If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.
To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.
For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-18978 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.8.1 Patched Versions: 7.9
Mitigation steps: Update to LiteSpeed Cache version 7.9 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes CVE: CVE-2026-3129 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.7 Patched Versions: 7.8
Mitigation steps: Update to LiteSpeed Cache version 7.8 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution CVE: CVE-2026-19949 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.109 Patched Versions: 7.110
Mitigation steps: Update to All-in-One WP Migration and Backup version 7.110 or greater.
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Remote Code Execution CVE: CVE-2026-17533 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup < 7.108 Patched Versions: 7.108
Mitigation steps: Update to All-in-One WP Migration and Backup version 7.108 or greater.
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-18039 Number of Installations: 1,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.7.1 Patched Versions: 6.7.2
Mitigation steps: Update to Essential Addons for Elementor version 6.7.2 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via HTTP Host Header CVE: CVE-2026-19760 Number of Installations: 1,000,000+ Affected Software: WP Fastest Cache ≤ 1.5.0 Patched Versions: 1.5.1
Mitigation steps: Update to WP Fastest Cache version 1.5.1 or greater.
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Remote Code Execution CVE: CVE-2026-13392 Number of Installations: 1,000,000+ Affected Software: ElementsKit Elementor Addons < 3.10.01 Patched Versions: 3.10.01
Mitigation steps: Update to ElementsKit Elementor Addons version 3.10.01 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages CVE: CVE-2026-4561 Number of Installations: 1,000,000+ Affected Software: MC4WP: Mailchimp for WordPress ≤ 4.12.0 Patched Versions: 4.12.1
Mitigation steps: Update to MC4WP: Mailchimp for WordPress version 4.12.1 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content CVE: CVE-2026-15446 Number of Installations: 1,000,000+ Affected Software: EWWW Image Optimizer ≤ 8.7.3 Patched Versions: 8.7.4
Mitigation steps: Update to EWWW Image Optimizer version 8.7.4 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes CVE: CVE-2026-15421 Number of Installations: 1,000,000+ Affected Software: Speed Optimizer ≤ 7.8.0 Patched Versions: 7.8.1
Mitigation steps: Update to Speed Optimizer version 7.8.1 or greater.
Security Risk: High Exploitation Level: Requires Translator or higher level authentication. Vulnerability: Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments CVE: CVE-2026-15066 Number of Installations: 1,000,000+ Affected Software: Loco Translate ≤ 2.8.7 Patched Versions: 2.8.8
Mitigation steps: Update to Loco Translate version 2.8.8 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint CVE: CVE-2026-17153 Number of Installations: 1,000,000+ Affected Software: AI Agent by SiteGround ≤ 1.2.7 Patched Versions: 1.2.8
Mitigation steps: Update to AI Agent by SiteGround version 1.2.8 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via REQUEST_URI Query String CVE: CVE-2026-15452 Number of Installations: 1,000,000+ Affected Software: Smash Balloon Social Photo Feed ≤ 6.11.3 Patched Versions: 6.11.4
Mitigation steps: Update to Smash Balloon Social Photo Feed version 6.11.4 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Path Traversal CVE: CVE-2026-18051 Number of Installations: 900,000+ Affected Software: W3 Total Cache < 2.10.5 Patched Versions: 2.10.5
Mitigation steps: Update to W3 Total Cache version 2.10.5 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Path Traversal CVE: CVE-2026-19725 Number of Installations: 900,000+ Affected Software: WPvivid < 0.9.131 Patched Versions: 0.9.131
Mitigation steps: Update to WPvivid version 0.9.131 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Author Name CVE: CVE-2026-18109 Number of Installations: 900,000+ Affected Software: W3 Total Cache ≤ 2.10.3 Patched Versions: 2.10.4
Mitigation steps: Update to W3 Total Cache version 2.10.4 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute CVE: CVE-2026-15798 Number of Installations: 800,000+ Affected Software: Smart Slider 3 ≤ 3.5.1.38 Patched Versions: 3.5.1.39
Mitigation steps: Update to Smart Slider 3 version 3.5.1.39 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values CVE: CVE-2026-18146 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.11 Patched Versions: 6.2.12
Mitigation steps: Update to Fluent Forms version 6.2.12 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-28177 Number of Installations: 700,000+ Affected Software: Popup Maker ≤ 1.23.0 Patched Versions: 1.24.0
Mitigation steps: Update to Popup Maker version 1.24.0 or greater.
Security Risk: High Exploitation Level: Requires Form Manager or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion CVE: CVE-2026-11578 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.4 Patched Versions: 6.2.5
Mitigation steps: Update to Fluent Forms version 6.2.5 or greater.
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation CVE: CVE-2026-11880 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.0 Patched Versions: 6.2.1
Mitigation steps: Update to Fluent Forms version 6.2.1 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration CVE: CVE-2026-15748 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.1 Patched Versions: 1.56.2
Mitigation steps: Update to Forminator Forms version 1.56.2 or greater.
Security Risk: High Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting CVE: CVE-2026-17123 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor ≤ 1.7.1064 Patched Versions: 1.7.1065
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1065 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Privilege Escalation CVE: CVE-2026-28111 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.0 Patched Versions: 1.56.0.1
Mitigation steps: Update to Forminator Forms version 1.56.0.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-66583 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0 Patched Versions: 1.57.1
Mitigation steps: Update to Forminator Forms version 1.57.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field CVE: CVE-2026-18324 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0.1 Patched Versions: 1.57.0.2
Mitigation steps: Update to Forminator Forms version 1.57.0.2 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter CVE: CVE-2026-18328 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0 Patched Versions: 1.57.0.1
Mitigation steps: Update to Forminator Forms version 1.57.0.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) CVE: CVE-2026-18323 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.57.0.2 Patched Versions: 1.57.0.3
Mitigation steps: Update to Forminator Forms version 1.57.0.3 or greater.
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Remote Code Execution CVE: CVE-2026-13405 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor < 1.7.1066 Patched Versions: 1.7.1066
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1066 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter CVE: CVE-2026-15780 Number of Installations: 600,000+ Affected Software: WP Statistics ≤ 14.16.8 Patched Versions: 14.16.9
Mitigation steps: Update to WP Statistics version 14.16.9 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61982 Number of Installations: 600,000+ Affected Software: SiteGuard WP Plugin ≤ 1.8.6 Patched Versions: 1.8.7
Mitigation steps: Update to SiteGuard WP Plugin version 1.8.7 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs CVE: CVE-2026-16636 Number of Installations: 600,000+ Affected Software: FluentSMTP ≤ 2.2.95 Patched Versions: 2.3.0
Mitigation steps: Update to FluentSMTP version 2.3.0 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field CVE: CVE-2026-18325 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.1 Patched Versions: 1.56.2
Mitigation steps: Update to Forminator Forms version 1.56.2 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-28143 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.56.0 Patched Versions: 1.56.1
Mitigation steps: Update to Forminator Forms version 1.56.1 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting CVE: CVE-2026-18100 Number of Installations: 600,000+ Affected Software: MetForm ≤ 4.1.8 Patched Versions: 4.1.9
Mitigation steps: Update to MetForm version 4.1.9 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-19217 Number of Installations: 600,000+ Affected Software: Royal Addons for Elementor ≤ 1.7.1064 Patched Versions: 1.7.1065
Mitigation steps: Update to Royal Addons for Elementor version 1.7.1065 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter CVE: CVE-2026-12998 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.55.0.2 Patched Versions: 1.55.1
Mitigation steps: Update to Forminator Forms version 1.55.1 or greater.
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-16562 Number of Installations: 600,000+ Affected Software: WP Statistics ≤ 14.16.9 Patched Versions: 14.16.10
Mitigation steps: Update to WP Statistics version 14.16.10 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution CVE: CVE-2026-16747 Number of Installations: 500,000+ Affected Software: Kirki < 6.2.1 Patched Versions: 6.2.1
Mitigation steps: Update to Kirki version 6.2.1 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution CVE: CVE-2026-18937 Number of Installations: 500,000+ Affected Software: Broken Link Checker < 2.4.12 Patched Versions: 2.4.12
Mitigation steps: Update to Broken Link Checker version 2.4.12 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-12720 Number of Installations: 500,000+ Affected Software: Kirki < 6.0.13 Patched Versions: 6.0.13
Mitigation steps: Update to Kirki version 6.0.13 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66629 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.2.4 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode CVE: CVE-2026-16974 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.2.0 Patched Versions: 6.2.1
Mitigation steps: Update to Kirki version 6.2.1 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting CVE: CVE-2026-18400 Number of Installations: 500,000+ Affected Software: Slider, Gallery, and Carousel by MetaSlider ≤ 3.111.0 Patched Versions: 3.111.1
Mitigation steps: Update to Slider, Gallery, and Carousel by MetaSlider version 3.111.1 or greater.
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter CVE: CVE-2026-17604 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.1.1 Patched Versions: 6.2.0
Mitigation steps: Update to Kirki version 6.2.0 or greater.
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting CVE: CVE-2026-74992 Number of Installations: 500,000+ Affected Software: Kirki < 6.2.3 Patched Versions: 6.2.3
Mitigation steps: Update to Kirki version 6.2.3 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter CVE: CVE-2026-18347 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.1.1 Patched Versions: 6.2.0
Mitigation steps: Update to Kirki version 6.2.0 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-15248 Number of Installations: 500,000+ Affected Software: Meta Box < 5.13.1 Patched Versions: 5.13.1
Mitigation steps: Update to Meta Box version 5.13.1 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Account Takeover via Password Reset Link Disclosure CVE: CVE-2026-19632 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.1 Patched Versions: 3.3.2
Mitigation steps: Update to TranslatePress version 3.3.2 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser CVE: CVE-2026-76053 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.3 Patched Versions: 3.3.4
Mitigation steps: Update to TranslatePress version 3.3.4 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66582 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.3.2 Patched Versions: 3.3.3
Mitigation steps: Update to TranslatePress version 3.3.3 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-75981 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.5 Patched Versions: 3.2.6
Mitigation steps: Update to TranslatePress version 3.2.6 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-18510 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.6 Patched Versions: 3.3
Mitigation steps: Update to TranslatePress version 3.3 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor CVE: CVE-2026-18512 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.6 Patched Versions: 3.3
Mitigation steps: Update to TranslatePress version 3.3 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-17505 Number of Installations: 400,000+ Affected Software: TranslatePress ≤ 3.2.5 Patched Versions: 3.2.6
Mitigation steps: Update to TranslatePress version 3.2.6 or greater.
Security Risk: High Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch CVE: CVE-2026-18438 Number of Installations: 300,000+ Affected Software: Templately ≤ 3.7.1 Patched Versions: 3.7.2
Mitigation steps: Update to Templately version 3.7.2 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-15381 Number of Installations: 300,000+ Affected Software: WP Go Maps < 10.1.04 Patched Versions: 10.1.04
Mitigation steps: Update to WP Go Maps version 10.1.04 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter CVE: CVE-2026-18331 Number of Installations: 300,000+ Affected Software: Formidable Forms ≤ 6.33.1 Patched Versions: 6.34
Mitigation steps: Update to Formidable Forms version 6.34 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66667 Number of Installations: 300,000+ Affected Software: Templately ≤ 3.7.1 Patched Versions: 3.7.2
Mitigation steps: Update to Templately version 3.7.2 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-28141 Number of Installations: 300,000+ Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.2.3 Patched Versions: 4.2.4
Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.2.4 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Arbitrary File Download CVE: CVE-2026-28146 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.14 Patched Versions: 2.0.15
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.15 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) CVE: CVE-2026-18488 Number of Installations: 300,000+ Affected Software: Blocksy Companion ≤ 2.1.51 Patched Versions: 2.1.52
Mitigation steps: Update to Blocksy Companion version 2.1.52 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Arbitrary Content Deletion CVE: CVE-2026-73356 Number of Installations: 300,000+ Affected Software: Breeze Cache ≤ 2.5.12 Patched Versions: 2.5.13
Mitigation steps: Update to Breeze Cache version 2.5.13 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Block Visibility Bypass via ai_ajax CVE: CVE-2026-11983 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.16 Patched Versions: 2.8.17
Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-15359 Number of Installations: 300,000+ Affected Software: Templately ≤ 3.7.0 Patched Versions: 3.7.1
Mitigation steps: Update to Templately version 3.7.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-14943 Number of Installations: 300,000+ Affected Software: Password Protected ≤ 2.8.3 Patched Versions: 2.8.4
Mitigation steps: Update to Password Protected version 2.8.4 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-19085 Number of Installations: 300,000+ Affected Software: Duplicate Post < 1.5.6 Patched Versions: 1.5.6
Mitigation steps: Update to Duplicate Post version 1.5.6 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-28147 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.15 Patched Versions: 2.0.16
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.16 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-12251 Number of Installations: 200,000+ Affected Software: Ultimate Member < 2.12.1 Patched Versions: 2.12.1
Mitigation steps: Update to Ultimate Member version 2.12.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter CVE: CVE-2026-77365 Number of Installations: 200,000+ Affected Software: Optimole ≤ 4.2.10 Patched Versions: 4.2.11
Mitigation steps: Update to Optimole version 4.2.11 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66596 Number of Installations: 200,000+ Affected Software: Newsletter ≤ 9.3.3 Patched Versions: 9.3.4
Mitigation steps: Update to Newsletter version 9.3.4 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) CVE: CVE-2026-18547 Number of Installations: 200,000+ Affected Software: Ultimate Member ≤ 2.12.1 Patched Versions: 2.13.0
Mitigation steps: Update to Ultimate Member version 2.13.0 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-19615 Number of Installations: 200,000+ Affected Software: Admin and Site Enhancements (ASE) < 9.0.1 Patched Versions: 9.0.1
Mitigation steps: Update to Admin and Site Enhancements (ASE) version 9.0.1 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute CVE: CVE-2026-16775 Number of Installations: 200,000+ Affected Software: Smash Balloon Social Post Feed ≤ 4.9.0 Patched Versions: 4.10.0
Mitigation steps: Update to Smash Balloon Social Post Feed version 4.10.0 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-73997 Number of Installations: 200,000+ Affected Software: Kadence Starter Templates ≤ 2.3.3 Patched Versions: 2.3.4
Mitigation steps: Update to Kadence Starter Templates version 2.3.4 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-13153 Number of Installations: 200,000+ Affected Software: Gutenberg Essential Blocks ≤ 6.3.0 Patched Versions: 6.4.0
Mitigation steps: Update to Gutenberg Essential Blocks version 6.4.0 or greater.
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-74011 Number of Installations: 200,000+ Affected Software: InfiniteWP Client ≤ 1.13.9 Patched Versions: 1.13.10
Mitigation steps: Update to InfiniteWP Client version 1.13.10 or greater.
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection CVE: CVE-2026-73346 Number of Installations: 200,000+ Affected Software: Mailchimp for WooCommerce < 6.2 Patched Versions: 6.2
Mitigation steps: Update to Mailchimp for WooCommerce version 6.2 or greater.
Security Risk: Medium Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection via 's' Parameter CVE: CVE-2026-5062 Number of Installations: 200,000+ Affected Software: PrettyLinks ≤ 3.6.20 Patched Versions: 3.6.21
Mitigation steps: Update to PrettyLinks version 3.6.21 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author Attribution CVE: CVE-2026-4244 Number of Installations: 200,000+ Affected Software: Post Duplicator ≤ 3.0.11 Patched Versions: 3.0.12
Mitigation steps: Update to Post Duplicator version 3.0.12 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authorization Bypass to Authenticated (Contributor+) Post Duplication CVE: CVE-2026-4245 Number of Installations: 200,000+ Affected Software: Post Duplicator ≤ 3.0.11 Patched Versions: 3.0.12
Mitigation steps: Update to Post Duplicator version 3.0.12 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection to Remote Code Execution CVE: CVE-2026-82222 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.7.1 Patched Versions: 4.16.7.2
Mitigation steps: Update to GiveWP version 4.16.7.2 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router CVE: CVE-2026-19598 Number of Installations: 100,000+ Affected Software: Pods 2.8 - 2.8.23.3 Patched Versions: 3.3.9.1
Mitigation steps: Update to Pods version 3.3.9.1 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter CVE: CVE-2026-18983 Number of Installations: 100,000+ Affected Software: One User Avatar ≤ 2.5.4 Patched Versions: 2.5.5
Mitigation steps: Update to One User Avatar version 2.5.5 or greater.
Security Risk: High Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes CVE: CVE-2026-75971 Number of Installations: 100,000+ Affected Software: ShopEngine Elementor WooCommerce Builder Addon ≤ 4.9.4 Patched Versions: 4.9.5
Mitigation steps: Update to ShopEngine Elementor WooCommerce Builder Addon version 4.9.5 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66623 Number of Installations: 100,000+ Affected Software: Social Media Share Buttons & Social Sharing Icons ≤ 2.9.9 Patched Versions: 3.0.0
Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.0 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-14292 Number of Installations: 100,000+ Affected Software: Download Manager < 3.3.66 Patched Versions: 3.3.66
Mitigation steps: Update to Download Manager version 3.3.66 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-17506 Number of Installations: 100,000+ Affected Software: Independent Analytics ≤ 2.15.0 Patched Versions: 2.15.1
Mitigation steps: Update to Independent Analytics version 2.15.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61961 Number of Installations: 100,000+ Affected Software: EmbedPress ≤ 4.5.6 Patched Versions: 4.6.0
Mitigation steps: Update to EmbedPress version 4.6.0 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters CVE: CVE-2026-16759 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.5 Patched Versions: 4.0.6
Mitigation steps: Update to Tutor LMS version 4.0.6 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) SQL Injection CVE: CVE-2026-15941 Number of Installations: 100,000+ Affected Software: Relevanssi ≤ 4.27.1 Patched Versions: 4.27.2
Mitigation steps: Update to Relevanssi version 4.27.2 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) SQL Injection CVE: CVE-2026-15361 Number of Installations: 100,000+ Affected Software: Content Views ≤ 4.4 Patched Versions: 4.5
Mitigation steps: Update to Content Views version 4.5 or greater.
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary File Read CVE: CVE-2026-16955 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.5 Patched Versions: 3.6.6
Mitigation steps: Update to AI Engine version 3.6.6 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVE: CVE-2026-5510 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.14.4 Patched Versions: 4.14.5
Mitigation steps: Update to GiveWP version 4.14.5 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description CVE: CVE-2026-3423 Number of Installations: 100,000+ Affected Software: Envira Gallery ≤ 1.12.4 Patched Versions: 1.12.5
Mitigation steps: Update to Envira Gallery version 1.12.5 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter CVE: CVE-2026-17090 Number of Installations: 100,000+ Affected Software: Beaver Builder Page Builder ≤ 2.10.2.2 Patched Versions: 2.10.3.2
Mitigation steps: Update to Beaver Builder Page Builder version 2.10.3.2 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-14230 Number of Installations: 100,000+ Affected Software: ECS ≤ 4.3.7 Patched Versions: 4.3.8
Mitigation steps: Update to ECS version 4.3.8 or greater.
Security Risk: Medium Exploitation Level: Requires Donor or higher level authentication. Vulnerability: Authenticated (Donor+) Stored Cross-Site Scripting CVE: CVE-2026-73357 Number of Installations: 100,000+ Affected Software: GiveWP < 4.16.6 Patched Versions: 4.16.6
Mitigation steps: Update to GiveWP version 4.16.6 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVE: CVE-2026-5391 Number of Installations: 100,000+ Affected Software: Appointment Booking Plugin ≤ 5.3.2 Patched Versions: 5.4.0
Mitigation steps: Update to Appointment Booking Plugin version 5.4.0 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter CVE: CVE-2026-15009 Number of Installations: 100,000+ Affected Software: Advanced File Manager ≤ 5.4.12 Patched Versions: 5.4.13
Mitigation steps: Update to Advanced File Manager version 5.4.13 or greater.
Security Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field CVE: CVE-2026-18385 Number of Installations: 100,000+ Affected Software: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content ≤ 4.16.19 Patched Versions: 4.17.0
Mitigation steps: Update to Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content version 4.17.0 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-73352 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.5.1 Patched Versions: 4.16.6
Mitigation steps: Update to GiveWP version 4.16.6 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Private Content Disclosure CVE: CVE-2026-14229 Number of Installations: 100,000+ Affected Software: ECS ≤ 4.3.7 Patched Versions: 4.3.8
Mitigation steps: Update to ECS version 4.3.8 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-73349 Number of Installations: 100,000+ Affected Software: GiveWP < 4.16.6 Patched Versions: 4.16.6
Mitigation steps: Update to GiveWP version 4.16.6 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated SMTP Header Injection CVE: CVE-2026-0673 Number of Installations: 100,000+ Affected Software: Element Pack Addons for Elementor ≤ 8.3.15 Patched Versions: 8.3.16
Mitigation steps: Update to Element Pack Addons for Elementor version 8.3.16 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: CAPTCHA Bypass CVE: CVE-2026-32469 Number of Installations: 100,000+ Affected Software: CAPTCHA 4WP ≤ 7.6.0 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-28180 Number of Installations: 100,000+ Affected Software: Mercado Pago payments for WooCommerce ≤ 8.9.0 Patched Versions: 8.9.1
Mitigation steps: Update to Mercado Pago payments for WooCommerce version 8.9.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: IP Spoofing to Protection Mechanism Bypass CVE: CVE-2026-11870 Number of Installations: 100,000+ Affected Software: WP Ghost (Hide My WP Ghost) < 7.0.05 Patched Versions: 7.0.05
Mitigation steps: Update to WP Ghost (Hide My WP Ghost) version 7.0.05 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Payment Bypass CVE: CVE-2026-14317 Number of Installations: 100,000+ Affected Software: GiveWP < 4.16.3 Patched Versions: 4.16.3
Mitigation steps: Update to GiveWP version 4.16.3 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Insecure Direct Object Reference to Unauthenticated Cross-Session Chatbot File Deletion CVE: CVE-2026-16953 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.3 Patched Versions: 3.6.4
Mitigation steps: Update to AI Engine version 3.6.4 or greater.
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Privilege Escalation CVE: CVE-2026-75796 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.0 Patched Versions: 3.6.1
Mitigation steps: Update to AI Engine version 3.6.1 or greater.
Security Risk: High Exploitation Level: Requires Shop manager or higher level authentication. Vulnerability: Authenticated (Shop manager+) Stored Cross-Site Scripting CVE: CVE-2026-28179 Number of Installations: 100,000+ Affected Software: FiboSearch ≤ 1.33.0 Patched Versions: 1.34.0
Mitigation steps: Update to FiboSearch version 1.34.0 or greater.
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting CVE: CVE-2026-5116 Number of Installations: 100,000+ Affected Software: DTX ≤ 5.0.5 Patched Versions: 5.0.6
Mitigation steps: Update to DTX version 5.0.6 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-19613 Number of Installations: 100,000+ Affected Software: ECS < 4.3.10 Patched Versions: 4.3.10
Mitigation steps: Update to ECS version 4.3.10 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-11565 Number of Installations: 100,000+ Affected Software: Advanced File Manager ≤ 5.4.12 Patched Versions: 5.4.13
Mitigation steps: Update to Advanced File Manager version 5.4.13 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-28005 Number of Installations: 90,000+ Affected Software: Kadence WooCommerce Email Designer ≤ 1.5.19 Patched Versions: 1.5.19.1
Mitigation steps: Update to Kadence WooCommerce Email Designer version 1.5.19.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission CVE: CVE-2026-6286 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 2.2 Patched Versions: 2.2.1
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.2.1 or greater.
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery CVE: CVE-2026-32553 Number of Installations: 90,000+ Affected Software: OttoKit: All-in-One Automation Platform ≤ 1.1.35 Patched Versions: 1.1.36
Mitigation steps: Update to OttoKit: All-in-One Automation Platform version 1.1.36 or greater.
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API CVE: CVE-2026-6020 Number of Installations: 90,000+ Affected Software: ShopLentor ≤ 3.3.7 Patched Versions: 3.3.8
Mitigation steps: Update to ShopLentor version 3.3.8 or greater.
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' CVE: CVE-2026-5096 Number of Installations: 90,000+ Affected Software: Everest Forms ≤ 3.4.4 Patched Versions: 3.4.5
Mitigation steps: Update to Everest Forms version 3.4.5 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-14822 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration < 5.29.0.1 Patched Versions: 5.29.0.1
Mitigation steps: Update to Event Tickets and Registration version 5.29.0.1 or greater.
Security Risk: Medium Exploitation Level: Requires Delegated or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints CVE: CVE-2026-13167 Number of Installations: 90,000+ Affected Software: Everest Forms ≤ 3.5.2 Patched Versions: 3.5.3
Mitigation steps: Update to Everest Forms version 3.5.3 or greater.
Security Risk: Medium Exploitation Level: Requires Provider (custom role) or higher level authentication. Vulnerability: Authenticated (Provider+) Information Exposure CVE: CVE-2026-14213 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar < 2.4.6 Patched Versions: 2.4.6
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.6 or greater.
Security Risk: TBC Exploitation Level: Requires Provider or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Provider+) Customer Data Disclosure CVE: CVE-2026-14211 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar ≤ 9.6 Patched Versions: 9.7
Mitigation steps: Update to Booking for Appointments and Events Calendar version 9.7 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-66678 Number of Installations: 90,000+ Affected Software: Advanced Custom Fields: Font Awesome Field ≤ 6.1.2 Patched Versions: 6.1.3
Mitigation steps: Update to Advanced Custom Fields: Font Awesome Field version 6.1.3 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference CVE: CVE-2026-14823 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration < 5.29.0.1 Patched Versions: 5.29.0.1
Mitigation steps: Update to Event Tickets and Registration version 5.29.0.1 or greater.
Security Risk: Medium Exploitation Level: Requires Manager (custom role) or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-14214 Number of Installations: 90,000+ Affected Software: Booking for Appointments and Events Calendar < 2.4.4 Patched Versions: 2.4.4
Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.4 or greater.
Security Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys CVE: CVE-2026-78003 Number of Installations: 80,000+ Affected Software: Mailgun for WordPress ≤ 2.2.0 Patched Versions: 2.2.1
Mitigation steps: Update to Mailgun for WordPress version 2.2.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-28139 Number of Installations: 80,000+ Affected Software: Ajax Search Lite ≤ 4.14.4 Patched Versions: 4.14.5
Mitigation steps: Update to Ajax Search Lite version 4.14.5 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-16258 Number of Installations: 80,000+ Affected Software: Ajax Search Lite ≤ 4.14.4 Patched Versions: 4.14.5
Mitigation steps: Update to Ajax Search Lite version 4.14.5 or greater.
Security Risk: Critical Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-66622 Number of Installations: 80,000+ Affected Software: Depicter ≤ 4.8.0 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form CVE: CVE-2026-6176 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.106.0 Patched Versions: 5.107.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.107.0 or greater.
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) Arbitrary File Upload CVE: CVE-2026-15049 Number of Installations: 80,000+ Affected Software: Depicter < 4.8.0 Patched Versions: 4.8.0
Mitigation steps: Update to Depicter version 4.8.0 or greater.
Security Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) OS Command Injection via 'file' Parameter CVE: CVE-2026-7693 Number of Installations: 80,000+ Affected Software: Backup Migration ≤ 2.1.1 Patched Versions: 2.1.5.2
Mitigation steps: Update to Backup Migration version 2.1.5.2 or greater.
Security Risk: TBC Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Remote Code Execution CVE: CVE-2026-66709 Number of Installations: 80,000+ Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.42 Patched Versions: 6.6.43
Mitigation steps: Update to Product Feed Manager for WooCommerce version 6.6.43 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API CVE: CVE-2026-11907 Number of Installations: 80,000+ Affected Software: Stream ≤ 4.2.0 Patched Versions: 4.2.1
Mitigation steps: Update to Stream version 4.2.1 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-19697 Number of Installations: 80,000+ Affected Software: GutenKit < 2.5.0 Patched Versions: 2.5.0
Mitigation steps: Update to GutenKit version 2.5.0 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-32548 Number of Installations: 80,000+ Affected Software: SureCart ≤ 4.6.2 Patched Versions: 4.6.3
Mitigation steps: Update to SureCart version 4.6.3 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-28140 Number of Installations: 80,000+ Affected Software: JetFormBuilder ≤ 3.6.4.1 Patched Versions: 3.6.4.2
Mitigation steps: Update to JetFormBuilder version 3.6.4.2 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-16608 Number of Installations: 80,000+ Affected Software: Download Monitor ≤ 5.2.5 Patched Versions: 5.2.6
Mitigation steps: Update to Download Monitor version 5.2.6 or greater.
Security Risk: Medium Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) Arbitrary File Downloaf CVE: CVE-2026-73383 Number of Installations: 80,000+ Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.46 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Minimal Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting CVE: CVE-2026-13701 Number of Installations: 80,000+ Affected Software: Advanced Excerpt ≤ 4.4 Patched Versions: 4.5
Mitigation steps: Update to Advanced Excerpt version 4.5 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Information Exposure CVE: CVE-2026-19699 Number of Installations: 80,000+ Affected Software: GutenKit ≤ 2.4.15 Patched Versions: 2.5.0
Mitigation steps: Update to GutenKit version 2.5.0 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action CVE: CVE-2026-16779 Number of Installations: 80,000+ Affected Software: Kubio AI Page Builder ≤ 2.8.5 Patched Versions: 2.8.6
Mitigation steps: Update to Kubio AI Page Builder version 2.8.6 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-14941 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.115.0 Patched Versions: 5.116.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.116.0 or greater.
Security Risk: High Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Arbitrary File Upload CVE: CVE-2026-66600 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.39 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-18366 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66597 Number of Installations: 70,000+ Affected Software: wpDataTables ≤ 6.5.1.4 Patched Versions: 6.5.1.5
Mitigation steps: Update to wpDataTables version 6.5.1.5 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-14287 Number of Installations: 70,000+ Affected Software: 10Web Booster ≤ 2.33.4 Patched Versions: 2.33.5
Mitigation steps: Update to 10Web Booster version 2.33.5 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61963 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.38 Patched Versions: 3.39
Mitigation steps: Update to Media Library Assistant version 3.39 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66457 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.2 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61964 Number of Installations: 70,000+ Affected Software: Ninja Tables ≤ 5.2.9 Patched Versions: 5.2.10
Mitigation steps: Update to Ninja Tables version 5.2.10 or greater.
Security Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys CVE: CVE-2026-14280 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.3.7.4 Patched Versions: 7.4
Mitigation steps: Update to Events Manager version 7.4 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action CVE: CVE-2026-15023 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Security Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) SQL Injection CVE: CVE-2026-16959 Number of Installations: 70,000+ Affected Software: Media Library Assistant < 3.40 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) SQL Injection CVE: CVE-2026-18057 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI CVE: CVE-2026-5092 Number of Installations: 70,000+ Affected Software: Greenshift ≤ 12.8.9 Patched Versions: 12.9.0
Mitigation steps: Update to Greenshift version 12.9.0 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting CVE: CVE-2026-66601 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.39 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-66591 Number of Installations: 70,000+ Affected Software: Media Library Assistant ≤ 3.39 Patched Versions: 3.40
Mitigation steps: Update to Media Library Assistant version 3.40 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-site Scripting CVE: CVE-2026-73340 Number of Installations: 70,000+ Affected Software: Featured Image from URL (FIFU) ≤ 5.3.3 Patched Versions: 6.0.0
Mitigation steps: Update to Featured Image from URL (FIFU) version 6.0.0 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute CVE: CVE-2026-18988 Number of Installations: 70,000+ Affected Software: Easy Accordion ≤ 3.1.8 Patched Versions: 3.1.9
Mitigation steps: Update to Easy Accordion version 3.1.9 or greater.
Security Risk: Low Exploitation Level: Requires Instructor or higher level authentication. Vulnerability: Authenticated (Instructor+) Server-Side Request Forgery CVE: CVE-2026-12971 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.3 Patched Versions: 4.4.4
Mitigation steps: Update to LearnPress version 4.4.4 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'header_format' Parameter CVE: CVE-2026-17089 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0.1 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters CVE: CVE-2026-10627 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.4.0 Patched Versions: 7.4.1
Mitigation steps: Update to Events Manager version 7.4.1 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter CVE: CVE-2026-3424 Number of Installations: 70,000+ Affected Software: kk Star Ratings ≤ 5.4.10.3 Patched Versions: 5.4.10.4
Mitigation steps: Update to kk Star Ratings version 5.4.10.4 or greater.
Security Risk: Medium Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) SQL Injection via 'orderby' Parameter CVE: CVE-2026-77823 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.4 Patched Versions: 4.4.5
Mitigation steps: Update to LearnPress version 4.4.5 or greater.
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter CVE: CVE-2026-75982 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.4 Patched Versions: 4.4.5
Mitigation steps: Update to LearnPress version 4.4.5 or greater.
Security Risk: Low Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings' CVE: CVE-2026-5093 Number of Installations: 70,000+ Affected Software: Greenshift ≤ 12.8.9 Patched Versions: 12.9.0
Mitigation steps: Update to Greenshift version 12.9.0 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-12976 Number of Installations: 70,000+ Affected Software: LearnPress < 4.4.4 Patched Versions: 4.4.4
Mitigation steps: Update to LearnPress version 4.4.4 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Meta Disclosure CVE: CVE-2026-16957 Number of Installations: 70,000+ Affected Software: Slim SEO ≤ 4.9.10 Patched Versions: 4.9.11
Mitigation steps: Update to Slim SEO version 4.9.11 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Information Exposure CVE: CVE-2026-14195 Number of Installations: 70,000+ Affected Software: Brizy < 2.8.18 Patched Versions: 2.8.18
Mitigation steps: Update to Brizy version 2.8.18 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Remote Code Execution CVE: CVE-2026-18781 Number of Installations: 60,000+ Affected Software: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 Patched Versions: 1.3.9.9
Mitigation steps: Update to Drag and Drop Multiple File Upload for Contact Form 7 version 1.3.9.9 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-13395 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System < 27.8 Patched Versions: 27.8
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 27.8 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66621 Number of Installations: 60,000+ Affected Software: Ultimate Dashboard ≤ 3.11.2 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action CVE: CVE-2026-13424 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 27.7 Patched Versions: 28.0
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.0 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-73382 Number of Installations: 60,000+ Affected Software: Site Reviews ≤ 8.2.0 Patched Versions: 8.2.1
Mitigation steps: Update to Site Reviews version 8.2.1 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure CVE: CVE-2026-13358 Number of Installations: 60,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.10 Patched Versions: 1.6.12.11
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.11 or greater.
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Denial of Service CVE: CVE-2026-16265 Number of Installations: 60,000+ Affected Software: WP Maps ≤ 4.9.6 Patched Versions: 4.9.7
Mitigation steps: Update to WP Maps version 4.9.7 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes CVE: CVE-2026-12801 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.43 Patched Versions: 3.5.44
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.44 or greater.
Security Risk: TBC Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-16540 Number of Installations: 60,000+ Affected Software: Simply Schedule Appointments < 1.6.12.6 Patched Versions: 1.6.12.6
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.6 or greater.
Security Risk: Minimal Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting CVE: CVE-2026-14325 Number of Installations: 60,000+ Affected Software: Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 Patched Versions: 1.3.9.9
Mitigation steps: Update to Drag and Drop Multiple File Upload for Contact Form 7 version 1.3.9.9 or greater.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Missing Authorization CVE: CVE-2026-18466 Number of Installations: 60,000+ Affected Software: WP Maps < 4.9.8 Patched Versions: 4.9.8
Mitigation steps: Update to WP Maps version 4.9.8 or greater.
Security Risk: Medium Exploitation Level: Requires Staff or higher level authentication. Vulnerability: Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter CVE: CVE-2026-12905 Number of Installations: 60,000+ Affected Software: Online Scheduling and Appointment Booking System ≤ 27.7 Patched Versions: 28.0
Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.0 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request CVE: CVE-2026-2996 Number of Installations: 50,000+ Affected Software: Advanced Product Fields (Product Addons) for WooCommerce ≤ 1.6.21 Patched Versions: 1.6.22
Mitigation steps: Update to Advanced Product Fields (Product Addons) for WooCommerce version 1.6.22 or greater.
Security Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-66439 Number of Installations: 50,000+ Affected Software: Advanced AJAX Product Filters ≤ 3.2.0.3 Patched Versions: 3.2.1
Mitigation steps: Update to Advanced AJAX Product Filters version 3.2.1 or greater.
Security Risk: Medium Exploitation Level: Requires Editor or higher level authentication. Vulnerability: Authenticated (Editor+) PHP Object Injection CVE: CVE-2026-66620 Number of Installations: 50,000+ Affected Software: OptionTree ≤ 2.7.3 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Medium Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter CVE: CVE-2026-18027 Number of Installations: 50,000+ Affected Software: WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels ≤ 4.9.8 Patched Versions: 5.0.0
Mitigation steps: Update to WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels version 5.0.0 or greater.
Security Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' CVE: CVE-2026-12231 Number of Installations: 50,000+ Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.8 Patched Versions: 2.7.9.9
Mitigation steps: Update to Exclusive Addons for Elementor version 2.7.9.9 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-17532 Number of Installations: 50,000+ Affected Software: Seraphinite Accelerator ≤ 2.29.18 Patched Versions: 2.29.19
Mitigation steps: Update to Seraphinite Accelerator version 2.29.19 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-16253 Number of Installations: 50,000+ Affected Software: Total Upkeep < 1.17.3 Patched Versions: 1.17.3
Mitigation steps: Update to Total Upkeep version 1.17.3 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-73403 Number of Installations: 50,000+ Affected Software: User Registration & Membership ≤ 5.2.6 Patched Versions: 5.2.7
Mitigation steps: Update to User Registration & Membership version 5.2.7 or greater.
Security Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-66708 Number of Installations: 50,000+ Affected Software: Total Upkeep ≤ 1.17.2 Patched Versions: 1.17.3
Mitigation steps: Update to Total Upkeep version 1.17.3 or greater.
Security Risk: TBC Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-16295 Number of Installations: 50,000+ Affected Software: Clearfy Cache < 2.4.3 Patched Versions: 2.4.3
Mitigation steps: Update to Clearfy Cache version 2.4.3 or greater.
Update your website software to reduce risk. Users unable to upgrade to the latest version are advised to implement a web application firewall, which can virtually patch known vulnerabilities and safeguard their website.