‘frm_user_id’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter CVE: CVE-2026-18331 Number of Installations: 300,000+ Affected Software: Formidable Forms ≤ 6.33.1 Patched Versions: 6.34
Mitigation steps: Update to Formidable Forms version 6.34 or greater.
Templately – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66667 Number of Installations: 300,000+ Affected Software: Templately ≤ 3.7.1 Patched Versions: 3.7.2
Mitigation steps: Update to Templately version 3.7.2 or greater.
Photo Gallery, Sliders, Proofing and Themes – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-28141 Number of Installations: 300,000+ Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.2.3 Patched Versions: 4.2.4
Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.2.4 or greater.
Unlimited Elements For Elementor – Authenticated (Contributor+) Arbitrary File Download
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Arbitrary File Download CVE: CVE-2026-28146 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.14 Patched Versions: 2.0.15
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.15 or greater.
Blocksy Companion – Authenticated (Author+) Stored Cross-Site Scripting via ‘tagName’ Block Attribute (blocksy/dynamic-data)
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) CVE: CVE-2026-18488 Number of Installations: 300,000+ Affected Software: Blocksy Companion ≤ 2.1.51 Patched Versions: 2.1.52
Mitigation steps: Update to Blocksy Companion version 2.1.52 or greater.
Breeze Cache – Missing Authorization to Unauthenticated Arbitrary Content Deletion
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Arbitrary Content Deletion CVE: CVE-2026-73356 Number of Installations: 300,000+ Affected Software: Breeze Cache ≤ 2.5.12 Patched Versions: 2.5.13
Mitigation steps: Update to Breeze Cache version 2.5.13 or greater.
Ad Inserter – Missing Authorization to Block Visibility Bypass via ai_ajax
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Block Visibility Bypass via ai_ajax CVE: CVE-2026-11983 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.16 Patched Versions: 2.8.17
Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.
Templately – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-15359 Number of Installations: 300,000+ Affected Software: Templately ≤ 3.7.0 Patched Versions: 3.7.1
Mitigation steps: Update to Templately version 3.7.1 or greater.
Password Protected – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-14943 Number of Installations: 300,000+ Affected Software: Password Protected ≤ 2.8.3 Patched Versions: 2.8.4
Mitigation steps: Update to Password Protected version 2.8.4 or greater.
Duplicate Post – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-19085 Number of Installations: 300,000+ Affected Software: Duplicate Post < 1.5.6 Patched Versions: 1.5.6
Mitigation steps: Update to Duplicate Post version 1.5.6 or greater.
Unlimited Elements For Elementor – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-28147 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.15 Patched Versions: 2.0.16
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.16 or greater.
Ultimate Member – Unauthenticated Privilege Escalation
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-12251 Number of Installations: 200,000+ Affected Software: Ultimate Member < 2.12.1 Patched Versions: 2.12.1
Mitigation steps: Update to Ultimate Member version 2.12.1 or greater.
Optimole – Unauthenticated Stored Cross-Site Scripting via ‘a’ (above_fold_images) Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter CVE: CVE-2026-77365 Number of Installations: 200,000+ Affected Software: Optimole ≤ 4.2.10 Patched Versions: 4.2.11
Mitigation steps: Update to Optimole version 4.2.11 or greater.
Newsletter – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66596 Number of Installations: 200,000+ Affected Software: Newsletter ≤ 9.3.3 Patched Versions: 9.3.4
Mitigation steps: Update to Newsletter version 9.3.4 or greater.
Ultimate Member – Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute)
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) CVE: CVE-2026-18547 Number of Installations: 200,000+ Affected Software: Ultimate Member ≤ 2.12.1 Patched Versions: 2.13.0
Mitigation steps: Update to Ultimate Member version 2.13.0 or greater.
Admin and Site Enhancements (ASE) – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-19615 Number of Installations: 200,000+ Affected Software: Admin and Site Enhancements (ASE) < 9.0.1 Patched Versions: 9.0.1
Mitigation steps: Update to Admin and Site Enhancements (ASE) version 9.0.1 or greater.
Smash Balloon Social Post Feed – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘id’ Shortcode Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute CVE: CVE-2026-16775 Number of Installations: 200,000+ Affected Software: Smash Balloon Social Post Feed ≤ 4.9.0 Patched Versions: 4.10.0
Mitigation steps: Update to Smash Balloon Social Post Feed version 4.10.0 or greater.
Kadence Starter Templates – Unauthenticated Denial of Service
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-73997 Number of Installations: 200,000+ Affected Software: Kadence Starter Templates ≤ 2.3.3 Patched Versions: 2.3.4
Mitigation steps: Update to Kadence Starter Templates version 2.3.4 or greater.
Gutenberg Essential Blocks – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-13153 Number of Installations: 200,000+ Affected Software: Gutenberg Essential Blocks ≤ 6.3.0 Patched Versions: 6.4.0
Mitigation steps: Update to Gutenberg Essential Blocks version 6.4.0 or greater.
InfiniteWP Client – Authenticated (Administrator+) SQL Injection
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-74011 Number of Installations: 200,000+ Affected Software: InfiniteWP Client ≤ 1.13.9 Patched Versions: 1.13.10
Mitigation steps: Update to InfiniteWP Client version 1.13.10 or greater.
Mailchimp for WooCommerce – Authenticated (Administrator+) SQL Injection
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-73346 Number of Installations: 200,000+ Affected Software: Mailchimp for WooCommerce < 6.2 Patched Versions: 6.2
Mitigation steps: Update to Mailchimp for WooCommerce version 6.2 or greater.
PrettyLinks – Authenticated (Administrator+) SQL Injection via ‘s’ Parameter
Security Risk: Medium Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection via 's' Parameter CVE: CVE-2026-5062 Number of Installations: 200,000+ Affected Software: PrettyLinks ≤ 3.6.20 Patched Versions: 3.6.21
Mitigation steps: Update to PrettyLinks version 3.6.21 or greater.
Post Duplicator – Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution CVE: CVE-2026-4244 Number of Installations: 200,000+ Affected Software: Post Duplicator ≤ 3.0.11 Patched Versions: 3.0.12
Mitigation steps: Update to Post Duplicator version 3.0.12 or greater.
Post Duplicator – Authorization Bypass to Authenticated (Contributor+) Post Duplication
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authorization Bypass to Authenticated (Contributor+) Post Duplication CVE: CVE-2026-4245 Number of Installations: 200,000+ Affected Software: Post Duplicator ≤ 3.0.11 Patched Versions: 3.0.12
Mitigation steps: Update to Post Duplicator version 3.0.12 or greater.
GiveWP – Unauthenticated PHP Object Injection to Remote Code Execution
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection to Remote Code Execution CVE: CVE-2026-82222 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.7.1 Patched Versions: 4.16.7.2
Mitigation steps: Update to GiveWP version 4.16.7.2 or greater.
Pods – Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via ‘pods_admin’ AJAX Router
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router CVE: CVE-2026-19598 Number of Installations: 100,000+ Affected Software: Pods 2.8 - 2.8.23.3 Patched Versions: 3.3.9.1
Mitigation steps: Update to Pods version 3.3.9.1 or greater.
One User Avatar – Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter CVE: CVE-2026-18983 Number of Installations: 100,000+ Affected Software: One User Avatar ≤ 2.5.4 Patched Versions: 2.5.5
Mitigation steps: Update to One User Avatar version 2.5.5 or greater.
ShopEngine Elementor WooCommerce Builder Addon – Authenticated (Shop Manager+) Privilege Escalation to WXR Import ‘<wp_option>’ Nodes
Security Risk: High Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes CVE: CVE-2026-75971 Number of Installations: 100,000+ Affected Software: ShopEngine Elementor WooCommerce Builder Addon ≤ 4.9.4 Patched Versions: 4.9.5
Mitigation steps: Update to ShopEngine Elementor WooCommerce Builder Addon version 4.9.5 or greater.
Social Media Share Buttons & Social Sharing Icons – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66623 Number of Installations: 100,000+ Affected Software: Social Media Share Buttons & Social Sharing Icons ≤ 2.9.9 Patched Versions: 3.0.0
Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.0 or greater.
Download Manager – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-14292 Number of Installations: 100,000+ Affected Software: Download Manager < 3.3.66 Patched Versions: 3.3.66
Mitigation steps: Update to Download Manager version 3.3.66 or greater.
Independent Analytics – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-17506 Number of Installations: 100,000+ Affected Software: Independent Analytics ≤ 2.15.0 Patched Versions: 2.15.1
Mitigation steps: Update to Independent Analytics version 2.15.1 or greater.
EmbedPress – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61961 Number of Installations: 100,000+ Affected Software: EmbedPress ≤ 4.5.6 Patched Versions: 4.6.0
Mitigation steps: Update to EmbedPress version 4.6.0 or greater.
Tutor LMS – Unauthenticated Remote Code Execution via ‘template’ and ‘data’ POST Parameters
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters CVE: CVE-2026-16759 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.5 Patched Versions: 4.0.6
Mitigation steps: Update to Tutor LMS version 4.0.6 or greater.
Relevanssi – Authenticated (Contributor+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) SQL Injection CVE: CVE-2026-15941 Number of Installations: 100,000+ Affected Software: Relevanssi ≤ 4.27.1 Patched Versions: 4.27.2
Mitigation steps: Update to Relevanssi version 4.27.2 or greater.
Content Views – Authenticated (Subscriber+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) SQL Injection CVE: CVE-2026-15361 Number of Installations: 100,000+ Affected Software: Content Views ≤ 4.4 Patched Versions: 4.5
Mitigation steps: Update to Content Views version 4.5 or greater.
AI Engine – Authenticated (Subscriber+) Arbitrary File Read
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary File Read CVE: CVE-2026-16955 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.5 Patched Versions: 3.6.6
Mitigation steps: Update to AI Engine version 3.6.6 or greater.
GiveWP – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVE: CVE-2026-5510 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.14.4 Patched Versions: 4.14.5
Mitigation steps: Update to GiveWP version 4.14.5 or greater.
Envira Gallery – Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description CVE: CVE-2026-3423 Number of Installations: 100,000+ Affected Software: Envira Gallery ≤ 1.12.4 Patched Versions: 1.12.5
Mitigation steps: Update to Envira Gallery version 1.12.5 or greater.
Beaver Builder Page Builder – Authenticated (Author+) Stored Cross-Site Scripting via Button Module ‘button’ Parameter
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter CVE: CVE-2026-17090 Number of Installations: 100,000+ Affected Software: Beaver Builder Page Builder ≤ 2.10.2.2 Patched Versions: 2.10.3.2
Mitigation steps: Update to Beaver Builder Page Builder version 2.10.3.2 or greater.
ECS – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-14230 Number of Installations: 100,000+ Affected Software: ECS ≤ 4.3.7 Patched Versions: 4.3.8
Mitigation steps: Update to ECS version 4.3.8 or greater.
GiveWP – Authenticated (Donor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Donor or higher level authentication. Vulnerability: Authenticated (Donor+) Stored Cross-Site Scripting CVE: CVE-2026-73357 Number of Installations: 100,000+ Affected Software: GiveWP < 4.16.6 Patched Versions: 4.16.6
Mitigation steps: Update to GiveWP version 4.16.6 or greater.
Appointment Booking Plugin – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVE: CVE-2026-5391 Number of Installations: 100,000+ Affected Software: Appointment Booking Plugin ≤ 5.3.2 Patched Versions: 5.4.0
Mitigation steps: Update to Appointment Booking Plugin version 5.4.0 or greater.
Advanced File Manager – Reflected Cross-Site Scripting via postMessage ‘soundFile’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter CVE: CVE-2026-15009 Number of Installations: 100,000+ Affected Software: Advanced File Manager ≤ 5.4.12 Patched Versions: 5.4.13
Mitigation steps: Update to Advanced File Manager version 5.4.13 or greater.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field CVE: CVE-2026-18385 Number of Installations: 100,000+ Affected Software: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content ≤ 4.16.19 Patched Versions: 4.17.0
Mitigation steps: Update to Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content version 4.17.0 or greater.
GiveWP – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-73352 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.5.1 Patched Versions: 4.16.6
Mitigation steps: Update to GiveWP version 4.16.6 or greater.
ECS – Missing Authorization to Unauthenticated Private Content Disclosure
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Private Content Disclosure CVE: CVE-2026-14229 Number of Installations: 100,000+ Affected Software: ECS ≤ 4.3.7 Patched Versions: 4.3.8
Mitigation steps: Update to ECS version 4.3.8 or greater.
GiveWP – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-73349 Number of Installations: 100,000+ Affected Software: GiveWP < 4.16.6 Patched Versions: 4.16.6
Mitigation steps: Update to GiveWP version 4.16.6 or greater.
Element Pack Addons for Elementor – Unauthenticated SMTP Header Injection
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated SMTP Header Injection CVE: CVE-2026-0673 Number of Installations: 100,000+ Affected Software: Element Pack Addons for Elementor ≤ 8.3.15 Patched Versions: 8.3.16
Mitigation steps: Update to Element Pack Addons for Elementor version 8.3.16 or greater.
CAPTCHA 4WP – CAPTCHA Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: CAPTCHA Bypass CVE: CVE-2026-32469 Number of Installations: 100,000+ Affected Software: CAPTCHA 4WP ≤ 7.6.0 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Mercado Pago payments for WooCommerce – Unauthenticated Insecure Direct Object Reference
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-28180 Number of Installations: 100,000+ Affected Software: Mercado Pago payments for WooCommerce ≤ 8.9.0 Patched Versions: 8.9.1
Mitigation steps: Update to Mercado Pago payments for WooCommerce version 8.9.1 or greater.
WP Ghost (Hide My WP Ghost) – IP Spoofing to Protection Mechanism Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: IP Spoofing to Protection Mechanism Bypass CVE: CVE-2026-11870 Number of Installations: 100,000+ Affected Software: WP Ghost (Hide My WP Ghost) < 7.0.05 Patched Versions: 7.0.05
Mitigation steps: Update to WP Ghost (Hide My WP Ghost) version 7.0.05 or greater.
GiveWP – Unauthenticated Payment Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Payment Bypass CVE: CVE-2026-14317 Number of Installations: 100,000+ Affected Software: GiveWP < 4.16.3 Patched Versions: 4.16.3
Mitigation steps: Update to GiveWP version 4.16.3 or greater.
AI Engine – Insecure Direct Object Reference to Unauthenticated Cross-Session Chatbot File Deletion
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Cross-Session Chatbot File Deletion CVE: CVE-2026-16953 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.3 Patched Versions: 3.6.4
Mitigation steps: Update to AI Engine version 3.6.4 or greater.
AI Engine – Authenticated (Administrator+) Privilege Escalation
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Privilege Escalation CVE: CVE-2026-75796 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.0 Patched Versions: 3.6.1
Mitigation steps: Update to AI Engine version 3.6.1 or greater.
FiboSearch – Authenticated (Shop manager+) Stored Cross-Site Scripting
Security Risk: High Exploitation Level: Requires Shop manager or higher level authentication. Vulnerability: Authenticated (Shop manager+) Stored Cross-Site Scripting CVE: CVE-2026-28179 Number of Installations: 100,000+ Affected Software: FiboSearch ≤ 1.33.0 Patched Versions: 1.34.0
Mitigation steps: Update to FiboSearch version 1.34.0 or greater.
DTX – Authenticated (Editor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting CVE: CVE-2026-5116 Number of Installations: 100,000+ Affected Software: DTX ≤ 5.0.5 Patched Versions: 5.0.6
Mitigation steps: Update to DTX version 5.0.6 or greater.
ECS – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-19613 Number of Installations: 100,000+ Affected Software: ECS < 4.3.10 Patched Versions: 4.3.10
Mitigation steps: Update to ECS version 4.3.10 or greater.
Advanced File Manager – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-11565 Number of Installations: 100,000+ Affected Software: Advanced File Manager ≤ 5.4.12 Patched Versions: 5.4.13
Mitigation steps: Update to Advanced File Manager version 5.4.13 or greater.
Kadence WooCommerce Email Designer – Unauthenticated Privilege Escalation
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-28005 Number of Installations: 90,000+ Affected Software: Kadence WooCommerce Email Designer ≤ 1.5.19 Patched Versions: 1.5.19.1
Mitigation steps: Update to Kadence WooCommerce Email Designer version 1.5.19.1 or greater.
Booking for Appointments and Events Calendar – Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission CVE: CVE-2026-6286 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 2.2 Patched Versions: 2.2.1
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.2.1 or greater.
OttoKit: All-in-One Automation Platform – Unauthenticated Server-Side Request Forgery
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery CVE: CVE-2026-32553 Number of Installations: 90,000+ Affected Software: OttoKit: All-in-One Automation Platform ≤ 1.1.35 Patched Versions: 1.1.36
Mitigation steps: Update to OttoKit: All-in-One Automation Platform version 1.1.36 or greater.
ShopLentor – Authenticated (Administrator+) Arbitrary Function Execution via ‘callback’ Parameter via REST API
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API CVE: CVE-2026-6020 Number of Installations: 90,000+ Affected Software: ShopLentor ≤ 3.3.7 Patched Versions: 3.3.8
Mitigation steps: Update to ShopLentor version 3.3.8 or greater.
Everest Forms – Unauthenticated Server-Side Request Forgery via Upload Field ‘Previous Value’
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' CVE: CVE-2026-5096 Number of Installations: 90,000+ Affected Software: Everest Forms ≤ 3.4.4 Patched Versions: 3.4.5
Mitigation steps: Update to Everest Forms version 3.4.5 or greater.
Event Tickets and Registration – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-14822 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration < 5.29.0.1 Patched Versions: 5.29.0.1
Mitigation steps: Update to Event Tickets and Registration version 5.29.0.1 or greater.
Everest Forms – Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints
Security Risk: Medium Exploitation Level: Requires Delegated or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints CVE: CVE-2026-13167 Number of Installations: 90,000+ Affected Software: Everest Forms ≤ 3.5.2 Patched Versions: 3.5.3
Mitigation steps: Update to Everest Forms version 3.5.3 or greater.
Booking for Appointments and Events Calendar – Authenticated (Provider+) Information Exposure
Security Risk: Medium Exploitation Level: Requires Provider (custom role) or higher level authentication. Vulnerability: Authenticated (Provider+) Information Exposure CVE: CVE-2026-14213 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar < 2.4.6 Patched Versions: 2.4.6
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.6 or greater.
Booking for Appointments and Events Calendar – Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure
Security Risk: TBC Exploitation Level: Requires Provider or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure CVE: CVE-2026-14211 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 9.6 Patched Versions: 9.7
Mitigation steps: Update to Booking for Appointments and Events Calendar version 9.7 or greater.
Advanced Custom Fields: Font Awesome Field – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-66678 Number of Installations: 90,000+ Affected Software: Advanced Custom Fields: Font Awesome Field ≤ 6.1.2 Patched Versions: 6.1.3
Mitigation steps: Update to Advanced Custom Fields: Font Awesome Field version 6.1.3 or greater.
Event Tickets and Registration – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-14823 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration < 5.29.0.1 Patched Versions: 5.29.0.1
Mitigation steps: Update to Event Tickets and Registration version 5.29.0.1 or greater.
Booking for Appointments and Events Calendar – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Manager (custom role) or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-14214 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar < 2.4.4 Patched Versions: 2.4.4
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.4 or greater.
Mailgun for WordPress – Unauthenticated Server-Side Request Forgery (SSRF) via ‘addresses’ Array Keys
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys CVE: CVE-2026-78003 Number of Installations: 80,000+ Affected Software: Mailgun for WordPress ≤ 2.2.0 Patched Versions: 2.2.1
Mitigation steps: Update to Mailgun for WordPress version 2.2.1 or greater.
Ajax Search Lite – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-28139 Number of Installations: 80,000+ Affected Software: Ajax Search Lite ≤ 4.14.4 Patched Versions: 4.14.5
Mitigation steps: Update to Ajax Search Lite version 4.14.5 or greater.
Ajax Search Lite – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-16258 Number of Installations: 80,000+ Affected Software: Ajax Search Lite ≤ 4.14.4 Patched Versions: 4.14.5
Mitigation steps: Update to Ajax Search Lite version 4.14.5 or greater.
Depicter – Unauthenticated SQL Injection
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-66622 Number of Installations: 80,000+ Affected Software: Depicter ≤ 4.8.0 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Customer Reviews for WooCommerce – Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form CVE: CVE-2026-6176 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.106.0 Patched Versions: 5.107.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.107.0 or greater.
Depicter – Authenticated (Editor+) Arbitrary File Upload
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Arbitrary File Upload CVE: CVE-2026-15049 Number of Installations: 80,000+ Affected Software: Depicter < 4.8.0 Patched Versions: 4.8.0
Mitigation steps: Update to Depicter version 4.8.0 or greater.
Backup Migration – Authenticated (Administrator+) OS Command Injection via ‘file’ Parameter
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) OS Command Injection via 'file' Parameter CVE: CVE-2026-7693 Number of Installations: 80,000+ Affected Software: Backup Migration ≤ 2.1.1 Patched Versions: 2.1.5.2
Mitigation steps: Update to Backup Migration version 2.1.5.2 or greater.
Product Feed Manager for WooCommerce – Authenticated (Shop Manager+) Remote Code Execution
Security Risk: TBC Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Remote Code Execution CVE: CVE-2026-66709 Number of Installations: 80,000+ Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.42 Patched Versions: 6.6.43
Mitigation steps: Update to Product Feed Manager for WooCommerce version 6.6.43 or greater.
Stream – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API CVE: CVE-2026-11907 Number of Installations: 80,000+ Affected Software: Stream ≤ 4.2.0 Patched Versions: 4.2.1
Mitigation steps: Update to Stream version 4.2.1 or greater.
GutenKit – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-19697 Number of Installations: 80,000+ Affected Software: GutenKit < 2.5.0 Patched Versions: 2.5.0
Mitigation steps: Update to GutenKit version 2.5.0 or greater.
SureCart – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-32548 Number of Installations: 80,000+ Affected Software: SureCart ≤ 4.6.2 Patched Versions: 4.6.3
Mitigation steps: Update to SureCart version 4.6.3 or greater.
JetFormBuilder – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-28140 Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.4.1 Patched Versions: 3.6.4.2
Mitigation steps: Update to JetFormBuilder version 3.6.4.2 or greater.
Download Monitor – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-16608 Number of Installations: 80,000+ Affected Software: Download Monitor ≤ 5.2.5 Patched Versions: 5.2.6
Mitigation steps: Update to Download Monitor version 5.2.6 or greater.
Product Feed Manager for WooCommerce – Authenticated (Shop Manager+) Arbitrary File Downloaf
Security Risk: Medium Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Arbitrary File Downloaf CVE: CVE-2026-73383 Number of Installations: 80,000+ Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.46 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Advanced Excerpt – Authenticated (Administrator+) Stored Cross-Site Scripting
Security Risk: Minimal Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting CVE: CVE-2026-13701 Number of Installations: 80,000+ Affected Software: Advanced Excerpt ≤ 4.4 Patched Versions: 4.5
Mitigation steps: Update to Advanced Excerpt version 4.5 or greater.
GutenKit – Authenticated (Contributor+) Information Exposure
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Information Exposure CVE: CVE-2026-19699 Number of Installations: 80,000+ Affected Software: GutenKit ≤ 2.4.15 Patched Versions: 2.5.0
Mitigation steps: Update to GutenKit version 2.5.0 or greater.
Kubio AI Page Builder – Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action CVE: CVE-2026-16779 Number of Installations: 80,000+ Affected Software: Kubio AI Page Builder ≤ 2.8.5 Patched Versions: 2.8.6
Mitigation steps: Update to Kubio AI Page Builder version 2.8.6 or greater.
Customer Reviews for WooCommerce – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-14941 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.115.0 Patched Versions: 5.116.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.116.0 or greater.
Media Library Assistant – Authenticated (Author+) Arbitrary File Upload
Security Risk: High Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Arbitrary File Upload CVE: CVE-2026-66600 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.39 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Events Manager – Unauthenticated Privilege Escalation
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-18366 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
wpDataTables – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66597 Number of Installations: 70,000+ Affected Software: wpDataTables ≤ 6.5.1.4 Patched Versions: 6.5.1.5
Mitigation steps: Update to wpDataTables version 6.5.1.5 or greater.
10Web Booster – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-14287 Number of Installations: 70,000+ Affected Software: 10Web Booster ≤ 2.33.4 Patched Versions: 2.33.5
Mitigation steps: Update to 10Web Booster version 2.33.5 or greater.
Media Library Assistant – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61963 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.38 Patched Versions: 3.39
Mitigation steps: Update to Media Library Assistant version 3.39 or greater.
Events Manager – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66457 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.2 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Ninja Tables – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61964 Number of Installations: 70,000+ Affected Software: Ninja Tables ≤ 5.2.9 Patched Versions: 5.2.10
Mitigation steps: Update to Ninja Tables version 5.2.10 or greater.
Events Manager – Authenticated (Administrator+) Local File Inclusion via ‘dbem_data[updates]’ Array Keys
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys CVE: CVE-2026-14280 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.3.7.4 Patched Versions: 7.4
Mitigation steps: Update to Events Manager version 7.4 or greater.
Events Manager – Authenticated (Contributor+) SQL Injection via ‘meta_key’ Parameter in Event/Location Duplicate Action
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action CVE: CVE-2026-15023 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Media Library Assistant – Authenticated (Author+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) SQL Injection CVE: CVE-2026-16959 Number of Installations: 70,000+ Affected Software: Media Library Assistant < 3.40 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Events Manager – Authenticated (Subscriber+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) SQL Injection CVE: CVE-2026-18057 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Greenshift – Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI CVE: CVE-2026-5092 Number of Installations: 70,000+ Affected Software: Greenshift ≤ 12.8.9 Patched Versions: 12.9.0
Mitigation steps: Update to Greenshift version 12.9.0 or greater.
Media Library Assistant – Authenticated (Subscriber+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting CVE: CVE-2026-66601 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.39 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Media Library Assistant – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-66591 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.39 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Featured Image from URL (FIFU) – Authenticated (Contributor+) Stored Cross-site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-site Scripting CVE: CVE-2026-73340 Number of Installations: 70,000+ Affected Software: Featured Image from URL (FIFU) ≤ 5.3.3 Patched Versions: 6.0.0
Mitigation steps: Update to Featured Image from URL (FIFU) version 6.0.0 or greater.
Easy Accordion – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘accordionTitleTag’ Block Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute CVE: CVE-2026-18988 Number of Installations: 70,000+ Affected Software: Easy Accordion ≤ 3.1.8 Patched Versions: 3.1.9
Mitigation steps: Update to Easy Accordion version 3.1.9 or greater.
LearnPress – Authenticated (Instructor+) Server-Side Request Forgery
Security Risk: Low Exploitation Level: Requires Instructor or higher level authentication. Vulnerability: Authenticated (Instructor+) Server-Side Request Forgery CVE: CVE-2026-12971 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.3 Patched Versions: 4.4.4
Mitigation steps: Update to LearnPress version 4.4.4 or greater.
Events Manager – Reflected Cross-Site Scripting via ‘header_format’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'header_format' Parameter CVE: CVE-2026-17089 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0.1 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Events Manager – Missing Authorization to Unauthenticated Sensitive Information Disclosure via ‘status’, ‘private’, and ‘private_only’ Parameters
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters CVE: CVE-2026-10627 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
kk Star Ratings – Unauthenticated Arbitrary Shortcode Execution via ‘payload’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter CVE: CVE-2026-3424 Number of Installations: 70,000+ Affected Software: kk Star Ratings ≤ 5.4.10.3 Patched Versions: 5.4.10.4
Mitigation steps: Update to kk Star Ratings version 5.4.10.4 or greater.
LearnPress – Authenticated (Administrator+) SQL Injection via ‘orderby’ Parameter
Security Risk: Medium Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection via 'orderby' Parameter CVE: CVE-2026-77823 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.4 Patched Versions: 4.4.5
Mitigation steps: Update to LearnPress version 4.4.5 or greater.
LearnPress – Missing Authorization to Authenticated (Editor+) Limited Option Update via ‘field_name’ Parameter
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter CVE: CVE-2026-75982 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.4 Patched Versions: 4.4.5
Mitigation steps: Update to LearnPress version 4.4.5 or greater.
Greenshift – Authenticated (Contributor+) Theme Settings Modification via ‘gspb_update_global_wp_settings’
Security Risk: Low Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings' CVE: CVE-2026-5093 Number of Installations: 70,000+ Affected Software: Greenshift ≤ 12.8.9 Patched Versions: 12.9.0
Mitigation steps: Update to Greenshift version 12.9.0 or greater.
LearnPress – Authenticated (Subscriber+) Information Exposure
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-12976 Number of Installations: 70,000+ Affected Software: LearnPress < 4.4.4 Patched Versions: 4.4.4
Mitigation steps: Update to LearnPress version 4.4.4 or greater.
Slim SEO – Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Meta Disclosure
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Meta Disclosure CVE: CVE-2026-16957 Number of Installations: 70,000+ Affected Software: Slim SEO ≤ 4.9.10 Patched Versions: 4.9.11
Mitigation steps: Update to Slim SEO version 4.9.11 or greater.
Brizy – Authenticated (Contributor+) Information Exposure
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Information Exposure CVE: CVE-2026-14195 Number of Installations: 70,000+ Affected Software: Brizy < 2.8.18 Patched Versions: 2.8.18
Mitigation steps: Update to Brizy version 2.8.18 or greater.
Drag and Drop Multiple File Upload for Contact Form 7 – Unauthenticated Remote Code Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution CVE: CVE-2026-18781 Number of Installations: 60,000+ Affected Software: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 Patched Versions: 1.3.9.9
Mitigation steps: Update to Drag and Drop Multiple File Upload for Contact Form 7 version 1.3.9.9 or greater.
Online Scheduling and Appointment Booking System – Unauthenticated SQL Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-13395 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System < 27.8 Patched Versions: 27.8
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 27.8 or greater.
Ultimate Dashboard – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66621 Number of Installations: 60,000+ Affected Software: Ultimate Dashboard ≤ 3.11.2 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Online Scheduling and Appointment Booking System – Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action CVE: CVE-2026-13424 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 27.7 Patched Versions: 28.0
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.0 or greater.
Site Reviews – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-73382 Number of Installations: 60,000+ Affected Software: Site Reviews ≤ 8.2.0 Patched Versions: 8.2.1
Mitigation steps: Update to Site Reviews version 8.2.1 or greater.
Simply Schedule Appointments – Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure CVE: CVE-2026-13358 Number of Installations: 60,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.10 Patched Versions: 1.6.12.11
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.11 or greater.
WP Maps – Authenticated (Subscriber+) Denial of Service
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Denial of Service CVE: CVE-2026-16265 Number of Installations: 60,000+ Affected Software: WP Maps ≤ 4.9.6 Patched Versions: 4.9.7
Mitigation steps: Update to WP Maps version 4.9.7 or greater.
Ultra Addons for Contact Form 7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes CVE: CVE-2026-12801 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.43 Patched Versions: 3.5.44
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.44 or greater.
Simply Schedule Appointments – Unauthenticated Insecure Direct Object Reference
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-16540 Number of Installations: 60,000+ Affected Software: Simply Schedule Appointments < 1.6.12.6 Patched Versions: 1.6.12.6
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.6 or greater.
Drag and Drop Multiple File Upload for Contact Form 7 – Authenticated (Administrator+) Stored Cross-Site Scripting
Security Risk: Minimal Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting CVE: CVE-2026-14325 Number of Installations: 60,000+ Affected Software: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 Patched Versions: 1.3.9.9
Mitigation steps: Update to Drag and Drop Multiple File Upload for Contact Form 7 version 1.3.9.9 or greater.
WP Maps – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-18466 Number of Installations: 60,000+ Affected Software: WP Maps < 4.9.8 Patched Versions: 4.9.8
Mitigation steps: Update to WP Maps version 4.9.8 or greater.
Online Scheduling and Appointment Booking System – Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via ‘params[id]’ Parameter
Security Risk: Medium Exploitation Level: Requires Staff or higher level authentication. Vulnerability: Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter CVE: CVE-2026-12905 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 27.7 Patched Versions: 28.0
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.0 or greater.
Advanced Product Fields (Product Addons) for WooCommerce – Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request CVE: CVE-2026-2996 Number of Installations: 50,000+ Affected Software: Advanced Product Fields (Product Addons) for WooCommerce ≤ 1.6.21 Patched Versions: 1.6.22
Mitigation steps: Update to Advanced Product Fields (Product Addons) for WooCommerce version 1.6.22 or greater.
Advanced AJAX Product Filters – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66439 Number of Installations: 50,000+ Affected Software: Advanced AJAX Product Filters ≤ 3.2.0.3 Patched Versions: 3.2.1
Mitigation steps: Update to Advanced AJAX Product Filters version 3.2.1 or greater.
OptionTree – Authenticated (Editor+) PHP Object Injection
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) PHP Object Injection CVE: CVE-2026-66620 Number of Installations: 50,000+ Affected Software: OptionTree ≤ 2.7.3 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels – Authenticated (Subscriber+) Arbitrary File Read via ‘customer_note’ Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter CVE: CVE-2026-18027 Number of Installations: 50,000+ Affected Software: WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels ≤ 4.9.8 Patched Versions: 5.0.0
Mitigation steps: Update to WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels version 5.0.0 or greater.
Exclusive Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘exad_infobox_image’
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' CVE: CVE-2026-12231 Number of Installations: 50,000+ Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.8 Patched Versions: 2.7.9.9
Mitigation steps: Update to Exclusive Addons for Elementor version 2.7.9.9 or greater.
Seraphinite Accelerator – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-17532 Number of Installations: 50,000+ Affected Software: Seraphinite Accelerator ≤ 2.29.18 Patched Versions: 2.29.19
Mitigation steps: Update to Seraphinite Accelerator version 2.29.19 or greater.
Total Upkeep – Unauthenticated Information Exposure
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-16253 Number of Installations: 50,000+ Affected Software: Total Upkeep < 1.17.3 Patched Versions: 1.17.3
Mitigation steps: Update to Total Upkeep version 1.17.3 or greater.
User Registration & Membership – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-73403 Number of Installations: 50,000+ Affected Software: User Registration & Membership ≤ 5.2.6 Patched Versions: 5.2.7
Mitigation steps: Update to User Registration & Membership version 5.2.7 or greater.
Total Upkeep – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-66708 Number of Installations: 50,000+ Affected Software: Total Upkeep ≤ 1.17.2 Patched Versions: 1.17.3
Mitigation steps: Update to Total Upkeep version 1.17.3 or greater.
Clearfy Cache – Authenticated (Subscriber+) Information Exposure
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-16295 Number of Installations: 50,000+ Affected Software: Clearfy Cache < 2.4.3 Patched Versions: 2.4.3
Mitigation steps: Update to Clearfy Cache version 2.4.3 or greater.
Update your website software to reduce risk. Users unable to upgrade to the latest version are advised to implement a web application firewall, which can virtually patch known vulnerabilities and safeguard their website.










