If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.
To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.
For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.
Plugins
WooCommerce – Unauthenticated Denial of Service
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-48888 Number of Installations: 7,000,000+ Affected Software: WooCommerce < 11.1.0 Patched Versions: 11.1.0
Mitigation steps: Update to WooCommerce version 11.1.0 or greater.
LiteSpeed Cache – Unauthenticated Server-Side Request Forgery
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery CVE: CVE-2026-84761 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.9 Patched Versions: 7.9.1
Mitigation steps: Update to LiteSpeed Cache version 7.9.1 or greater.
WooCommerce – Authenticated (Shop Manager+) SQL Injection
Security Risk: High Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) SQL Injection CVE: CVE-2026-57777 Number of Installations: 7,000,000+ Affected Software: WooCommerce ≤ 10.9.4 Patched Versions: 11.0
Mitigation steps: Update to WooCommerce version 11.0 or greater.
LiteSpeed Cache – Reflected Cross-Site Scripting via ESI ‘esi’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via ESI 'esi' Parameter CVE: CVE-2026-76579 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.9 Patched Versions: 7.9.1
Mitigation steps: Update to LiteSpeed Cache version 7.9.1 or greater.
WPForms – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-84744 Number of Installations: 5,000,000+ Affected Software: WPForms 1.5.0.1 - 2.0.2 Patched Versions: 2.0.2.1
Mitigation steps: Update to WPForms version 2.0.2.1 or greater.
WPForms – Reflected Cross-Site Scripting via ‘page_title’ POST Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'page_title' POST Parameter CVE: CVE-2026-88996 Number of Installations: 5,000,000+ Affected Software: WPForms ≤ 2.0.2 Patched Versions: 2.0.2.1
Mitigation steps: Update to WPForms version 2.0.2.1 or greater.
WPForms – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-74991 Number of Installations: 5,000,000+ Affected Software: WPForms 1.8.8.2 - 2.0.1.1 Patched Versions: 2.0.2
Mitigation steps: Update to WPForms version 2.0.2 or greater.
All-in-One WP Migration and Backup – Unauthenticated Insufficient Credential Protection via Authorization Basic Header
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insufficient Credential Protection via Authorization Basic Header CVE: CVE-2026-89064 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.110 Patched Versions: 7.111
Mitigation steps: Update to All-in-One WP Migration and Backup version 7.111 or greater.
All-in-One WP Migration and Backup – Authenticated (Admin+) Privilege Escalation
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Privilege Escalation CVE: CVE-2026-81810 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.110 Patched Versions: 7.111
Mitigation steps: Update to All-in-One WP Migration and Backup version 7.111 or greater.
Rank Math SEO – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-77783 Number of Installations: 4,000,000+ Affected Software: Rank Math SEO < 1.0.277 Patched Versions: 1.0.277
Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.
UpdraftPlus: WP Backup & Migration Plugin – Authenticated (Subscriber+) Information Exposure
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-82841 Number of Installations: 4,000,000+ Affected Software: UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.26.7 Patched Versions: 2.26.8.26
Mitigation steps: Update to UpdraftPlus: WP Backup & Migration Plugin version 2.26.8.26 or greater.
Rank Math SEO – Missing Authorization to Authenticated (Author+) SEO Object Updates
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Author+) SEO Object Updates CVE: CVE-2026-77784 Number of Installations: 4,000,000+ Affected Software: Rank Math SEO < 1.0.277 Patched Versions: 1.0.277
Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.
Rank Math SEO – Authenticated (Author+) Information Exposure
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Information Exposure CVE: CVE-2026-77785 Number of Installations: 4,000,000+ Affected Software: Rank Math SEO < 1.0.277 Patched Versions: 1.0.277
Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.
Really Simple Security – Unauthenticated Denial of Service
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-84775 Number of Installations: 3,000,000+ Affected Software: Really Simple Security ≤ 9.8.0 Patched Versions: 9.8.1
Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.
Jetpack – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 16.1 - 16.1.2 Patched Versions: 16.1.3
Mitigation steps: Update to Jetpack version 16.1.3 or greater.
Jetpack – Authenticated (Administrator+) PHP Object Injection
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) PHP Object Injection CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 12.0 - 12.0.2 Patched Versions: 16.1.3
Mitigation steps: Update to Jetpack version 16.1.3 or greater.
Jetpack – Authenticated (Administrator+) PHP Object Injection
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) PHP Object Injection CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 16.1 - 16.1.2 Patched Versions: 16.1.3
Mitigation steps: Update to Jetpack version 16.1.3 or greater.
Jetpack – Reflected to Stored Cross-Site Scripting via Reader Repost Parameters
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected to Stored Cross-Site Scripting via Reader Repost Parameters CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 14.5 Patched Versions: 16.1.3
Mitigation steps: Update to Jetpack version 16.1.3 or greater.
Really Simple Security – Unauthenticated Unbounded Option Growth
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Unbounded Option Growth CVE: CVE-2026-88798 Number of Installations: 3,000,000+ Affected Software: Really Simple Security ≤ 9.8.2 Patched Versions: 9.8.3
Mitigation steps: Update to Really Simple Security version 9.8.3 or greater.
Really Simple Security – Unauthenticated Two-Factor Authentication Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Two-Factor Authentication Bypass CVE: CVE-2026-89080 Number of Installations: 3,000,000+ Affected Software: Really Simple Security ≤ 9.8.0 Patched Versions: 9.8.1
Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.
Really Simple Security – Unauthenticated Two-Factor Authentication Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Two-Factor Authentication Bypass CVE: CVE-2026-84777 Number of Installations: 3,000,000+ Affected Software: Really Simple Security ≤ 9.8.0 Patched Versions: 9.8.1
Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.
Really Simple Security – Missing Authorization to 2FA Bypass
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Missing Authorization to 2FA Bypass CVE: CVE-2026-82519 Number of Installations: 3,000,000+ Affected Software: Really Simple Security ≤ 9.8.1 Patched Versions: 9.8.2
Mitigation steps: Update to Really Simple Security version 9.8.2 or greater.
Jetpack – Missing Authorization on WPCOM Media API Attachment Parent
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Missing Authorization on WPCOM Media API Attachment Parent CVE: CVE-2024-10858 Number of Installations: 3,000,000+ Affected Software: Jetpack 3.2 - 16.1.2 Patched Versions: 16.1.3
Mitigation steps: Update to Jetpack version 16.1.3 or greater.
All in One SEO – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-82884 Number of Installations: 2,000,000+ Affected Software: All in One SEO ≤ 5.0.0.0 Patched Versions: 5.0.0.1
Mitigation steps: Update to All in One SEO version 5.0.0.1 or greater.
Complianz GDPR/CCPA Cookie Consent Banner – Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex CVE: CVE-2026-83561 Number of Installations: 1,000,000+ Affected Software: Complianz GDPR/CCPA Cookie Consent Banner ≤ 7.5.4 Patched Versions: 7.5.5
Mitigation steps: Update to Complianz GDPR/CCPA Cookie Consent Banner version 7.5.5 or greater.
EWWW Image Optimizer – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84773 Number of Installations: 1,000,000+ Affected Software: EWWW Image Optimizer ≤ 8.7.6 Patched Versions: 8.7.7
Mitigation steps: Update to EWWW Image Optimizer version 8.7.7 or greater.
EWWW Image Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-97067 Number of Installations: 1,000,000+ Affected Software: EWWW Image Optimizer ≤ 8.7.7 Patched Versions: 8.8.0
Mitigation steps: Update to EWWW Image Optimizer version 8.8.0 or greater.
ElementsKit Elementor Addons – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-94500 Number of Installations: 1,000,000+ Affected Software: ElementsKit Elementor Addons ≤ 4.0.5 Patched Versions: 4.0.6
Mitigation steps: Update to ElementsKit Elementor Addons version 4.0.6 or greater.
Safe SVG – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-94077 Number of Installations: 1,000,000+ Affected Software: Safe SVG ≤ 2.5.0 Patched Versions: 2.5.1
Mitigation steps: Update to Safe SVG version 2.5.1 or greater.
EWWW Image Optimizer – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-91011 Number of Installations: 1,000,000+ Affected Software: EWWW Image Optimizer ≤ 8.7.6 Patched Versions: 8.7.7
Mitigation steps: Update to EWWW Image Optimizer version 8.7.7 or greater.
All-In-One Security (AIOS) – Authenticated (Subscriber+) Security Control Bypass
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Security Control Bypass CVE: CVE-2026-96825 Number of Installations: 1,000,000+ Affected Software: All-In-One Security (AIOS) ≤ 5.4.8 Patched Versions: 5.4.9
Mitigation steps: Update to All-In-One Security (AIOS) version 5.4.9 or greater.
MC4WP: Mailchimp for WordPress – Reflected Cross-Site Scripting via ‘data’ Dynamic Content Tag
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'data' Dynamic Content Tag CVE: CVE-2026-87917 Number of Installations: 1,000,000+ Affected Software: MC4WP: Mailchimp for WordPress ≤ 4.14.0 Patched Versions: 4.14.1
Mitigation steps: Update to MC4WP: Mailchimp for WordPress version 4.14.1 or greater.
Spectra Legacy – Authenticated (Contributor+) Sensitive Information Exposure
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Sensitive Information Exposure CVE: CVE-2026-16302 Number of Installations: 1,000,000+ Affected Software: Spectra Legacy ≤ 2.20.0 Patched Versions: 2.20.1
Mitigation steps: Update to Spectra Legacy version 2.20.1 or greater.
Safe SVG – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-94672 Number of Installations: 1,000,000+ Affected Software: Safe SVG ≤ 2.5.0 Patched Versions: 2.5.1
Mitigation steps: Update to Safe SVG version 2.5.1 or greater.
Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-62134 Number of Installations: 1,000,000+ Affected Software: Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg ≤ 4.7.5 Patched Versions: 4.7.6
Mitigation steps: Update to Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg version 4.7.6 or greater.
W3 Total Cache – Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator CVE: CVE-2026-78438 Number of Installations: 900,000+ Affected Software: W3 Total Cache ≤ 2.10.5 Patched Versions: 2.10.6
Mitigation steps: Update to W3 Total Cache version 2.10.6 or greater.
WPvivid – Authenticated (Administrator+) Arbitrary File Upload
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Arbitrary File Upload CVE: CVE-2026-82193 Number of Installations: 900,000+ Affected Software: WPvivid < 0.9.134 Patched Versions: 0.9.134
Mitigation steps: Update to WPvivid version 0.9.134 or greater.
Translate WordPress with GTranslate – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-86604 Number of Installations: 900,000+ Affected Software: Translate WordPress with GTranslate ≤ 5.0.0 Patched Versions: 5.0.1
Mitigation steps: Update to Translate WordPress with GTranslate version 5.0.1 or greater.
WPvivid – Authenticated (Administrator+) Arbitrary File Deletion
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Arbitrary File Deletion CVE: CVE-2026-82194 Number of Installations: 900,000+ Affected Software: WPvivid < 0.9.134 Patched Versions: 0.9.134
Mitigation steps: Update to WPvivid version 0.9.134 or greater.
Redux Framework – Authenticated (Subscriber+) Stored Cross-Site Scripting via ‘user-mediaurl’ Media Field
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field CVE: CVE-2026-90992 Number of Installations: 900,000+ Affected Software: Redux Framework ≤ 4.5.14 Patched Versions: 4.5.15
Mitigation steps: Update to Redux Framework version 4.5.15 or greater.
Redux Framework – Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input CVE: CVE-2026-5410 Number of Installations: 900,000+ Affected Software: Redux Framework ≤ 4.5.13 Patched Versions: 4.5.14
Mitigation steps: Update to Redux Framework version 4.5.14 or greater.
Redux Framework – Authenticated (Subscriber+) Cross-Site Scripting via User Input
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Cross-Site Scripting via User Input CVE: CVE-2026-5400 Number of Installations: 900,000+ Affected Software: Redux Framework ≤ 4.5.13 Patched Versions: 4.5.14
Mitigation steps: Update to Redux Framework version 4.5.14 or greater.
Redux Framework – Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value CVE: CVE-2026-5399 Number of Installations: 900,000+ Affected Software: Redux Framework ≤ 4.5.13.1 Patched Versions: 4.5.14
Mitigation steps: Update to Redux Framework version 4.5.14 or greater.
WPvivid – Authenticated (Administrator+) SQL Injection
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-82182 Number of Installations: 900,000+ Affected Software: WPvivid < 0.9.133 Patched Versions: 0.9.133
Mitigation steps: Update to WPvivid version 0.9.133 or greater.
Translate WordPress with GTranslate – Authenticated (Administrator+) Stored Cross-Site Scripting
Security Risk: Minimal Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting CVE: CVE-2025-15695 Number of Installations: 900,000+ Affected Software: Translate WordPress with GTranslate < 3.0.10 Patched Versions: 3.0.10
Mitigation steps: Update to Translate WordPress with GTranslate version 3.0.10 or greater.
Redux Framework – Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via ‘attachment_id’ Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter CVE: CVE-2026-88999 Number of Installations: 900,000+ Affected Software: Redux Framework ≤ 4.5.14 Patched Versions: 4.5.15
Mitigation steps: Update to Redux Framework version 4.5.15 or greater.
Autoptimize – Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path CVE: CVE-2026-14995 Number of Installations: 800,000+ Affected Software: Autoptimize ≤ 3.1.15.1 Patched Versions: 3.1.16
Mitigation steps: Update to Autoptimize version 3.1.16 or greater.
Breadcrumb NavXT – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84765 Number of Installations: 800,000+ Affected Software: Breadcrumb NavXT ≤ 7.5.1 Patched Versions: 7.5.2
Mitigation steps: Update to Breadcrumb NavXT version 7.5.2 or greater.
Polylang – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-97279 Number of Installations: 800,000+ Affected Software: Polylang ≤ 3.8.9 Patched Versions: 3.8.10
Mitigation steps: Update to Polylang version 3.8.10 or greater.
Smart Slider 3 – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘data-href’ Attribute in Custom HTML Block
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block CVE: CVE-2026-14876 Number of Installations: 800,000+ Affected Software: Smart Slider 3 ≤ 3.5.1.38 Patched Versions: 3.5.1.39
Mitigation steps: Update to Smart Slider 3 version 3.5.1.39 or greater.
Flamingo – Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search CVE: CVE-2026-12853 Number of Installations: 800,000+ Affected Software: Flamingo ≤ 2.6.2 Patched Versions: 2.6.3
Mitigation steps: Update to Flamingo version 2.6.3 or greater.
Popup Maker – Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter CVE: CVE-2026-87915 Number of Installations: 700,000+ Affected Software: Popup Maker ≤ 1.24.0 Patched Versions: 1.25.0
Mitigation steps: Update to Popup Maker version 1.25.0 or greater.
Popup Maker – Authenticated (Contributor+) Stored Cross-Site Scripting via post_title
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via post_title CVE: CVE-2026-15797 Number of Installations: 700,000+ Affected Software: Popup Maker ≤ 1.24.0 Patched Versions: 1.25.0
Mitigation steps: Update to Popup Maker version 1.25.0 or greater.
The Events Calendar – Unauthenticated Code Injection to Remote Code Execution via Widget ‘classes’ Map Callable Invocation
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation CVE: CVE-2026-78159 Number of Installations: 600,000+ Affected Software: The Events Calendar ≤ 6.17.3 Patched Versions: 6.17.3.1
Mitigation steps: Update to The Events Calendar version 6.17.3.1 or greater.
The Events Calendar – Unauthenticated PHP Object Injection to Remote Code Execution
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection to Remote Code Execution CVE: CVE-2026-78006 Number of Installations: 600,000+ Affected Software: The Events Calendar ≤ 6.17.4 Patched Versions: 6.17.4.1
Mitigation steps: Update to The Events Calendar version 6.17.4.1 or greater.
Forminator Forms – Unauthenticated Arbitrary Shortcode Execution via ‘current_url’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter CVE: CVE-2026-92229 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2 Patched Versions: 1.57.3
Mitigation steps: Update to Forminator Forms version 1.57.3 or greater.
Ninja Forms – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-91827 Number of Installations: 600,000+ Affected Software: Ninja Forms ≤ 3.15.3 Patched Versions: 3.15.4
Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.
Forminator Forms – Unauthenticated Stored Cross-Site Scripting via ‘postdata-1[post-custom]’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter CVE: CVE-2026-92144 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field CVE: CVE-2026-85235 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
WP Statistics – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-93770 Number of Installations: 600,000+ Affected Software: WP Statistics ≤ 14.16.13 Patched Versions: 14.16.14
Mitigation steps: Update to WP Statistics version 14.16.14 or greater.
Ninja Forms – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-95515 Number of Installations: 600,000+ Affected Software: Ninja Forms ≤ 3.15.3 Patched Versions: 3.15.4
Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.
Ninja Forms – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-92438 Number of Installations: 600,000+ Affected Software: Ninja Forms ≤ 3.15.3 Patched Versions: 3.15.4
Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.
Forminator Forms – Authenticated (Admin+) Privilege Escalation
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Privilege Escalation CVE: CVE-2026-87068 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2.0 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
Royal Addons for Elementor – Unauthenticated Arbitrary HTML Injection in Notification Emails
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary HTML Injection in Notification Emails CVE: CVE-2026-13407 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor ≤ 1.7.1066 Patched Versions: 1.7.1067
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1067 or greater.
Ninja Forms – Unauthenticated Stored Cross-Site Scripting via Repeater Child ‘type’ Confusion via Unmatched Array Key
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key CVE: CVE-2026-19769 Number of Installations: 600,000+ Affected Software: Ninja Forms ≤ 3.15.1 Patched Versions: 3.15.2
Mitigation steps: Update to Ninja Forms version 3.15.2 or greater.
WP Statistics – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84774 Number of Installations: 600,000+ Affected Software: WP Statistics ≤ 14.16.11 Patched Versions: 14.16.12
Mitigation steps: Update to WP Statistics version 14.16.12 or greater.
Under Construction – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-81295 Number of Installations: 600,000+ Affected Software: Under Construction ≤ 5.82 Patched Versions: 5.83
Mitigation steps: Update to Under Construction version 5.83 or greater.
Forminator Forms – Authenticated (Admin+) PHP Object Injection
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) PHP Object Injection CVE: CVE-2026-87067 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2.0 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
Ninja Forms – Authenticated (Administrator+) PHP Object Injection via Form Import
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) PHP Object Injection via Form Import CVE: CVE-2026-11363 Number of Installations: 600,000+ Affected Software: Ninja Forms ≤ 3.14.6 Patched Versions: 3.14.7
Mitigation steps: Update to Ninja Forms version 3.14.7 or greater.
Ninja Forms – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-80437 Number of Installations: 600,000+ Affected Software: Ninja Forms 3.14.10 - 3.15.1 Patched Versions: 3.15.2
Mitigation steps: Update to Ninja Forms version 3.15.2 or greater.
Premium Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-94168 Number of Installations: 600,000+ Affected Software: Premium Addons for Elementor ≤ 4.11.105 Patched Versions: 4.11.106
Mitigation steps: Update to Premium Addons for Elementor version 4.11.106 or greater.
The Events Calendar – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-84741 Number of Installations: 600,000+ Affected Software: The Events Calendar 4.5 - 6.17.4.1 Patched Versions: 6.17.5
Mitigation steps: Update to The Events Calendar version 6.17.5 or greater.
Forminator Forms – Unauthenticated Poll Vote Limit Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Poll Vote Limit Bypass CVE: CVE-2026-87070 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2.0 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
Forminator Forms – Missing Authorization to Unauthenticated Arbitrary Post Meta Injection
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Arbitrary Post Meta Injection CVE: CVE-2026-87071 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2.0 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
Royal Addons for Elementor – Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in ‘wpr_keyword’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter CVE: CVE-2026-17585 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor ≤ 1.7.1066 Patched Versions: 1.7.1067
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1067 or greater.
MetForm – Unauthenticated Email Header Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Email Header Injection CVE: CVE-2026-86813 Number of Installations: 600,000+ Affected Software: MetForm < 4.1.9 Patched Versions: 4.1.9
Mitigation steps: Update to MetForm version 4.1.9 or greater.
The Events Calendar – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-97285 Number of Installations: 600,000+ Affected Software: The Events Calendar ≤ 6.17.5 Patched Versions: 6.17.5.1
Mitigation steps: Update to The Events Calendar version 6.17.5.1 or greater.
Forminator Forms – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-87069 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.2.0 Patched Versions: 1.57.2.1
Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.
The Events Calendar – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-84742 Number of Installations: 600,000+ Affected Software: The Events Calendar 6.15.0 - 6.17.4.1 Patched Versions: 6.17.5
Mitigation steps: Update to The Events Calendar version 6.17.5 or greater.
The Events Calendar – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-84743 Number of Installations: 600,000+ Affected Software: The Events Calendar 6.15.16.1 - 6.17.4.1 Patched Versions: 6.17.5
Mitigation steps: Update to The Events Calendar version 6.17.5 or greater.
The Events Calendar – Authenticated (Contributor+) Information Exposure
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Information Exposure CVE: CVE-2026-84745 Number of Installations: 600,000+ Affected Software: The Events Calendar < 6.17.3.1 Patched Versions: 6.17.3.1
Mitigation steps: Update to The Events Calendar version 6.17.3.1 or greater.
Ninja Forms – Authenticated (Custom Role+) Information Exposure
Security Risk: High Exploitation Level: Requires Custom Role or higher level authentication. Vulnerability: Authenticated (Custom Role+) Information Exposure CVE: CVE-2026-80438 Number of Installations: 600,000+ Affected Software: Ninja Forms 3.14.0 - 3.15.1 Patched Versions: 3.15.2
Mitigation steps: Update to Ninja Forms version 3.15.2 or greater.
Extendify – Unauthenticated Stored Cross-Site Scripting via ‘styles.blocks’ Block Type Key
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key CVE: CVE-2026-85679 Number of Installations: 500,000+ Affected Software: Extendify ≤ 3.1.6 Patched Versions: 3.2.0
Mitigation steps: Update to Extendify version 3.2.0 or greater.
Ninja Forms – Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Stored Cross-Site Scripting CVE: CVE-2026-94504 Number of Installations: 500,000+ Affected Software: Ninja Forms ≤ 3.15.3 Patched Versions: 3.15.4
Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.
Kirki – Unauthenticated Stored Cross-Site Scripting via ‘comment’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter CVE: CVE-2026-17037 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.2.0 Patched Versions: 6.2.1
Mitigation steps: Update to Kirki version 6.2.1 or greater.
Kirki – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84219 Number of Installations: 500,000+ Affected Software: Kirki 6.2.1 - 6.2.5 Patched Versions: 6.3.0
Mitigation steps: Update to Kirki version 6.3.0 or greater.
SureForms – Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload CVE: CVE-2026-18406 Number of Installations: 500,000+ Affected Software: SureForms ≤ 2.12.2 Patched Versions: 2.12.3
Mitigation steps: Update to SureForms version 2.12.3 or greater.
Broken Link Checker – Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log CVE: CVE-2026-75528 Number of Installations: 500,000+ Affected Software: Broken Link Checker ≤ 2.4.13 Patched Versions: 2.4.13.1
Mitigation steps: Update to Broken Link Checker version 2.4.13.1 or greater.
Ocean Extra – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-94684 Number of Installations: 500,000+ Affected Software: Ocean Extra ≤ 2.6.1 Patched Versions: 2.6.2
Mitigation steps: Update to Ocean Extra version 2.6.2 or greater.
Kirki – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-84223 Number of Installations: 500,000+ Affected Software: Kirki 6.0.0 - 6.3.0 Patched Versions: 6.3.1
Mitigation steps: Update to Kirki version 6.3.1 or greater.
Broken Link Checker – Authenticated (Editor+) Server-Side Request Forgery
Security Risk: Low Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Server-Side Request Forgery CVE: CVE-2026-84772 Number of Installations: 500,000+ Affected Software: Broken Link Checker ≤ 2.4.14 Patched Versions: 2.4.14.1
Mitigation steps: Update to Broken Link Checker version 2.4.14.1 or greater.
Kirki – Unauthenticated Blind Server-Side Request Forgery via ‘kirki_data’ Parameter
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter CVE: CVE-2026-18335 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.2.0 Patched Versions: 6.2.1
Mitigation steps: Update to Kirki version 6.2.1 or greater.
Kirki – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-84222 Number of Installations: 500,000+ Affected Software: Kirki 6.2.1 - 6.2.5 Patched Versions: 6.3.0
Mitigation steps: Update to Kirki version 6.3.0 or greater.
SureForms – Unauthenticated Insecure Direct Object Reference
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-85308 Number of Installations: 500,000+ Affected Software: SureForms ≤ 2.12.5 Patched Versions: 2.12.6
Mitigation steps: Update to SureForms version 2.12.6 or greater.
Kirki – Authenticated (Editor+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) SQL Injection CVE: CVE-2026-84221 Number of Installations: 500,000+ Affected Software: Kirki 6.0.0 - 6.2.5 Patched Versions: 6.3.0
Mitigation steps: Update to Kirki version 6.3.0 or greater.
Kirki – Authenticated (Custom Role+) Insecure Direct Object Reference
Security Risk: High Exploitation Level: Requires Custom Role or higher level authentication. Vulnerability: Authenticated (Custom Role+) Insecure Direct Object Reference CVE: CVE-2026-84225 Number of Installations: 500,000+ Affected Software: Kirki 6.0.0 - 6.2.5 Patched Versions: 6.3.0
Mitigation steps: Update to Kirki version 6.3.0 or greater.
TranslatePress – Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel CVE: CVE-2026-89412 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.5 Patched Versions: 3.3.6
Mitigation steps: Update to TranslatePress version 3.3.6 or greater.
Template Kit – Authenticated (Editor+) Arbitrary File Deletion
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Arbitrary File Deletion CVE: CVE-2026-96824 Number of Installations: 400,000+ Affected Software: Template Kit ≤ 1.0.16 Patched Versions: 1.0.17
Mitigation steps: Update to Template Kit version 1.0.17 or greater.
HappyAddons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-62080 Number of Installations: 400,000+ Affected Software: HappyAddons for Elementor ≤ 3.23.1 Patched Versions: 3.50.0
Mitigation steps: Update to HappyAddons for Elementor version 3.50.0 or greater.
PixelYourSite – Authenticated (Subscriber+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting CVE: CVE-2026-95530 Number of Installations: 400,000+ Affected Software: PixelYourSite ≤ 11.4.1 Patched Versions: 11.4.2
Mitigation steps: Update to PixelYourSite version 11.4.2 or greater.
HappyAddons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-85006 Number of Installations: 400,000+ Affected Software: HappyAddons for Elementor ≤ 3.49.0 Patched Versions: 3.50.0
Mitigation steps: Update to HappyAddons for Elementor version 3.50.0 or greater.
SureRank SEO – Unauthenticated Information Exposure
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-78152 Number of Installations: 400,000+ Affected Software: SureRank SEO 1.6.2 - 1.10.0 Patched Versions: 1.10.1
Mitigation steps: Update to SureRank SEO version 1.10.1 or greater.
YITH WooCommerce Wishlist – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-82305 Number of Installations: 400,000+ Affected Software: YITH WooCommerce Wishlist < 4.18.1 Patched Versions: 4.18.1
Mitigation steps: Update to YITH WooCommerce Wishlist version 4.18.1 or greater.
BackWPup – Missing Authorization
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Missing Authorization CVE: CVE-2026-86815 Number of Installations: 400,000+ Affected Software: BackWPup 5.2.2 - 5.7.4 Patched Versions: 5.7.5
Mitigation steps: Update to BackWPup version 5.7.5 or greater.
ShortPixel Image Optimizer – Authenticated (Author+) PHP Object Injection via Nested JSON Post Content
Security Risk: High Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) PHP Object Injection via Nested JSON Post Content CVE: CVE-2026-17086 Number of Installations: 300,000+ Affected Software: ShortPixel Image Optimizer ≤ 6.5.5 Patched Versions: 6.5.6
Mitigation steps: Update to ShortPixel Image Optimizer version 6.5.6 or greater.
Photo Gallery, Sliders, Proofing and Themes – Unauthenticated Arbitrary File Read
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary File Read CVE: CVE-2026-94123 Number of Installations: 300,000+ Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.5.0 Patched Versions: 4.5.1
Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.1 or greater.
ShortPixel Image Optimizer – Authenticated (Subscriber+) PHP Object Injection
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) PHP Object Injection CVE: CVE-2026-97246 Number of Installations: 300,000+ Affected Software: ShortPixel Image Optimizer ≤ 6.5.5 Patched Versions: 6.5.6
Mitigation steps: Update to ShortPixel Image Optimizer version 6.5.6 or greater.
Unlimited Elements For Elementor – Authenticated (Subscriber+) PHP Object Injection
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) PHP Object Injection CVE: CVE-2026-85017 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.19 Patched Versions: 2.0.20
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.20 or greater.
Unlimited Elements For Elementor – Unauthenticated SQL Injection
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-18561 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.16 Patched Versions: 2.0.17
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.17 or greater.
WP Go Maps – Unauthenticated Denial of Service
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-84780 Number of Installations: 300,000+ Affected Software: WP Go Maps ≤ 10.1.08 Patched Versions: 10.1.09
Mitigation steps: Update to WP Go Maps version 10.1.09 or greater.
PDF Invoices & Packing Slips for WooCommerce – Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields CVE: CVE-2026-92244 Number of Installations: 300,000+ Affected Software: PDF Invoices & Packing Slips for WooCommerce ≤ 5.16.1 Patched Versions: 5.16.2
Mitigation steps: Update to PDF Invoices & Packing Slips for WooCommerce version 5.16.2 or greater.
Ad Inserter – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-97077 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.18 Patched Versions: 2.8.19
Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.
Photo Gallery, Sliders, Proofing and Themes – Authenticated (Admin+) Arbitrary File Upload
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Arbitrary File Upload CVE: CVE-2026-81650 Number of Installations: 300,000+ Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.4.0 Patched Versions: 4.5.0
Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.0 or greater.
Jeg Kit for Elementor – Unauthenticated Stored Cross-Site Scripting via Comment Content
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-18405 Number of Installations: 300,000+ Affected Software: Jeg Kit for Elementor ≤ 3.2.16 Patched Versions: 3.2.17
Mitigation steps: Update to Jeg Kit for Elementor version 3.2.17 or greater.
Unlimited Elements For Elementor – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84820 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.17 Patched Versions: 2.0.18
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.18 or greater.
Formidable Forms – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-19857 Number of Installations: 300,000+ Affected Software: Formidable Forms ≤ 6.34 Patched Versions: 6.35
Mitigation steps: Update to Formidable Forms version 6.35 or greater.
Duplicate Post – Authenticated (Subscriber+) Stored Cross-Site Scripting via ‘noti_token’ Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter CVE: CVE-2026-89424 Number of Installations: 300,000+ Affected Software: Duplicate Post ≤ 1.5.6 Patched Versions: 1.5.7
Mitigation steps: Update to Duplicate Post version 1.5.7 or greater.
Ad Inserter – Authenticated (Subscriber+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting CVE: CVE-2026-81655 Number of Installations: 300,000+ Affected Software: Ad Inserter 2.8.12 - 2.8.18 Patched Versions: 2.8.19
Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.
Unlimited Elements For Elementor – Authenticated (Contributor+) Server-Side Request Forgery
Security Risk: Low Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery CVE: CVE-2026-66608 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.19 Patched Versions: 2.0.20
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.20 or greater.
SEOPress – Authenticated (Contributor+) Server-Side Request Forgery
Security Risk: Low Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery CVE: CVE-2026-85305 Number of Installations: 300,000+ Affected Software: SEOPress ≤ 10.1 Patched Versions: 10.2
Mitigation steps: Update to SEOPress version 10.2 or greater.
Ad Inserter – Reflected Cross-Site Scripting via ‘s’ Search Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 's' Search Parameter CVE: CVE-2026-89427 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.18 Patched Versions: 2.8.19
Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.
Ad Inserter – Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
CVE: CVE-2026-19902
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.18
Patched Versions: 2.8.19Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.
Unlimited Elements For Elementor – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-77150 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.16 Patched Versions: 2.0.17
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.17 or greater.
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-18964 Number of Installations: 300,000+ Affected Software: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button ≤ 3.5.9 Patched Versions: 3.6.0
Mitigation steps: Update to Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button version 3.6.0 or greater.
Unlimited Elements For Elementor – Reflected Cross-Site Scripting via ‘formData[id]’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'formData[id]' Parameter CVE: CVE-2026-75586 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.17 Patched Versions: 2.0.18
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.18 or greater.
Blocksy Companion – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-97247 Number of Installations: 300,000+ Affected Software: Blocksy Companion ≤ 2.1.55 Patched Versions: 2.1.56
Mitigation steps: Update to Blocksy Companion version 2.1.56 or greater.
Breeze Cache – Unauthenticated Cache Poisoning
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Cache Poisoning CVE: CVE-2026-79713 Number of Installations: 300,000+ Affected Software: Breeze Cache ≤ 2.5.14 Patched Versions: 2.5.15
Mitigation steps: Update to Breeze Cache version 2.5.15 or greater.
Ad Inserter – Missing Authorization to Unauthenticated Header/Footer Code Disclosure via ‘ai-debug-code’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter CVE: CVE-2026-11984 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.16 Patched Versions: 2.8.17
Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.
Formidable Forms – Unauthenticated Content Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Content Injection CVE: CVE-2026-85641 Number of Installations: 300,000+ Affected Software: Formidable Forms ≤ 6.34 Patched Versions: 6.35
Mitigation steps: Update to Formidable Forms version 6.35 or greater.
Otter Blocks – Missing Authorization to Unauthenticated Purchase Verification Bypass
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Purchase Verification Bypass CVE: CVE-2026-4945 Number of Installations: 300,000+ Affected Software: Otter Blocks ≤ 3.1.7 Patched Versions: 3.1.8
Mitigation steps: Update to Otter Blocks version 3.1.8 or greater.
Unlimited Elements For Elementor – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-85304 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.17 Patched Versions: 2.0.18
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.18 or greater.
WP Activity Log – Authenticated (Administrator+) SQL Injection
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-62085 Number of Installations: 300,000+ Affected Software: WP Activity Log ≤ 5.6.6 Patched Versions: 5.6.7
Mitigation steps: Update to WP Activity Log version 5.6.7 or greater.
CMB2 – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-80338 Number of Installations: 300,000+ Affected Software: CMB2 ≤ 2.12.0 Patched Versions: 2.13.0
Mitigation steps: Update to CMB2 version 2.13.0 or greater.
Photo Gallery, Sliders, Proofing and Themes – Authenticated (Admin+) Insecure Direct Object Reference
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Insecure Direct Object Reference CVE: CVE-2026-81654 Number of Installations: 300,000+ Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.4.0 Patched Versions: 4.5.0
Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.0 or greater.
Photo Gallery, Sliders, Proofing and Themes – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-81652 Number of Installations: 300,000+ Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.4.0 Patched Versions: 4.5.0
Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.0 or greater.
CartFlows – Authenticated (Contributor+) Remote Code Execution
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Remote Code Execution CVE: CVE-2026-96837 Number of Installations: 200,000+ Affected Software: CartFlows ≤ 3.2.0 Patched Versions: 3.2.1
Mitigation steps: Update to CartFlows version 3.2.1 or greater.
Migrate Guru – Unauthenticated Denial of Service
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-84778 Number of Installations: 200,000+ Affected Software: Migrate Guru ≤ 6.65 Patched Versions: 6.72
Mitigation steps: Update to Migrate Guru version 6.72 or greater.
MalCare WordPress Security Plugin – Unauthenticated Denial of Service
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-84776 Number of Installations: 200,000+ Affected Software: MalCare WordPress Security Plugin ≤ 6.69 Patched Versions: 6.72
Mitigation steps: Update to MalCare WordPress Security Plugin version 6.72 or greater.
CMP – Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action
Security Risk: High Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action CVE: CVE-2026-12470 Number of Installations: 200,000+ Affected Software: CMP ≤ 4.1.17 Patched Versions: 4.1.18
Mitigation steps: Update to CMP version 4.1.18 or greater.
Ultimate Member – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-85680 Number of Installations: 200,000+ Affected Software: Ultimate Member ≤ 2.13.0 Patched Versions: 2.13.1
Mitigation steps: Update to Ultimate Member version 2.13.1 or greater.
Optimole – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84829 Number of Installations: 200,000+ Affected Software: Optimole ≤ 4.2.11 Patched Versions: 4.2.12
Mitigation steps: Update to Optimole version 4.2.12 or greater.
Spam protection, Honeypot, Anti-Spam by CleanTalk – Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder CVE: CVE-2026-77830 Number of Installations: 200,000+ Affected Software: Spam protection, Honeypot, Anti-Spam by CleanTalk ≤ 6.86 Patched Versions: 6.87
Mitigation steps: Update to Spam protection, Honeypot, Anti-Spam by CleanTalk version 6.87 or greater.
iubenda – Unauthenticated Stored Cross-Site Scripting via Comment Content
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-77263 Number of Installations: 200,000+ Affected Software: iubenda ≤ 3.13.4 Patched Versions: 3.13.5
Mitigation steps: Update to iubenda version 3.13.5 or greater.
iubenda – Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite CVE: CVE-2026-77233 Number of Installations: 200,000+ Affected Software: iubenda ≤ 3.13.4 Patched Versions: 3.13.5
Mitigation steps: Update to iubenda version 3.13.5 or greater.
InfiniteWP Client – Authenticated (Admin+) SQL Injection via ‘iwp_get_comments_*’ Array Key
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key CVE: CVE-2026-17576 Number of Installations: 200,000+ Affected Software: InfiniteWP Client ≤ 1.13.9 Patched Versions: 1.13.10
Mitigation steps: Update to InfiniteWP Client version 1.13.10 or greater.
Spam protection, Honeypot, Anti-Spam by CleanTalk – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-19855 Number of Installations: 200,000+ Affected Software: Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 Patched Versions: 6.87
Mitigation steps: Update to Spam protection, Honeypot, Anti-Spam by CleanTalk version 6.87 or greater.
Redirection for Contact Form 7 – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-80439 Number of Installations: 200,000+ Affected Software: Redirection for Contact Form 7 2.2.7 - 3.2.10 Patched Versions: 3.2.11
Mitigation steps: Update to Redirection for Contact Form 7 version 3.2.11 or greater.
Gutenberg Essential Blocks – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘marker’ Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute CVE: CVE-2026-96256 Number of Installations: 200,000+ Affected Software: Gutenberg Essential Blocks ≤ 6.4.5 Patched Versions: 6.4.6
Mitigation steps: Update to Gutenberg Essential Blocks version 6.4.6 or greater.
Qi Addons For Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-62079 Number of Installations: 200,000+ Affected Software: Qi Addons For Elementor ≤ 1.11 Patched Versions: 1.11.1
Mitigation steps: Update to Qi Addons For Elementor version 1.11.1 or greater.
Supreme Modules Lite – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-102384 Number of Installations: 200,000+ Affected Software: Supreme Modules Lite ≤ 2.5.63 Patched Versions: 2.5.64
Mitigation steps: Update to Supreme Modules Lite version 2.5.64 or greater.
Optimole – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-96531 Number of Installations: 200,000+ Affected Software: Optimole 4.0.0 - 4.2.12 Patched Versions: 4.2.13
Mitigation steps: Update to Optimole version 4.2.13 or greater.
DearFlip – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘.dvcss’ Element Class Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute CVE: CVE-2026-8623 Number of Installations: 200,000+ Affected Software: DearFlip ≤ 2.4.30 Patched Versions: 2.4.37
Mitigation steps: Update to DearFlip version 2.4.37 or greater.
Social Chat – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘consent_message’ JSON Attribute in .qlwapp data-box
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box CVE: CVE-2026-18404 Number of Installations: 200,000+ Affected Software: Social Chat ≤ 8.6.2 Patched Versions: 8.6.3
Mitigation steps: Update to Social Chat version 8.6.3 or greater.
DearFlip – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘.df-element’ Element Inner HTML
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML CVE: CVE-2026-8625 Number of Installations: 200,000+ Affected Software: DearFlip ≤ 2.4.30 Patched Versions: 2.4.37
Mitigation steps: Update to DearFlip version 2.4.37 or greater.
JetBackup – Authenticated (Subscriber+) Privilege Escalation
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Privilege Escalation CVE: CVE-2026-19453 Number of Installations: 200,000+ Affected Software: JetBackup 3.1.7.9 - 3.1.23.3 Patched Versions: 3.1.23.5
Mitigation steps: Update to JetBackup version 3.1.23.5 or greater.
Qi Addons For Elementor – Reflected DOM-Based Cross-Site Scripting via ‘s’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Reflected DOM-Based Cross-Site Scripting via 's' Parameter CVE: CVE-2026-92249 Number of Installations: 200,000+ Affected Software: Qi Addons For Elementor ≤ 1.11 Patched Versions: 1.11.1
Mitigation steps: Update to Qi Addons For Elementor version 1.11.1 or greater.
Newsletter – Reflected Cross-Site Scripting via ‘nn’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'nn' Parameter CVE: CVE-2026-90981 Number of Installations: 200,000+ Affected Software: Newsletter ≤ 9.3.8 Patched Versions: 9.3.9
Mitigation steps: Update to Newsletter version 9.3.9 or greater.
Simple CAPTCHA with Cloudflare Turnstile – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-66632 Number of Installations: 200,000+ Affected Software: Simple CAPTCHA with Cloudflare Turnstile ≤ 1.42.1 Patched Versions: 1.42.3
Mitigation steps: Update to Simple CAPTCHA with Cloudflare Turnstile version 1.42.3 or greater.
FileBird – Authenticated (Author+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-15004 Number of Installations: 200,000+ Affected Software: FileBird ≤ 6.5.6 Patched Versions: 6.5.7
Mitigation steps: Update to FileBird version 6.5.7 or greater.
Mailchimp for WooCommerce – Unauthenticated Insecure Direct Object Reference
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-92436 Number of Installations: 200,000+ Affected Software: Mailchimp for WooCommerce ≤ 6.2 Patched Versions: 6.3
Mitigation steps: Update to Mailchimp for WooCommerce version 6.3 or greater.
TikTok – Missing Authorization to Unauthenticated TikTok Integration Takeover via ‘auth_code’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter CVE: CVE-2026-18346 Number of Installations: 200,000+ Affected Software: TikTok ≤ 1.4.1 Patched Versions: 1.4.2
Mitigation steps: Update to TikTok version 1.4.2 or greater.
TikTok – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-92965 Number of Installations: 200,000+ Affected Software: TikTok 1.2.0 - 1.4.1 Patched Versions: 1.4.2
Mitigation steps: Update to TikTok version 1.4.2 or greater.
Mailchimp for WooCommerce – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-92435 Number of Installations: 200,000+ Affected Software: Mailchimp for WooCommerce ≤ 6.1.0 Patched Versions: 6.1.1
Mitigation steps: Update to Mailchimp for WooCommerce version 6.1.1 or greater.
Simple CAPTCHA with Cloudflare Turnstile – Captcha Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Captcha Bypass CVE: CVE-2026-66674 Number of Installations: 200,000+ Affected Software: Simple CAPTCHA with Cloudflare Turnstile ≤ 1.42.1 Patched Versions: 1.42.3
Mitigation steps: Update to Simple CAPTCHA with Cloudflare Turnstile version 1.42.3 or greater.
Appointment Booking Plugin – Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field CVE: CVE-2026-92966 Number of Installations: 100,000+ Affected Software: Appointment Booking Plugin ≤ 5.7.0 Patched Versions: 5.7.1
Mitigation steps: Update to Appointment Booking Plugin version 5.7.1 or greater.
Tutor LMS – Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution CVE: CVE-2026-78175 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.7 Patched Versions: 4.0.8
Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.
Modula Image Gallery – Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via ‘file’ Parameter
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter CVE: CVE-2026-92713 Number of Installations: 100,000+ Affected Software: Modula Image Gallery ≤ 3.0.2 Patched Versions: 3.0.3
Mitigation steps: Update to Modula Image Gallery version 3.0.3 or greater.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Authenticated (Subscriber+) Arbitrary Shortcode Execution via ‘eup_bio’ Biography Field (Entity-Encoded Shortcode Bracket)
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) CVE: CVE-2026-85658 Number of Installations: 100,000+ Affected Software: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content ≤ 4.17.2 Patched Versions: 4.17.3
Mitigation steps: Update to Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content version 4.17.3 or greater.
Two Factor – Unauthenticated Denial of Service
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-100508 Number of Installations: 100,000+ Affected Software: Two Factor ≤ 0.16.0 Patched Versions: 0.17.0
Mitigation steps: Update to Two Factor version 0.17.0 or greater.
Modula Image Gallery – Missing Authorization to Unauthenticated Private Gallery Image Disclosure via ‘modula_gallery_id’ and ‘modula_image_id’ Parameters
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters CVE: CVE-2026-89406 Number of Installations: 100,000+ Affected Software: Modula Image Gallery ≤ 3.0.1 Patched Versions: 3.0.2
Mitigation steps: Update to Modula Image Gallery version 3.0.2 or greater.
GiveWP – Unauthenticated Privilege Escalation
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-85530 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.8.0 Patched Versions: 4.16.8.1
Mitigation steps: Update to GiveWP version 4.16.8.1 or greater.
Advanced Custom Fields: Extended – Unauthenticated Privilege Escalation
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-80467 Number of Installations: 100,000+ Affected Software: Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 Patched Versions: 0.9.2.7
Mitigation steps: Update to Advanced Custom Fields: Extended version 0.9.2.7 or greater.
GiveWP – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-96830 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.9 Patched Versions: 4.17.0
Mitigation steps: Update to GiveWP version 4.17.0 or greater.
پارسی دیت – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-96836 Number of Installations: 100,000+ Affected Software: پارسی دیت ≤ 6.3 Patched Versions: 6.4
Mitigation steps: Update to پارسی دیت version 6.4 or greater.
WPS Limit Login – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-93622 Number of Installations: 100,000+ Affected Software: WPS Limit Login ≤ 1.5.9.3 Patched Versions: 1.5.9.4
Mitigation steps: Update to WPS Limit Login version 1.5.9.4 or greater.
Asset CleanUp: Page Speed Booster – Unauthenticated Stored Cross-Site Scripting via Comment Content
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-13354 Number of Installations: 100,000+ Affected Software: Asset CleanUp: Page Speed Booster ≤ 1.4.0.5 Patched Versions: 1.4.0.6
Mitigation steps: Update to Asset CleanUp: Page Speed Booster version 1.4.0.6 or greater.
User Role Editor – Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant CVE: CVE-2026-75927 Number of Installations: 100,000+ Affected Software: User Role Editor ≤ 2.50.0 Patched Versions: 2.50.1
Mitigation steps: Update to User Role Editor version 2.50.1 or greater.
Hide My WP Ghost – Unauthenticated Server-Side Request Forgery
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery CVE: CVE-2026-81806 Number of Installations: 100,000+ Affected Software: Hide My WP Ghost ≤ 7.0.09 Patched Versions: 7.0.10
Mitigation steps: Update to Hide My WP Ghost version 7.0.10 or greater.
Tutor LMS – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via ‘student_id’ Parameter
Security Risk: Low Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter CVE: CVE-2026-89333 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.8 Patched Versions: 4.0.9
Mitigation steps: Update to Tutor LMS version 4.0.9 or greater.
GiveWP – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-85113 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.8 Patched Versions: 4.16.9
Mitigation steps: Update to GiveWP version 4.16.9 or greater.
Photo Gallery by 10Web – Authenticated (Author+) SQL Injection via ‘album_id’ Shortcode Attribute
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute CVE: CVE-2026-85652 Number of Installations: 100,000+ Affected Software: Photo Gallery by 10Web ≤ 1.8.44 Patched Versions: 1.8.45
Mitigation steps: Update to Photo Gallery by 10Web version 1.8.45 or greater.
Download Manager – Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via ‘wpdm_duplicate’ Parameter
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter CVE: CVE-2026-92714 Number of Installations: 100,000+ Affected Software: Download Manager ≤ 3.3.68 Patched Versions: 3.3.69
Mitigation steps: Update to Download Manager version 3.3.69 or greater.
AI Engine – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via ‘mediaId’ Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter CVE: CVE-2026-89141 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.7.7 Patched Versions: 3.7.8
Mitigation steps: Update to AI Engine version 3.7.8 or greater.
Beaver Builder Page Builder – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-18021 Number of Installations: 100,000+ Affected Software: Beaver Builder Page Builder ≤ 2.10.3.1 Patched Versions: 2.10.3.2
Mitigation steps: Update to Beaver Builder Page Builder version 2.10.3.2 or greater.
LukasApps CAPTCHA tools for Contact Form 7 – Unauthenticated Arbitrary Shortcode Execution
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-85117 Number of Installations: 100,000+ Affected Software: LukasApps CAPTCHA tools for Contact Form 7 0.1.7 - 0.1.8 Patched Versions: 0.1.9
Mitigation steps: Update to LukasApps CAPTCHA tools for Contact Form 7 version 0.1.9 or greater.
Pods – Authenticated (Author+) Arbitrary File Read
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Arbitrary File Read CVE: CVE-2026-74853 Number of Installations: 100,000+ Affected Software: Pods 3.3 - 3.3.9.1 Patched Versions: 3.3.9.2
Mitigation steps: Update to Pods version 3.3.9.2 or greater.
EmbedPress – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-85002 Number of Installations: 100,000+ Affected Software: EmbedPress ≤ 4.6.6 Patched Versions: 4.6.7
Mitigation steps: Update to EmbedPress version 4.6.7 or greater.
The Plus Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-96829 Number of Installations: 100,000+ Affected Software: The Plus Addons for Elementor ≤ 6.5.1 Patched Versions: 6.5.2
Mitigation steps: Update to The Plus Addons for Elementor version 6.5.2 or greater.
The Post Grid – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-94680 Number of Installations: 100,000+ Affected Software: The Post Grid ≤ 7.9.5 Patched Versions: 7.9.6
Mitigation steps: Update to The Post Grid version 7.9.6 or greater.
The Post Grid – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-84151 Number of Installations: 100,000+ Affected Software: The Post Grid ≤ 7.9.4 Patched Versions: 7.9.5
Mitigation steps: Update to The Post Grid version 7.9.5 or greater.
VK All in One Expansion Unit – Authenticated (Author+) Stored Cross-Site Scripting via ‘vkExUnit_cta_img_position’ Post Meta
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta CVE: CVE-2026-17586 Number of Installations: 100,000+ Affected Software: VK All in One Expansion Unit ≤ 9.118.0 Patched Versions: 9.119.0
Mitigation steps: Update to VK All in One Expansion Unit version 9.119.0 or greater.
Element Pack Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-66574 Number of Installations: 100,000+ Affected Software: Element Pack Addons for Elementor ≤ 8.8.3 Patched Versions: 8.8.4
Mitigation steps: Update to Element Pack Addons for Elementor version 8.8.4 or greater.
Custom Twitter Feeds – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘buttoncolor’ Shortcode Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute CVE: CVE-2026-84909 Number of Installations: 100,000+ Affected Software: Custom Twitter Feeds ≤ 2.8.0 Patched Versions: 2.9.0
Mitigation steps: Update to Custom Twitter Feeds version 2.9.0 or greater.
Photo Gallery by 10Web – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVE: CVE-2026-86311 Number of Installations: 100,000+ Affected Software: Photo Gallery by 10Web ≤ 1.8.44 Patched Versions: 1.8.45
Mitigation steps: Update to Photo Gallery by 10Web version 1.8.45 or greater.
ShopEngine Elementor WooCommerce Builder Addon – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘shopengine_product_title_header_size’ Parameter
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter CVE: CVE-2026-85575 Number of Installations: 100,000+ Affected Software: ShopEngine Elementor WooCommerce Builder Addon ≤ 4.9.5 Patched Versions: 4.9.6
Mitigation steps: Update to ShopEngine Elementor WooCommerce Builder Addon version 4.9.6 or greater.
Aruba HiSpeed Cache – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content CVE: CVE-2026-15889 Number of Installations: 100,000+ Affected Software: Aruba HiSpeed Cache ≤ 3.0.14 Patched Versions: 3.0.15
Mitigation steps: Update to Aruba HiSpeed Cache version 3.0.15 or greater.
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-85418 Number of Installations: 100,000+ Affected Software: Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More ≤ 3.0.8 Patched Versions: 3.0.9
Mitigation steps: Update to Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More version 3.0.9 or greater.
Pods – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘not_found’ Shortcode Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute CVE: CVE-2026-76573 Number of Installations: 100,000+ Affected Software: Pods ≤ 3.3.9.1 Patched Versions: 3.3.9.2
Mitigation steps: Update to Pods version 3.3.9.2 or greater.
Gallery : FooGallery – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘custom_settings’ Shortcode Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute CVE: CVE-2026-85414 Number of Installations: 100,000+ Affected Software: Gallery : FooGallery ≤ 3.3.2 Patched Versions: 3.3.3
Mitigation steps: Update to Gallery : FooGallery version 3.3.3 or greater.
Social Media Share Buttons & Social Sharing Icons – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-19719 Number of Installations: 100,000+ Affected Software: Social Media Share Buttons & Social Sharing Icons < 3.0.1 Patched Versions: 3.0.1
Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.1 or greater.
Social Media Share Buttons & Social Sharing Icons – Reflected DOM-Based Cross-Site Scripting via URL
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Reflected DOM-Based Cross-Site Scripting via URL CVE: CVE-2026-89047 Number of Installations: 100,000+ Affected Software: Social Media Share Buttons & Social Sharing Icons ≤ 3.0.1 Patched Versions: 3.0.2
Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.2 or greater.
Tutor LMS – Reflected Cross-Site Scripting via ‘back_url’ and ‘search’ Parameters
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters CVE: CVE-2026-89081 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.8 Patched Versions: 4.0.9
Mitigation steps: Update to Tutor LMS version 4.0.9 or greater.
EmbedPress – Reflected Cross-Site Scripting via ‘hash’ and ‘unique’ Parameters
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters CVE: CVE-2026-89330 Number of Installations: 100,000+ Affected Software: EmbedPress ≤ 4.6.5 Patched Versions: 4.6.6
Mitigation steps: Update to EmbedPress version 4.6.6 or greater.
Relevanssi – Reflected Cross-Site Scripting
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-19985 Number of Installations: 100,000+ Affected Software: Relevanssi ≤ 4.28.1 Patched Versions: 4.28.2
Mitigation steps: Update to Relevanssi version 4.28.2 or greater.
Social Media Share Buttons & Social Sharing Icons – Reflected Cross-Site Scripting
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-19723 Number of Installations: 100,000+ Affected Software: Social Media Share Buttons & Social Sharing Icons < 3.0.1 Patched Versions: 3.0.1
Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.1 or greater.
Photo Gallery by 10Web – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-12865 Number of Installations: 100,000+ Affected Software: Photo Gallery by 10Web < 1.8.44 Patched Versions: 1.8.44
Mitigation steps: Update to Photo Gallery by 10Web version 1.8.44 or greater.
Asset CleanUp: Page Speed Booster – Authenticated (Administrator+) Server-Side Request Forgery via ‘page_url’ Parameter
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter CVE: CVE-2026-12037 Number of Installations: 100,000+ Affected Software: Asset CleanUp: Page Speed Booster ≤ 1.4.0.5 Patched Versions: 1.4.0.6
Mitigation steps: Update to Asset CleanUp: Page Speed Booster version 1.4.0.6 or greater.
WP Popular Posts – Unauthenticated Information Disclosure in ‘post_type’ and ‘context’ Parameters
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters CVE: CVE-2026-92548 Number of Installations: 100,000+ Affected Software: WP Popular Posts ≤ 7.4.2 Patched Versions: 7.4.3
Mitigation steps: Update to WP Popular Posts version 7.4.3 or greater.
GiveWP – Unauthenticated User Impersonation
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated User Impersonation CVE: CVE-2026-97196 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.9 Patched Versions: 4.17.0
Mitigation steps: Update to GiveWP version 4.17.0 or greater.
GiveWP – Unauthenticated Insecure Direct Object Reference
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-97066 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.9 Patched Versions: 4.17.0
Mitigation steps: Update to GiveWP version 4.17.0 or greater.
Captcha Code – Unauthenticated Login Captcha Protection Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Login Captcha Protection Bypass CVE: CVE-2026-94457 Number of Installations: 100,000+ Affected Software: Captcha Code ≤ 3.32 Patched Versions: 3.33
Mitigation steps: Update to Captcha Code version 3.33 or greater.
Secure Custom Fields – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-92403 Number of Installations: 100,000+ Affected Software: Secure Custom Fields ≤ 6.9.3 Patched Versions: 6.9.4
Mitigation steps: Update to Secure Custom Fields version 6.9.4 or greater.
Hide My WP Ghost – Unauthenticated Protection Mechanism Bypass
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Protection Mechanism Bypass CVE: CVE-2026-86796 Number of Installations: 100,000+ Affected Software: Hide My WP Ghost ≤ 7.0.10 Patched Versions: 7.0.11
Mitigation steps: Update to Hide My WP Ghost version 7.0.11 or greater.
Hide My WP Ghost – Unauthenticated Login Protection Bypass
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Login Protection Bypass CVE: CVE-2026-86800 Number of Installations: 100,000+ Affected Software: Hide My WP Ghost ≤ 7.0.10 Patched Versions: 7.0.11
Mitigation steps: Update to Hide My WP Ghost version 7.0.11 or greater.
Schema & Structured Data for WP & AMP – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-82124 Number of Installations: 100,000+ Affected Software: Schema & Structured Data for WP & AMP ≤ 1.65 Patched Versions: 1.66
Mitigation steps: Update to Schema & Structured Data for WP & AMP version 1.66 or greater.
Schema & Structured Data for WP & AMP – Unauthenticated Insecure Direct Object Reference
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-82125 Number of Installations: 100,000+ Affected Software: Schema & Structured Data for WP & AMP ≤ 1.65 Patched Versions: 1.66
Mitigation steps: Update to Schema & Structured Data for WP & AMP version 1.66 or greater.
bbPress – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-62137 Number of Installations: 100,000+ Affected Software: bbPress ≤ 2.6.14 Patched Versions: 2.6.15
Mitigation steps: Update to bbPress version 2.6.15 or greater.
Payment Plugins for Stripe WooCommerce – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-80339 Number of Installations: 100,000+ Affected Software: Payment Plugins for Stripe WooCommerce ≤ 4.0.11 Patched Versions: 4.0.12
Mitigation steps: Update to Payment Plugins for Stripe WooCommerce version 4.0.12 or greater.
Content Views – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-17517 Number of Installations: 100,000+ Affected Software: Content Views < 4.5.1.2 Patched Versions: 4.5.1.2
Mitigation steps: Update to Content Views version 4.5.1.2 or greater.
EmbedPress – Unauthenticated Paid API Consumption and Database Row Injection
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Paid API Consumption and Database Row Injection CVE: CVE-2026-84936 Number of Installations: 100,000+ Affected Software: EmbedPress 4.6.0 - 4.6.3 Patched Versions: 4.6.4
Mitigation steps: Update to EmbedPress version 4.6.4 or greater.
FormLayer – Unauthenticated Information Exposure
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-78151 Number of Installations: 100,000+ Affected Software: FormLayer < 1.0.9 Patched Versions: 1.0.9
Mitigation steps: Update to FormLayer version 1.0.9 or greater.
WPML Multilingual & Multicurrency for WooCommerce – Authenticated (Shop Manager+) SQL Injection via Exchange Rate Field
Security Risk: High Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) SQL Injection via Exchange Rate Field CVE: Not provided Number of Installations: 100,000+ Affected Software: WPML Multilingual & Multicurrency for WooCommerce ≤ 5.5.7 Patched Versions: 5.5.8
Mitigation steps: Update to WPML Multilingual & Multicurrency for WooCommerce version 5.5.8 or greater.
Hide My WP Ghost – Unauthenticated Open Redirect via ‘redirect_to’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Open Redirect via 'redirect_to' Parameter CVE: CVE-2026-7527 Number of Installations: 100,000+ Affected Software: Hide My WP Ghost ≤ 7.0.02 Patched Versions: 7.0.03
Mitigation steps: Update to Hide My WP Ghost version 7.0.03 or greater.
Temporary Login Without Password – Authenticated (Administrator+) Privilege Escalation
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Privilege Escalation CVE: CVE-2026-77752 Number of Installations: 100,000+ Affected Software: Temporary Login Without Password 1.5 - 1.9.8 Patched Versions: 1.9.9
Mitigation steps: Update to Temporary Login Without Password version 1.9.9 or greater.
Newsletters, Email Marketing, SMS and Popups by Omnisend – Authenticated (Subscriber+) Insecure Direct Object Reference
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Insecure Direct Object Reference CVE: CVE-2026-97074 Number of Installations: 100,000+ Affected Software: Newsletters, Email Marketing, SMS and Popups by Omnisend ≤ 1.9.0 Patched Versions: 1.9.1
Mitigation steps: Update to Newsletters, Email Marketing, SMS and Popups by Omnisend version 1.9.1 or greater.
GiveWP – Authenticated (Subscriber+) Information Exposure
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-96834 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.9 Patched Versions: 4.17.0
Mitigation steps: Update to GiveWP version 4.17.0 or greater.
MailerLite – Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion CVE: CVE-2026-3253 Number of Installations: 100,000+ Affected Software: MailerLite ≤ 1.7.21 Patched Versions: 1.7.22
Mitigation steps: Update to MailerLite version 1.7.22 or greater.
Tutor LMS – Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via ‘payload’ Parameter
Security Risk: Low Exploitation Level: Requires Custom or higher level authentication. Vulnerability: Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter CVE: CVE-2026-18439 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.7 Patched Versions: 4.0.8
Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.
Tutor LMS – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via ‘lesson_id’ Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter CVE: CVE-2026-88944 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.8 Patched Versions: 4.0.9
Mitigation steps: Update to Tutor LMS version 4.0.9 or greater.
Appointment Booking Plugin – Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)
Security Risk: Low Exploitation Level: Requires Custom or higher level authentication. Vulnerability: Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking) CVE: CVE-2026-13471 Number of Installations: 100,000+ Affected Software: Appointment Booking Plugin ≤ 5.6.3 Patched Versions: 5.6.4
Mitigation steps: Update to Appointment Booking Plugin version 5.6.4 or greater.
Appointment Booking Plugin – Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via ‘customer[id]’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter CVE: CVE-2026-18441 Number of Installations: 100,000+ Affected Software: Appointment Booking Plugin ≤ 5.6.9 Patched Versions: 5.6.10
Mitigation steps: Update to Appointment Booking Plugin version 5.6.10 or greater.
Tutor LMS – Authenticated (Subscriber+) Information Exposure
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-85572 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.7 Patched Versions: 4.0.8
Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.
Tutor LMS – REST API Authentication Confusion
Security Risk: High Exploitation Level: No authentication required. Vulnerability: REST API Authentication Confusion CVE: CVE-2026-85569 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.7 Patched Versions: 4.0.8
Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.
Schema & Structured Data for WP & AMP – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-82126 Number of Installations: 100,000+ Affected Software: Schema & Structured Data for WP & AMP ≤ 1.65 Patched Versions: 1.66
Mitigation steps: Update to Schema & Structured Data for WP & AMP version 1.66 or greater.
Temporary Login Without Password – Authenticated (Custom Role+) Persistent Access After Login Revocation
Security Risk: High Exploitation Level: Requires custom cole. Vulnerability: Authenticated (Custom Role+) Persistent Access After Login Revocation CVE: CVE-2026-77753 Number of Installations: 100,000+ Affected Software: Temporary Login Without Password < 1.9.9 Patched Versions: 1.9.9
Mitigation steps: Update to Temporary Login Without Password version 1.9.9 or greater.
EmbedPress – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-84926 Number of Installations: 100,000+ Affected Software: EmbedPress 4.6.0 - 4.6.3 Patched Versions: 4.6.4
Mitigation steps: Update to EmbedPress version 4.6.4 or greater.
EmbedPress – Missing Authorization to Authenticated (Contributor+) Site-Wide Places Library Modification
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Site-Wide Places Library Modification CVE: CVE-2026-84927 Number of Installations: 100,000+ Affected Software: EmbedPress 4.6.0 - 4.6.3 Patched Versions: 4.6.4
Mitigation steps: Update to EmbedPress version 4.6.4 or greater.
Everest Forms – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-62103 Number of Installations: 90,000+ Affected Software: Everest Forms ≤ 3.6.0 Patched Versions: 3.6.1
Mitigation steps: Update to Everest Forms version 3.6.1 or greater.
Go Live Update Urls – Authenticated (Contributor+) PHP Object Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) PHP Object Injection CVE: CVE-2026-94678 Number of Installations: 90,000+ Affected Software: Go Live Update Urls ≤ 7.0.8 Patched Versions: 7.1.0
Mitigation steps: Update to Go Live Update Urls version 7.1.0 or greater.
Event Tickets and Registration – Missing Authorization to Unauthenticated Stripe Credentials Update
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Stripe Credentials Update CVE: CVE-2026-3174 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration ≤ 5.27.4 Patched Versions: 5.27.4.1
Mitigation steps: Update to Event Tickets and Registration version 5.27.4.1 or greater.
AI Engine – Unauthenticated Stored Cross-Site Scripting via ‘model_’ Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection CVE: CVE-2026-96561 Number of Installations: 90,000+ Affected Software: AI Engine ≤ 3.8.0 Patched Versions: 3.8.1
Mitigation steps: Update to AI Engine version 3.8.1 or greater.
Event Tickets and Registration – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-93526 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration ≤ 5.29.4 Patched Versions: 5.29.5
Mitigation steps: Update to Event Tickets and Registration version 5.29.5 or greater.
Kadence WooCommerce Email Designer – Authenticated (Shop Manager+) PHP Object Injection
Security Risk: TBC Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) PHP Object Injection CVE: CVE-2026-94677 Number of Installations: 90,000+ Affected Software: Kadence WooCommerce Email Designer ≤ 1.5.19.1 Patched Versions: 1.5.19.2
Mitigation steps: Update to Kadence WooCommerce Email Designer version 1.5.19.2 or greater.
Event Tickets and Registration – Authenticated (Contributor+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) SQL Injection CVE: CVE-2026-97287 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration ≤ 5.29.5 Patched Versions: 5.29.5.1
Mitigation steps: Update to Event Tickets and Registration version 5.29.5.1 or greater.
Hustle – Unauthenticated Arbitrary Shortcode Execution
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-80440 Number of Installations: 90,000+ Affected Software: Hustle < 7.8.14.2 Patched Versions: 7.8.14.2
Mitigation steps: Update to Hustle version 7.8.14.2 or greater.
Booking for Appointments and Events Calendar – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘load_manually’ Parameter
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter CVE: CVE-2026-10148 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.9 Patched Versions: 2.4.10
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.10 or greater.
Booking for Appointments and Events Calendar – Authenticated (Custom Role+) Privilege Escalation
Security Risk: Medium Exploitation Level: Requires Custom Role or higher level authentication. Vulnerability: Authenticated (Custom Role+) Privilege Escalation CVE: CVE-2026-77705 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar < 2.4.10 Patched Versions: 2.4.10
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.10 or greater.
Booking for Appointments and Events Calendar – Authenticated (Custom+) Missing Authorization to Limited Account Takeover
Security Risk: Medium Exploitation Level: Requires Custom or higher level authentication. Vulnerability: Authenticated (Custom+) Missing Authorization to Limited Account Takeover CVE: CVE-2026-14311 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.4 Patched Versions: 2.4.5
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.5 or greater.
AI Engine – Unauthenticated Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-93623 Number of Installations: 90,000+ Affected Software: AI Engine ≤ 3.7.8 Patched Versions: 3.7.9
Mitigation steps: Update to AI Engine version 3.7.9 or greater.
Booking for Appointments and Events Calendar – Missing Authorization to Unauthenticated Payment Bypass
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Payment Bypass CVE: CVE-2026-16582 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.5 Patched Versions: 2.4.6
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.6 or greater.
Booking for Appointments and Events Calendar – Unauthenticated Payment Bypass
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Payment Bypass CVE: CVE-2026-77689 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar 9.0 - 9.8.0 Patched Versions: 9.8.1
Mitigation steps: Update to Booking for Appointments and Events Calendar version 9.8.1 or greater.
Booking for Appointments and Events Calendar – Authenticated (Editor+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) SQL Injection CVE: CVE-2026-62112 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.9 Patched Versions: 2.4.10
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.10 or greater.
BuddyPress – Insecure Direct Object Reference to Notifications Deletion
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Insecure Direct Object Reference to Notifications Deletion CVE: CVE-2024-12145 Number of Installations: 90,000+ Affected Software: BuddyPress ≤ 14.3.3 Patched Versions: 14.3.4
Mitigation steps: Update to BuddyPress version 14.3.4 or greater.
JetFormBuilder – Unauthenticated Privilege Escalation via ‘_jet_engine_booking_form_id’ Parameter
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter CVE: CVE-2026-12793 Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.2 Patched Versions: 3.6.2.1
Mitigation steps: Update to JetFormBuilder version 3.6.2.1 or greater.
JetFormBuilder – Unauthenticated Arbitrary Shortcode Execution
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-19859 Number of Installations: 80,000+ Affected Software: JetFormBuilder < 3.6.5.2 Patched Versions: 3.6.5.2
Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.
Customer Reviews for WooCommerce – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via ‘items[][media]’ Parameter
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter CVE: CVE-2026-89055 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.120.0 Patched Versions: 5.121.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.121.0 or greater.
SureCart – Authenticated (Subscriber+) Arbitrary Account Email Takeover
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary Account Email Takeover CVE: CVE-2026-18480 Number of Installations: 80,000+ Affected Software: SureCart < 4.6.3 Patched Versions: 4.6.3
Mitigation steps: Update to SureCart version 4.6.3 or greater.
HUSKY – Unauthenticated Local File Inclusion via ‘custom_tpl’ Shortcode Attribute via ‘woof_draw_products’ AJAX
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX CVE: CVE-2026-92969 Number of Installations: 80,000+ Affected Software: HUSKY ≤ 1.4.4 Patched Versions: 1.4.5
Mitigation steps: Update to HUSKY version 1.4.5 or greater.
JetFormBuilder – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84817 Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.5.1 Patched Versions: 3.6.5.2
Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.
JetFormBuilder – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-19861 Number of Installations: 80,000+ Affected Software: JetFormBuilder < 3.6.5.2 Patched Versions: 3.6.5.2
Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.
JetFormBuilder – Authenticated (Administrator+) Arbitrary File Deletion
Security Risk: Medium Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Arbitrary File Deletion CVE: CVE-2026-19860 Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.5.2 Patched Versions: 3.6.5.3
Mitigation steps: Update to JetFormBuilder version 3.6.5.3 or greater.
Strong Testimonials – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-97286 Number of Installations: 80,000+ Affected Software: Strong Testimonials ≤ 3.3.11 Patched Versions: 3.3.12
Mitigation steps: Update to Strong Testimonials version 3.3.12 or greater.
Kubio AI Page Builder – Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content CVE: CVE-2026-14472 Number of Installations: 80,000+ Affected Software: Kubio AI Page Builder ≤ 2.8.4 Patched Versions: 2.8.5
Mitigation steps: Update to Kubio AI Page Builder version 2.8.5 or greater.
Strong Testimonials – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘lightbox_class’ Shortcode Attribute
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute CVE: CVE-2026-92622 Number of Installations: 80,000+ Affected Software: Strong Testimonials ≤ 3.3.8 Patched Versions: 3.3.9
Mitigation steps: Update to Strong Testimonials version 3.3.9 or greater.
GutenKit – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘postBodyCss’
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss' CVE: CVE-2026-2573 Number of Installations: 80,000+ Affected Software: GutenKit ≤ 2.4.4 Patched Versions: 2.4.5
Mitigation steps: Update to GutenKit version 2.4.5 or greater.
SureCart – Authenticated (Shop Worker+) Privilege Escalation
Security Risk: TBC Exploitation Level: Requires Shop Worker or higher level authentication. Vulnerability: Authenticated (Shop Worker+) Privilege Escalation CVE: CVE-2026-97245 Number of Installations: 80,000+ Affected Software: SureCart ≤ 4.7.2 Patched Versions: 4.7.3
Mitigation steps: Update to SureCart version 4.7.3 or greater.
JetFormBuilder – Reflected Cross-Site Scripting via ‘jfb_xss’ (URL Query Variable) Parameter via Calculated Field
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field CVE: CVE-2026-92212 Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.5.3 Patched Versions: 3.6.5.4
Mitigation steps: Update to JetFormBuilder version 3.6.5.4 or greater.
ShopLentor – Reflected Cross-Site Scripting via Query-String Parameter Name
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via Query-String Parameter Name CVE: CVE-2026-92554 Number of Installations: 80,000+ Affected Software: ShopLentor ≤ 3.5.1 Patched Versions: 3.5.2
Mitigation steps: Update to ShopLentor version 3.5.2 or greater.
HUSKY – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-18562 Number of Installations: 80,000+ Affected Software: HUSKY ≤ 1.4.3 Patched Versions: 1.4.3.1
Mitigation steps: Update to HUSKY version 1.4.3.1 or greater.
Customer Reviews for WooCommerce – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-96823 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.120.0 Patched Versions: 5.121.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.121.0 or greater.
Payment Plugins for PayPal WooCommerce – Unauthenticated Insecure Direct Object Reference
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-80342 Number of Installations: 80,000+ Affected Software: Payment Plugins for PayPal WooCommerce ≤ 2.0.26 Patched Versions: 2.0.27
Mitigation steps: Update to Payment Plugins for PayPal WooCommerce version 2.0.27 or greater.
SureCart – Unauthorized WordPress Account Creation
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthorized WordPress Account Creation CVE: CVE-2026-75793 Number of Installations: 80,000+ Affected Software: SureCart < 4.7.0 Patched Versions: 4.7.0
Mitigation steps: Update to SureCart version 4.7.0 or greater.
JetFormBuilder – Unauthenticated Information Exposure
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-19858 Number of Installations: 80,000+ Affected Software: JetFormBuilder < 3.6.5.2 Patched Versions: 3.6.5.2
Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.
Payment Plugins for PayPal WooCommerce – Unauthenticated Information Exposure
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-80340 Number of Installations: 80,000+ Affected Software: Payment Plugins for PayPal WooCommerce ≤ 2.0.25 Patched Versions: 2.0.26
Mitigation steps: Update to Payment Plugins for PayPal WooCommerce version 2.0.26 or greater.
JetFormBuilder – Missing Authorization to Unauthenticated JetEngine Options Page Modification
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated JetEngine Options Page Modification CVE: Not provided Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.2 Patched Versions: 3.6.2.1
Mitigation steps: Update to JetFormBuilder version 3.6.2.1 or greater.
JetFormBuilder – Unauthenticated Email Header Injection
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Email Header Injection CVE: CVE-2026-19862 Number of Installations: 80,000+ Affected Software: JetFormBuilder < 3.6.5.2 Patched Versions: 3.6.5.2
Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.
Email Log – Authenticated (Administrator+) SQL Injection
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-94174 Number of Installations: 80,000+ Affected Software: Email Log ≤ 2.63 Patched Versions: 2.64
Mitigation steps: Update to Email Log version 2.64 or greater.
Product Feed Manager for WooCommerce – Authenticated (Shop Manager+) Path Traversal to File Deletion via ‘provider’ Parameter
Security Risk: Medium Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter CVE: CVE-2026-15095 Number of Installations: 80,000+ Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.43 Patched Versions: 6.6.44
Mitigation steps: Update to Product Feed Manager for WooCommerce version 6.6.44 or greater.
Checkout Field Manager (Checkout Manager) for WooCommerce – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-87831 Number of Installations: 80,000+ Affected Software: Checkout Field Manager (Checkout Manager) for WooCommerce ≤ 7.9.6 Patched Versions: 7.9.7
Mitigation steps: Update to Checkout Field Manager (Checkout Manager) for WooCommerce version 7.9.7 or greater.
Checkout Field Manager (Checkout Manager) for WooCommerce – Authenticated (Subscriber+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Insecure Direct Object Reference CVE: CVE-2026-87829 Number of Installations: 80,000+ Affected Software: Checkout Field Manager (Checkout Manager) for WooCommerce ≤ 7.9.6 Patched Versions: 7.9.7
Mitigation steps: Update to Checkout Field Manager (Checkout Manager) for WooCommerce version 7.9.7 or greater.
Payment Plugins for PayPal WooCommerce – Missing Authorization
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-80341 Number of Installations: 80,000+ Affected Software: Payment Plugins for PayPal WooCommerce ≤ 2.0.25 Patched Versions: 2.0.26
Mitigation steps: Update to Payment Plugins for PayPal WooCommerce version 2.0.26 or greater.
GutenKit – Authenticated (Contributor+) Arbitrary CSS Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Arbitrary CSS Injection CVE: CVE-2026-19698 Number of Installations: 80,000+ Affected Software: GutenKit ≤ 2.5.0 Patched Versions: 2.5.1
Mitigation steps: Update to GutenKit version 2.5.1 or greater.
Hummingbird Performance – Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log CVE: CVE-2026-83627 Number of Installations: 70,000+ Affected Software: Hummingbird Performance ≤ 3.21.0 Patched Versions: 3.21.1
Mitigation steps: Update to Hummingbird Performance version 3.21.1 or greater.
Import and export users and customers – Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields CVE: CVE-2026-86583 Number of Installations: 70,000+ Affected Software: Import and export users and customers ≤ 2.4.17 Patched Versions: 2.4.18
Mitigation steps: Update to Import and export users and customers version 2.4.18 or greater.
LearnPress – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via ‘item_id’ Parameter
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter CVE: CVE-2026-93882 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.8 Patched Versions: 4.4.9
Mitigation steps: Update to LearnPress version 4.4.9 or greater.
10Web Booster – Authenticated (Contributor+) PHP Object Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) PHP Object Injection CVE: CVE-2026-94121 Number of Installations: 70,000+ Affected Software: 10Web Booster ≤ 2.33.6 Patched Versions: 2.34.0
Mitigation steps: Update to 10Web Booster version 2.34.0 or greater.
AMP for WP – Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation CVE: CVE-2026-83591 Number of Installations: 70,000+ Affected Software: AMP for WP ≤ 1.1.16 Patched Versions: 1.1.17
Mitigation steps: Update to AMP for WP version 1.1.17 or greater.
Import and export users and customers – Authenticated (Admin+) Privilege Escalation
Security Risk: Medium Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Privilege Escalation CVE: CVE-2026-92540 Number of Installations: 70,000+ Affected Software: Import and export users and customers ≤ 2.5.1 Patched Versions: 2.5.2
Mitigation steps: Update to Import and export users and customers version 2.5.2 or greater.
Hummingbird Performance – Authenticated (Administrator+) Remote Code Execution
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Remote Code Execution CVE: CVE-2026-19224 Number of Installations: 70,000+ Affected Software: Hummingbird Performance < 3.21.2 Patched Versions: 3.21.2
Mitigation steps: Update to Hummingbird Performance version 3.21.2 or greater.
Media Library Assistant – Authenticated (Contributor+) SQL Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) SQL Injection CVE: CVE-2026-97293 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.41 Patched Versions: 3.42
Mitigation steps: Update to Media Library Assistant version 3.42 or greater.
Ninja Tables – Unauthenticated Arbitrary Shortcode Execution
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-86612 Number of Installations: 70,000+ Affected Software: Ninja Tables ≤ 5.2.16 Patched Versions: 5.2.17
Mitigation steps: Update to Ninja Tables version 5.2.17 or greater.
HT Mega Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table ‘display_options’ Setting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting CVE: CVE-2026-11895 Number of Installations: 70,000+ Affected Software: HT Mega Addons for Elementor ≤ 3.1.1 Patched Versions: 3.1.2
Mitigation steps: Update to HT Mega Addons for Elementor version 3.1.2 or greater.
HT Mega Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-86788 Number of Installations: 70,000+ Affected Software: HT Mega Addons for Elementor 3.2.0 - 3.2.5 Patched Versions: 3.2.6
Mitigation steps: Update to HT Mega Addons for Elementor version 3.2.6 or greater.
Media Library Assistant – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘mla_link_href’ Shortcode Parameter
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter CVE: CVE-2026-6641 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.35 Patched Versions: 3.36
Mitigation steps: Update to Media Library Assistant version 3.36 or greater.
Media Library Assistant – Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import CVE: CVE-2026-6642 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.35 Patched Versions: 3.36
Mitigation steps: Update to Media Library Assistant version 3.36 or greater.
Media Library Assistant – Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter CVE: CVE-2026-6640 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.35 Patched Versions: 3.36
Mitigation steps: Update to Media Library Assistant version 3.36 or greater.
LearnPress – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘layout_custom_css’
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' CVE: CVE-2026-12230 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.3.9.1 Patched Versions: 4.4.0
Mitigation steps: Update to LearnPress version 4.4.0 or greater.
Greenshift – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-83544 Number of Installations: 70,000+ Affected Software: Greenshift < 13.2.0 Patched Versions: 13.2.0
Mitigation steps: Update to Greenshift version 13.2.0 or greater.
Greenshift – Authenticated (Contributor+) Server-Side Request Forgery
Security Risk: Low Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery CVE: CVE-2026-83543 Number of Installations: 70,000+ Affected Software: Greenshift < 13.2.0 Patched Versions: 13.2.0
Mitigation steps: Update to Greenshift version 13.2.0 or greater.
LearnPress – Authenticated (Instructor+) Stored Cross-Site Scripting
Security Risk: TBC Exploitation Level: Requires Instructor or higher level authentication. Vulnerability: Authenticated (Instructor+) Stored Cross-Site Scripting CVE: CVE-2026-82024 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.5 Patched Versions: 4.4.6
Mitigation steps: Update to LearnPress version 4.4.6 or greater.
Import and export users and customers – Authenticated (Subscriber+) Privilege Escalation
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Privilege Escalation CVE: CVE-2026-94178 Number of Installations: 70,000+ Affected Software: Import and export users and customers ≤ 2.5.2 Patched Versions: 2.5.4
Mitigation steps: Update to Import and export users and customers version 2.5.4 or greater.
LearnPress – Reflected Cross-Site Scripting
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-86444 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.6 Patched Versions: 4.4.7
Mitigation steps: Update to LearnPress version 4.4.7 or greater.
Import and export users and customers – Authenticated (Administrator+) Server-Side Request Forgery
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Server-Side Request Forgery CVE: CVE-2026-16542 Number of Installations: 70,000+ Affected Software: Import and export users and customers ≤ 2.4.4 Patched Versions: 2.4.5
Mitigation steps: Update to Import and export users and customers version 2.4.5 or greater.
10Web Booster – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-82195 Number of Installations: 70,000+ Affected Software: 10Web Booster ≤ 2.33.0 Patched Versions: 2.34.0
Mitigation steps: Update to 10Web Booster version 2.34.0 or greater.
WPC Smart Compare for WooCommerce – Unauthenticated Information Exposure
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-90985 Number of Installations: 70,000+ Affected Software: WPC Smart Compare for WooCommerce ≤ 6.6.0 Patched Versions: 6.6.1
Mitigation steps: Update to WPC Smart Compare for WooCommerce version 6.6.1 or greater.
LearnPress – Unauthenticated Information Exposure
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-86446 Number of Installations: 70,000+ Affected Software: LearnPress 4.4.3 - 4.4.6 Patched Versions: 4.4.7
Mitigation steps: Update to LearnPress version 4.4.7 or greater.
3D FlipBook – Unauthenticated Sensitive Information Exposure in ‘id’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Sensitive Information Exposure in 'id' Parameter CVE: CVE-2026-15758 Number of Installations: 70,000+ Affected Software: 3D FlipBook ≤ 1.16.20 Patched Versions: 1.16.21
Mitigation steps: Update to 3D FlipBook version 1.16.21 or greater.
LearnPress – Unauthenticated Information Exposure
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-86448 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.6 Patched Versions: 4.4.7
Mitigation steps: Update to LearnPress version 4.4.7 or greater.
Slim SEO – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-62113 Number of Installations: 70,000+ Affected Software: Slim SEO ≤ 4.10.0 Patched Versions: 4.10.1
Mitigation steps: Update to Slim SEO version 4.10.1 or greater.
LearnPress – Missing Authorization
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Missing Authorization CVE: CVE-2026-82023 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.5 Patched Versions: 4.4.6
Mitigation steps: Update to LearnPress version 4.4.6 or greater.
Ultra Addons for Contact Form 7 – Unauthenticated Arbitrary File Upload via Signature Form Field
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary File Upload via Signature Form Field CVE: CVE-2026-82901 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.50 Patched Versions: 3.5.51
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.51 or greater.
Ultra Addons for Contact Form 7 – Unauthenticated Arbitrary File Upload
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary File Upload CVE: CVE-2026-84750 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 3.2.4 - 3.5.50 Patched Versions: 3.5.51
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.51 or greater.
Online Scheduling and Appointment Booking System – Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via ‘order_id’ Parameter
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter CVE: CVE-2026-93399 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
WP Ultimate Review – Authenticated (Subscriber+) Arbitrary Shortcode Execution via ‘xs_submit_review_data[xs_reviw_summery]’ Parameter
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter CVE: CVE-2026-92235 Number of Installations: 60,000+ Affected Software: WP Ultimate Review ≤ 2.4.2 Patched Versions: 2.4.3
Mitigation steps: Update to WP Ultimate Review version 2.4.3 or greater.
Site Reviews – Unauthenticated PHP Object Injection
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-82925 Number of Installations: 60,000+ Affected Software: Site Reviews 7.2.2 - 8.2.2 Patched Versions: 8.3.0
Mitigation steps: Update to Site Reviews version 8.3.0 or greater.
Online Scheduling and Appointment Booking System – Authenticated (Bookly Administrator+) PHP Object Injection
Security Risk: Low Exploitation Level: Requires Bookly Administratoristrator or higher level authentication. Vulnerability: Authenticated (Bookly Administrator+) PHP Object Injection CVE: CVE-2026-86841 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System 23.2 - 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
WP Maps – Authenticated (Subscriber+) Local File Inclusion via ‘page’ Parameter
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter CVE: CVE-2026-13456 Number of Installations: 60,000+ Affected Software: WP Maps ≤ 4.9.8 Patched Versions: 5.0.0
Mitigation steps: Update to WP Maps version 5.0.0 or greater.
Online Scheduling and Appointment Booking System – Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via ‘conversation_id’ Parameter
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter CVE: CVE-2026-89063 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.1 Patched Versions: 28.2
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.2 or greater.
Comments – Unauthenticated SQL Injection
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-19704 Number of Installations: 60,000+ Affected Software: Comments < 7.6.66 Patched Versions: 7.6.66
Mitigation steps: Update to Comments version 7.6.66 or greater.
Site Reviews – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-94078 Number of Installations: 60,000+ Affected Software: Site Reviews ≤ 8.3.1 Patched Versions: 8.3.2
Mitigation steps: Update to Site Reviews version 8.3.2 or greater.
Ultra Addons for Contact Form 7 – Authenticated (Editor+) PHP Object Injection
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) PHP Object Injection CVE: CVE-2026-96833 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.51 Patched Versions: 3.5.52
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.52 or greater.
WP Maps – Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter CVE: CVE-2026-13179 Number of Installations: 60,000+ Affected Software: WP Maps ≤ 4.9.8 Patched Versions: 5.0.0
Mitigation steps: Update to WP Maps version 5.0.0 or greater.
Ultra Addons for Contact Form 7 – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-95586 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.50 Patched Versions: 3.5.51
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.51 or greater.
Master Slider – Authenticated (Contributor+) Stored Cross-Site Scripting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-14844 Number of Installations: 60,000+ Affected Software: Master Slider ≤ 3.11.2 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Brizy – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘rootAttributes’ Parameter
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter CVE: CVE-2026-2585 Number of Installations: 60,000+ Affected Software: Brizy ≤ 2.8.14 Patched Versions: 2.8.15
Mitigation steps: Update to Brizy version 2.8.15 or greater.
Advanced Popups – Authenticated (Author+) Stored Cross-Site Scripting via ‘Notification Button Link’ Field
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field CVE: CVE-2026-11996 Number of Installations: 60,000+ Affected Software: Advanced Popups ≤ 1.2.3 Patched Versions: 1.2.4
Mitigation steps: Update to Advanced Popups version 1.2.4 or greater.
Theme My Login – Authenticated (Subscriber+) Privilege Escalation
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Privilege Escalation CVE: CVE-2026-81583 Number of Installations: 60,000+ Affected Software: Theme My Login 7.0 - 7.1.15 Patched Versions: 7.2.0
Mitigation steps: Update to Theme My Login version 7.2.0 or greater.
Online Scheduling and Appointment Booking System – Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update CVE: CVE-2026-2520 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 27.2 Patched Versions: 27.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 27.3 or greater.
Events Manager – Unauthenticated Stored Cross-Site Scripting via Event Attributes
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Event Attributes CVE: CVE-2025-14945 Number of Installations: 60,000+ Affected Software: Events Manager ≤ 7.3.3 Patched Versions: 7.3.4
Mitigation steps: Update to Events Manager version 7.3.4 or greater.
Online Scheduling and Appointment Booking System – Unauthenticated Payment Bypass
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Payment Bypass CVE: CVE-2026-86838 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
Online Scheduling and Appointment Booking System – Unauthenticated Insecure Direct Object Reference
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-86837 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
Online Scheduling and Appointment Booking System – Unauthenticated Authorization Bypass via PHP Type Juggling via ‘verification_code’ Parameter Type Juggling via json_data
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data CVE: CVE-2026-92799 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
Online Scheduling and Appointment Booking System – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-96348 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
Online Scheduling and Appointment Booking System – Unauthenticated Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-91847 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.1 Patched Versions: 28.2
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.2 or greater.
WP Maps – Authenticated (Administrator+) SQL Injection
Security Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-66618 Number of Installations: 60,000+ Affected Software: WP Maps ≤ 4.9.9 Patched Versions: 5.0.0
Mitigation steps: Update to WP Maps version 5.0.0 or greater.
Online Scheduling and Appointment Booking System – Authenticated (Staff+) Insecure Direct Object Reference
Security Risk: TBC Exploitation Level: Requires Staff or higher level authentication. Vulnerability: Authenticated (Staff+) Insecure Direct Object Reference CVE: CVE-2026-86839 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
Online Scheduling and Appointment Booking System – Authenticated (Subscriber+) Insecure Direct Object Reference
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Insecure Direct Object Reference CVE: CVE-2026-96347 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2 Patched Versions: 28.3
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.
Events Manager – Authenticated (Subscriber+) Information Exposure
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-93662 Number of Installations: 60,000+ Affected Software: Events Manager 7.4.1 - 7.4.4 Patched Versions: 7.4.5
Mitigation steps: Update to Events Manager version 7.4.5 or greater.
Events Manager – Authenticated (Contributor+) Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-93661 Number of Installations: 60,000+ Affected Software: Events Manager ≤ 7.4.4 Patched Versions: 7.4.5
Mitigation steps: Update to Events Manager version 7.4.5 or greater.
Theme My Login – Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via ‘gimmeanotherblog’ Signup Stage
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage CVE: CVE-2026-83628 Number of Installations: 60,000+ Affected Software: Theme My Login ≤ 7.1.15 Patched Versions: 7.2.0
Mitigation steps: Update to Theme My Login version 7.2.0 or greater.
WP Recipe Maker – Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content CVE: CVE-2026-89274 Number of Installations: 50,000+ Affected Software: WP Recipe Maker ≤ 10.8.1 Patched Versions: 10.8.2
Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.
Simply Schedule Appointments – Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via ‘recursive’ Parameter on the appointment_types REST Endpoint via Public Nonce
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce CVE: CVE-2026-92245 Number of Installations: 50,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.32 Patched Versions: 1.6.12.33
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.
Simply Schedule Appointments – Authenticated (Subscriber+) Local File Inclusion via ‘ssa_locale’ Parameter
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter CVE: CVE-2026-89294 Number of Installations: 50,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.27 Patched Versions: 1.6.12.33
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.
WP Store Locator – Unauthenticated Denial of Service
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-94681 Number of Installations: 50,000+ Affected Software: WP Store Locator < 3.0.0 Patched Versions: 3.0.0
Mitigation steps: Update to WP Store Locator version 3.0.0 or greater.
Product Filter for WooCommerce by WBW – Unauthenticated SQL Injection
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-95601 Number of Installations: 50,000+ Affected Software: Product Filter for WooCommerce by WBW ≤ 3.1.7 Patched Versions: 3.1.8
Mitigation steps: Update to Product Filter for WooCommerce by WBW version 3.1.8 or greater.
RTMKit – Authenticated (Contributor+) PHP Object Injection
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) PHP Object Injection CVE: CVE-2026-84752 Number of Installations: 50,000+ Affected Software: RTMKit ≤ 2.1.5 Patched Versions: 2.1.6
Mitigation steps: Update to RTMKit version 2.1.6 or greater.
User Registration & Membership – Unauthenticated Open Redirect
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Open Redirect CVE: CVE-2026-80072 Number of Installations: 50,000+ Affected Software: User Registration & Membership < 5.2.8 Patched Versions: 5.2.8
Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.
RTMKit – Unauthenticated Stored Cross-Site Scripting
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-84763 Number of Installations: 50,000+ Affected Software: RTMKit ≤ 2.1.5 Patched Versions: 2.1.6
Mitigation steps: Update to RTMKit version 2.1.6 or greater.
WP Table Builder – Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via ‘ids’ Parameter
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter CVE: CVE-2026-6922 Number of Installations: 50,000+ Affected Software: WP Table Builder ≤ 2.2.1 Patched Versions: 2.2.2
Mitigation steps: Update to WP Table Builder version 2.2.2 or greater.
Simply Schedule Appointments – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via ‘complete_group’ Parameter
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter CVE: CVE-2026-91109 Number of Installations: 50,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.31 Patched Versions: 1.6.12.33
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.
WP Recipe Maker – Unauthenticated Arbitrary Shortcode Execution
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-86601 Number of Installations: 50,000+ Affected Software: WP Recipe Maker ≤ 10.8.1 Patched Versions: 10.8.2
Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.
Email Subscribers & Newsletters – Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field CVE: CVE-2026-12757 Number of Installations: 50,000+ Affected Software: Email Subscribers & Newsletters ≤ 5.9.27 Patched Versions: 5.9.28
Mitigation steps: Update to Email Subscribers & Newsletters version 5.9.28 or greater.
Contextual Related Posts – Authenticated (Author+) Stored Cross-Site Scripting via ‘other_attributes’ Block Parameter
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter CVE: CVE-2026-85653 Number of Installations: 50,000+ Affected Software: Contextual Related Posts ≤ 4.4.1 Patched Versions: 4.4.2
Mitigation steps: Update to Contextual Related Posts version 4.4.2 or greater.
Gum Addon for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘pop_tag’ Widget Setting
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting CVE: CVE-2026-8354 Number of Installations: 50,000+ Affected Software: Gum Addon for Elementor ≤ 1.3.15 Patched Versions: 1.3.16
Mitigation steps: Update to Gum Addon for Elementor version 1.3.16 or greater.
Getwid – Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps ‘customStyle’
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle' CVE: CVE-2026-5924 Number of Installations: 50,000+ Affected Software: Getwid 2.1.3 Patched Versions: 2.2.0
Mitigation steps: Update to Getwid version 2.2.0 or greater.
User Registration & Membership – Authenticated (Author+) Privilege Escalation
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Privilege Escalation CVE: CVE-2026-80071 Number of Installations: 50,000+ Affected Software: User Registration & Membership < 5.2.8 Patched Versions: 5.2.8
Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.
User Registration & Membership – Authenticated (Subscriber+) Privilege Escalation
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Privilege Escalation CVE: CVE-2026-86406 Number of Installations: 50,000+ Affected Software: User Registration & Membership 4.4.6 - 5.2.7 Patched Versions: 5.2.8
Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.
WP-Members Membership Plugin – Reflected Cross-Site Scripting
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-84960 Number of Installations: 50,000+ Affected Software: WP-Members Membership Plugin ≤ 3.5.6 Patched Versions: 3.5.7
Mitigation steps: Update to WP-Members Membership Plugin version 3.5.7 or greater.
Product Filter for WooCommerce by WBW – Reflected Cross-Site Scripting via ‘wpf_fid’ Parameter
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'wpf_fid' Parameter CVE: CVE-2026-7804 Number of Installations: 50,000+ Affected Software: Product Filter for WooCommerce by WBW ≤ 3.4.2 Patched Versions: 3.4.3
Mitigation steps: Update to Product Filter for WooCommerce by WBW version 3.4.3 or greater.
WP Recipe Maker – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘notes’ Parameter via REST Preview Endpoint
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint CVE: CVE-2026-90884 Number of Installations: 50,000+ Affected Software: WP Recipe Maker ≤ 10.8.1 Patched Versions: 10.8.2
Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.
Simply Schedule Appointments – Unauthenticated Insecure Direct Object Reference
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-94673 Number of Installations: 50,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.31 Patched Versions: 1.6.12.33
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.
Simply Schedule Appointments – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-94074 Number of Installations: 50,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.29 Patched Versions: 1.6.12.31
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.31 or greater.
Email Subscribers & Newsletters – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-83555 Number of Installations: 50,000+ Affected Software: Email Subscribers & Newsletters ≤ 5.9.34 Patched Versions: 5.9.35
Mitigation steps: Update to Email Subscribers & Newsletters version 5.9.35 or greater.
WP Recipe Maker – Unauthenticated Arbitrary User Meta Corruption
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary User Meta Corruption CVE: CVE-2026-86608 Number of Installations: 50,000+ Affected Software: WP Recipe Maker 9.8.0 - 10.8.1 Patched Versions: 10.8.2
Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.
User Registration & Membership – Missing Authorization
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-74017 Number of Installations: 50,000+ Affected Software: User Registration & Membership ≤ 5.2.7 Patched Versions: 5.2.8
Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.
User Registration & Membership – Unauthenticated Information Exposure
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-86407 Number of Installations: 50,000+ Affected Software: User Registration & Membership 5.0 - 5.2.7 Patched Versions: 5.2.8
Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.
المنتور فارسی – Payment Bypass to Unauthenticated Unauthorized Order Completion
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Payment Bypass to Unauthenticated Unauthorized Order Completion CVE: CVE-2026-86809 Number of Installations: 50,000+ Affected Software: المنتور فارسی 2.7.10 - 2.8.1 Patched Versions: 2.8.2
Mitigation steps: Update to المنتور فارسی version 2.8.2 or greater.
Email Subscribers & Newsletters – Authenticated (Administrator+) Stored Cross-Site Scripting
Security Risk: Minimal Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting CVE: CVE-2025-15692 Number of Installations: 50,000+ Affected Software: Email Subscribers & Newsletters ≤ 5.8.5 Patched Versions: 5.8.6
Mitigation steps: Update to Email Subscribers & Newsletters version 5.8.6 or greater.
Blog2Social: Social Media Auto Post & Scheduler – Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers CVE: CVE-2026-92829 Number of Installations: 50,000+ Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.1.0 Patched Versions: 9.1.1
Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.1 or greater.
WP Recipe Maker – Authenticated (Subscriber+) Information Exposure
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-86603 Number of Installations: 50,000+ Affected Software: WP Recipe Maker ≤ 10.8.1 Patched Versions: 10.8.2
Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.
WP Recipe Maker – Authenticated (Subscriber+) Information Exposure
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-86602 Number of Installations: 50,000+ Affected Software: WP Recipe Maker 10.3.0 - 10.8.1 Patched Versions: 10.8.2
Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.
Blog2Social: Social Media Auto Post & Scheduler – Insecure Direct Object Reference
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Insecure Direct Object Reference CVE: CVE-2026-89031 Number of Installations: 50,000+ Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.0.0 Patched Versions: 9.1.0
Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.0 or greater.
Blog2Social: Social Media Auto Post & Scheduler – Authenticated (Subscriber+) Username Enumeration
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Username Enumeration CVE: CVE-2026-89029 Number of Installations: 50,000+ Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.0.0 Patched Versions: 9.1.0
Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.0 or greater.
Blog2Social: Social Media Auto Post & Scheduler – Missing Authorization
Security Risk: Medium Exploitation Level: Requires custom role. Vulnerability: Missing Authorization CVE: CVE-2026-89030 Number of Installations: 50,000+ Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.0.0 Patched Versions: 9.1.0
Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.0 or greater.
Seraphinite Accelerator – Authenticated (Subscriber+) Full Admin Area Denial of Service
Security Risk: Low Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Full Admin Area Denial of Service CVE: CVE-2026-87828 Number of Installations: 50,000+ Affected Software: Seraphinite Accelerator ≤ 2.29.23 Patched Versions: 2.29.24
Mitigation steps: Update to Seraphinite Accelerator version 2.29.24 or greater.
WP Recipe Maker – Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via ‘[wprm-recipe]’ Shortcode
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via '[wprm-recipe]' Shortcode CVE: CVE-2026-75905 Number of Installations: 50,000+ Affected Software: WP Recipe Maker ≤ 10.8.0 Patched Versions: 10.8.1
Mitigation steps: Update to WP Recipe Maker version 10.8.1 or greater.
Themes
Astra – Authenticated (Shop Manager+) Arbitrary CSS Injection
Security Risk: High Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Arbitrary CSS Injection CVE: CVE-2026-27085 Number of Installations: 1,000,000+ Affected Software: Astra ≤ 4.13.12 Patched Versions: 4.14.0
Mitigation steps: Update to Astra version 4.14.0 or greater.
Update your website software to reduce risk. Users unable to upgrade to the latest version are advised to implement a web application firewall, which can virtually patch known vulnerabilities and safeguard their website.








