Vulnerability & Patch Roundup — September 2026
If you operate a website, you’re already aware that a single unpatched vulnerability can render your 2026-10-1 04:30:11 Author: blog.sucuri.net(查看原文) 阅读量:4 收藏

If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.

To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.

For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.


Plugins


WooCommerce – Unauthenticated Denial of Service

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-48888
Number of Installations: 7,000,000+
Affected Software: WooCommerce < 11.1.0
Patched Versions: 11.1.0

Mitigation steps: Update to WooCommerce version 11.1.0 or greater.


LiteSpeed Cache – Unauthenticated Server-Side Request Forgery

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Server-Side Request Forgery
CVE: CVE-2026-84761
Number of Installations: 7,000,000+
Affected Software: LiteSpeed Cache ≤ 7.9
Patched Versions: 7.9.1

Mitigation steps: Update to LiteSpeed Cache version 7.9.1 or greater.


WooCommerce – Authenticated (Shop Manager+) SQL Injection

Security Risk: High
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) SQL Injection
CVE: CVE-2026-57777
Number of Installations: 7,000,000+
Affected Software: WooCommerce ≤ 10.9.4
Patched Versions: 11.0

Mitigation steps: Update to WooCommerce version 11.0 or greater.


LiteSpeed Cache – Reflected Cross-Site Scripting via ESI ‘esi’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via ESI 'esi' Parameter
CVE: CVE-2026-76579
Number of Installations: 7,000,000+
Affected Software: LiteSpeed Cache ≤ 7.9
Patched Versions: 7.9.1

Mitigation steps: Update to LiteSpeed Cache version 7.9.1 or greater.


WPForms – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-84744
Number of Installations: 5,000,000+
Affected Software: WPForms 1.5.0.1 - 2.0.2
Patched Versions: 2.0.2.1

Mitigation steps: Update to WPForms version 2.0.2.1 or greater.


WPForms – Reflected Cross-Site Scripting via ‘page_title’ POST Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'page_title' POST Parameter
CVE: CVE-2026-88996
Number of Installations: 5,000,000+
Affected Software: WPForms ≤ 2.0.2
Patched Versions: 2.0.2.1

Mitigation steps: Update to WPForms version 2.0.2.1 or greater.


WPForms – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-74991
Number of Installations: 5,000,000+
Affected Software: WPForms 1.8.8.2 - 2.0.1.1
Patched Versions: 2.0.2

Mitigation steps: Update to WPForms version 2.0.2 or greater.


All-in-One WP Migration and Backup – Unauthenticated Insufficient Credential Protection via Authorization Basic Header

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insufficient Credential Protection via Authorization Basic Header
CVE: CVE-2026-89064
Number of Installations: 5,000,000+
Affected Software: All-in-One WP Migration and Backup ≤ 7.110
Patched Versions: 7.111

Mitigation steps: Update to All-in-One WP Migration and Backup version 7.111 or greater.


All-in-One WP Migration and Backup – Authenticated (Admin+) Privilege Escalation

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) Privilege Escalation
CVE: CVE-2026-81810
Number of Installations: 5,000,000+
Affected Software: All-in-One WP Migration and Backup ≤ 7.110
Patched Versions: 7.111

Mitigation steps: Update to All-in-One WP Migration and Backup version 7.111 or greater.


Rank Math SEO – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-77783
Number of Installations: 4,000,000+
Affected Software: Rank Math SEO < 1.0.277
Patched Versions: 1.0.277

Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.


UpdraftPlus: WP Backup & Migration Plugin – Authenticated (Subscriber+) Information Exposure

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-82841
Number of Installations: 4,000,000+
Affected Software: UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.26.7
Patched Versions: 2.26.8.26

Mitigation steps: Update to UpdraftPlus: WP Backup & Migration Plugin version 2.26.8.26 or greater.


Rank Math SEO – Missing Authorization to Authenticated (Author+) SEO Object Updates

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Author+) SEO Object Updates
CVE: CVE-2026-77784
Number of Installations: 4,000,000+
Affected Software: Rank Math SEO < 1.0.277
Patched Versions: 1.0.277

Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.


Rank Math SEO – Authenticated (Author+) Information Exposure

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Information Exposure
CVE: CVE-2026-77785
Number of Installations: 4,000,000+
Affected Software: Rank Math SEO < 1.0.277
Patched Versions: 1.0.277

Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.


Really Simple Security – Unauthenticated Denial of Service

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-84775
Number of Installations: 3,000,000+
Affected Software: Really Simple Security ≤ 9.8.0
Patched Versions: 9.8.1

Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.


Jetpack – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: Not provided
Number of Installations: 3,000,000+
Affected Software: Jetpack 16.1 - 16.1.2
Patched Versions: 16.1.3

Mitigation steps: Update to Jetpack version 16.1.3 or greater.


Jetpack – Authenticated (Administrator+) PHP Object Injection

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) PHP Object Injection
CVE: Not provided
Number of Installations: 3,000,000+
Affected Software: Jetpack 12.0 - 12.0.2
Patched Versions: 16.1.3

Mitigation steps: Update to Jetpack version 16.1.3 or greater.


Jetpack – Authenticated (Administrator+) PHP Object Injection

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) PHP Object Injection
CVE: Not provided
Number of Installations: 3,000,000+
Affected Software: Jetpack 16.1 - 16.1.2
Patched Versions: 16.1.3

Mitigation steps: Update to Jetpack version 16.1.3 or greater.


Jetpack – Reflected to Stored Cross-Site Scripting via Reader Repost Parameters

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Reflected to Stored Cross-Site Scripting via Reader Repost Parameters
CVE: Not provided
Number of Installations: 3,000,000+
Affected Software: Jetpack 14.5
Patched Versions: 16.1.3

Mitigation steps: Update to Jetpack version 16.1.3 or greater.


Really Simple Security – Unauthenticated Unbounded Option Growth

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability:  Unauthenticated Unbounded Option Growth
CVE: CVE-2026-88798
Number of Installations: 3,000,000+
Affected Software: Really Simple Security ≤ 9.8.2
Patched Versions: 9.8.3

Mitigation steps: Update to Really Simple Security version 9.8.3 or greater.


Really Simple Security – Unauthenticated Two-Factor Authentication Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability:  Unauthenticated Two-Factor Authentication Bypass
CVE: CVE-2026-89080
Number of Installations: 3,000,000+
Affected Software: Really Simple Security ≤ 9.8.0
Patched Versions: 9.8.1

Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.


Really Simple Security – Unauthenticated Two-Factor Authentication Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Two-Factor Authentication Bypass
CVE: CVE-2026-84777
Number of Installations: 3,000,000+
Affected Software: Really Simple Security ≤ 9.8.0
Patched Versions: 9.8.1

Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.


Really Simple Security – Missing Authorization to 2FA Bypass

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Missing Authorization to 2FA Bypass
CVE: CVE-2026-82519
Number of Installations: 3,000,000+
Affected Software: Really Simple Security ≤ 9.8.1
Patched Versions: 9.8.2

Mitigation steps: Update to Really Simple Security version 9.8.2 or greater.


Jetpack – Missing Authorization on WPCOM Media API Attachment Parent

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Missing Authorization on WPCOM Media API Attachment Parent
CVE: CVE-2024-10858
Number of Installations: 3,000,000+
Affected Software: Jetpack 3.2 - 16.1.2
Patched Versions: 16.1.3

Mitigation steps: Update to Jetpack version 16.1.3 or greater.


All in One SEO – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-82884
Number of Installations: 2,000,000+
Affected Software: All in One SEO ≤ 5.0.0.0
Patched Versions: 5.0.0.1

Mitigation steps: Update to All in One SEO version 5.0.0.1 or greater.


Complianz GDPR/CCPA Cookie Consent Banner – Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex
CVE: CVE-2026-83561
Number of Installations: 1,000,000+
Affected Software: Complianz GDPR/CCPA Cookie Consent Banner ≤ 7.5.4
Patched Versions: 7.5.5

Mitigation steps: Update to Complianz GDPR/CCPA Cookie Consent Banner version 7.5.5 or greater.


EWWW Image Optimizer – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84773
Number of Installations: 1,000,000+
Affected Software: EWWW Image Optimizer ≤ 8.7.6
Patched Versions: 8.7.7

Mitigation steps: Update to EWWW Image Optimizer version 8.7.7 or greater.


EWWW Image Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-97067
Number of Installations: 1,000,000+
Affected Software: EWWW Image Optimizer ≤ 8.7.7
Patched Versions: 8.8.0

Mitigation steps: Update to EWWW Image Optimizer version 8.8.0 or greater.


ElementsKit Elementor Addons – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-94500
Number of Installations: 1,000,000+
Affected Software: ElementsKit Elementor Addons ≤ 4.0.5
Patched Versions: 4.0.6

Mitigation steps: Update to ElementsKit Elementor Addons version 4.0.6 or greater.


Safe SVG – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-94077
Number of Installations: 1,000,000+
Affected Software: Safe SVG ≤ 2.5.0
Patched Versions: 2.5.1

Mitigation steps: Update to Safe SVG version 2.5.1 or greater.


EWWW Image Optimizer – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-91011
Number of Installations: 1,000,000+
Affected Software: EWWW Image Optimizer ≤ 8.7.6
Patched Versions: 8.7.7

Mitigation steps: Update to EWWW Image Optimizer version 8.7.7 or greater.


All-In-One Security (AIOS) – Authenticated (Subscriber+) Security Control Bypass

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Security Control Bypass
CVE: CVE-2026-96825
Number of Installations: 1,000,000+
Affected Software: All-In-One Security (AIOS) ≤ 5.4.8
Patched Versions: 5.4.9

Mitigation steps: Update to All-In-One Security (AIOS) version 5.4.9 or greater.


MC4WP: Mailchimp for WordPress – Reflected Cross-Site Scripting via ‘data’ Dynamic Content Tag

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'data' Dynamic Content Tag
CVE: CVE-2026-87917
Number of Installations: 1,000,000+
Affected Software: MC4WP: Mailchimp for WordPress ≤ 4.14.0
Patched Versions: 4.14.1

Mitigation steps: Update to MC4WP: Mailchimp for WordPress version 4.14.1 or greater.


Spectra Legacy – Authenticated (Contributor+) Sensitive Information Exposure

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Sensitive Information Exposure
CVE: CVE-2026-16302
Number of Installations: 1,000,000+
Affected Software: Spectra Legacy ≤ 2.20.0
Patched Versions: 2.20.1

Mitigation steps: Update to Spectra Legacy version 2.20.1 or greater.


Safe SVG – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-94672
Number of Installations: 1,000,000+
Affected Software: Safe SVG ≤ 2.5.0
Patched Versions: 2.5.1

Mitigation steps: Update to Safe SVG version 2.5.1 or greater.


Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-62134
Number of Installations: 1,000,000+
Affected Software: Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg ≤ 4.7.5
Patched Versions: 4.7.6

Mitigation steps: Update to Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg version 4.7.6 or greater.


W3 Total Cache – Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator
CVE: CVE-2026-78438
Number of Installations: 900,000+
Affected Software: W3 Total Cache ≤ 2.10.5
Patched Versions: 2.10.6

Mitigation steps: Update to W3 Total Cache version 2.10.6 or greater.


WPvivid – Authenticated (Administrator+) Arbitrary File Upload

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Arbitrary File Upload
CVE: CVE-2026-82193
Number of Installations: 900,000+
Affected Software: WPvivid < 0.9.134
Patched Versions: 0.9.134

Mitigation steps: Update to WPvivid version 0.9.134 or greater.


Translate WordPress with GTranslate – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-86604
Number of Installations: 900,000+
Affected Software: Translate WordPress with GTranslate ≤ 5.0.0
Patched Versions: 5.0.1

Mitigation steps: Update to Translate WordPress with GTranslate version 5.0.1 or greater.


WPvivid – Authenticated (Administrator+) Arbitrary File Deletion

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Arbitrary File Deletion
CVE: CVE-2026-82194
Number of Installations: 900,000+
Affected Software: WPvivid < 0.9.134
Patched Versions: 0.9.134

Mitigation steps: Update to WPvivid version 0.9.134 or greater.


Redux Framework – Authenticated (Subscriber+) Stored Cross-Site Scripting via ‘user-mediaurl’ Media Field

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field
CVE: CVE-2026-90992
Number of Installations: 900,000+
Affected Software: Redux Framework ≤ 4.5.14
Patched Versions: 4.5.15

Mitigation steps: Update to Redux Framework version 4.5.15 or greater.


Redux Framework – Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input
CVE: CVE-2026-5410
Number of Installations: 900,000+
Affected Software: Redux Framework ≤ 4.5.13
Patched Versions: 4.5.14

Mitigation steps: Update to Redux Framework version 4.5.14 or greater.


Redux Framework – Authenticated (Subscriber+) Cross-Site Scripting via User Input

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Cross-Site Scripting via User Input
CVE: CVE-2026-5400
Number of Installations: 900,000+
Affected Software: Redux Framework ≤ 4.5.13
Patched Versions: 4.5.14

Mitigation steps: Update to Redux Framework version 4.5.14 or greater.


Redux Framework – Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value
CVE: CVE-2026-5399
Number of Installations: 900,000+
Affected Software: Redux Framework ≤ 4.5.13.1
Patched Versions: 4.5.14

Mitigation steps: Update to Redux Framework version 4.5.14 or greater.


WPvivid – Authenticated (Administrator+) SQL Injection

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection
CVE: CVE-2026-82182
Number of Installations: 900,000+
Affected Software: WPvivid < 0.9.133
Patched Versions: 0.9.133

Mitigation steps: Update to WPvivid version 0.9.133 or greater.


Translate WordPress with GTranslate – Authenticated (Administrator+) Stored Cross-Site Scripting

Security Risk: Minimal
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting
CVE: CVE-2025-15695
Number of Installations: 900,000+
Affected Software: Translate WordPress with GTranslate < 3.0.10
Patched Versions: 3.0.10

Mitigation steps: Update to Translate WordPress with GTranslate version 3.0.10 or greater.


Redux Framework – Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via ‘attachment_id’ Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter
CVE: CVE-2026-88999
Number of Installations: 900,000+
Affected Software: Redux Framework ≤ 4.5.14
Patched Versions: 4.5.15

Mitigation steps: Update to Redux Framework version 4.5.15 or greater.


Autoptimize – Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path
CVE: CVE-2026-14995
Number of Installations: 800,000+
Affected Software: Autoptimize ≤ 3.1.15.1
Patched Versions: 3.1.16

Mitigation steps: Update to Autoptimize version 3.1.16 or greater.


Breadcrumb NavXT – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84765
Number of Installations: 800,000+
Affected Software: Breadcrumb NavXT ≤ 7.5.1
Patched Versions: 7.5.2

Mitigation steps: Update to Breadcrumb NavXT version 7.5.2 or greater.


Polylang – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-97279
Number of Installations: 800,000+
Affected Software: Polylang ≤ 3.8.9
Patched Versions: 3.8.10

Mitigation steps: Update to Polylang version 3.8.10 or greater.


Smart Slider 3 – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘data-href’ Attribute in Custom HTML Block

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block
CVE: CVE-2026-14876
Number of Installations: 800,000+
Affected Software: Smart Slider 3 ≤ 3.5.1.38
Patched Versions: 3.5.1.39

Mitigation steps: Update to Smart Slider 3 version 3.5.1.39 or greater.


Flamingo – Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search
CVE: CVE-2026-12853
Number of Installations: 800,000+
Affected Software: Flamingo ≤ 2.6.2
Patched Versions: 2.6.3

Mitigation steps: Update to Flamingo version 2.6.3 or greater.


Popup Maker – Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter
CVE: CVE-2026-87915
Number of Installations: 700,000+
Affected Software: Popup Maker ≤ 1.24.0
Patched Versions: 1.25.0

Mitigation steps: Update to Popup Maker version 1.25.0 or greater.


Popup Maker – Authenticated (Contributor+) Stored Cross-Site Scripting via post_title

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via post_title
CVE: CVE-2026-15797
Number of Installations: 700,000+
Affected Software: Popup Maker ≤ 1.24.0
Patched Versions: 1.25.0

Mitigation steps: Update to Popup Maker version 1.25.0 or greater.


The Events Calendar – Unauthenticated Code Injection to Remote Code Execution via Widget ‘classes’ Map Callable Invocation

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation
CVE: CVE-2026-78159
Number of Installations: 600,000+
Affected Software: The Events Calendar ≤ 6.17.3
Patched Versions: 6.17.3.1

Mitigation steps: Update to The Events Calendar version 6.17.3.1 or greater.


The Events Calendar – Unauthenticated PHP Object Injection to Remote Code Execution

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection to Remote Code Execution
CVE: CVE-2026-78006
Number of Installations: 600,000+
Affected Software: The Events Calendar ≤ 6.17.4
Patched Versions: 6.17.4.1

Mitigation steps: Update to The Events Calendar version 6.17.4.1 or greater.


Forminator Forms – Unauthenticated Arbitrary Shortcode Execution via ‘current_url’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter
CVE: CVE-2026-92229
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2
Patched Versions: 1.57.3

Mitigation steps: Update to Forminator Forms version 1.57.3 or greater.


Ninja Forms – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-91827
Number of Installations: 600,000+
Affected Software: Ninja Forms ≤ 3.15.3
Patched Versions: 3.15.4

Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting via ‘postdata-1[post-custom]’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
CVE: CVE-2026-92144
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
CVE: CVE-2026-85235
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


WP Statistics – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-93770
Number of Installations: 600,000+
Affected Software: WP Statistics ≤ 14.16.13
Patched Versions: 14.16.14

Mitigation steps: Update to WP Statistics version 14.16.14 or greater.


Ninja Forms – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-95515
Number of Installations: 600,000+
Affected Software: Ninja Forms ≤ 3.15.3
Patched Versions: 3.15.4

Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.


Ninja Forms – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-92438
Number of Installations: 600,000+
Affected Software: Ninja Forms ≤ 3.15.3
Patched Versions: 3.15.4

Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.


Forminator Forms – Authenticated (Admin+) Privilege Escalation

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) Privilege Escalation
CVE: CVE-2026-87068
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2.0
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


Royal Addons for Elementor – Unauthenticated Arbitrary HTML Injection in Notification Emails

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary HTML Injection in Notification Emails
CVE: CVE-2026-13407
Number of Installations: 600,000+
Affected Software: Royal Addons for Elementor ≤ 1.7.1066
Patched Versions: 1.7.1067

Mitigation steps: Update to Royal Addons for Elementor version 1.7.1067 or greater.


Ninja Forms – Unauthenticated Stored Cross-Site Scripting via Repeater Child ‘type’ Confusion via Unmatched Array Key

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key
CVE: CVE-2026-19769
Number of Installations: 600,000+
Affected Software: Ninja Forms ≤ 3.15.1
Patched Versions: 3.15.2

Mitigation steps: Update to Ninja Forms version 3.15.2 or greater.


WP Statistics – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84774
Number of Installations: 600,000+
Affected Software: WP Statistics ≤ 14.16.11
Patched Versions: 14.16.12

Mitigation steps: Update to WP Statistics version 14.16.12 or greater.


Under Construction – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-81295
Number of Installations: 600,000+
Affected Software: Under Construction ≤ 5.82
Patched Versions: 5.83

Mitigation steps: Update to Under Construction version 5.83 or greater.


Forminator Forms – Authenticated (Admin+) PHP Object Injection

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) PHP Object Injection
CVE: CVE-2026-87067
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2.0
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


Ninja Forms – Authenticated (Administrator+) PHP Object Injection via Form Import

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) PHP Object Injection via Form Import
CVE: CVE-2026-11363
Number of Installations: 600,000+
Affected Software: Ninja Forms ≤ 3.14.6
Patched Versions: 3.14.7

Mitigation steps: Update to Ninja Forms version 3.14.7 or greater.


Ninja Forms – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-80437
Number of Installations: 600,000+
Affected Software: Ninja Forms 3.14.10 - 3.15.1
Patched Versions: 3.15.2

Mitigation steps: Update to Ninja Forms version 3.15.2 or greater.


Premium Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-94168
Number of Installations: 600,000+
Affected Software: Premium Addons for Elementor ≤ 4.11.105
Patched Versions: 4.11.106

Mitigation steps: Update to Premium Addons for Elementor version 4.11.106 or greater.


The Events Calendar – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-84741
Number of Installations: 600,000+
Affected Software: The Events Calendar 4.5 - 6.17.4.1
Patched Versions: 6.17.5

Mitigation steps: Update to The Events Calendar version 6.17.5 or greater.


Forminator Forms – Unauthenticated Poll Vote Limit Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Poll Vote Limit Bypass
CVE: CVE-2026-87070
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2.0
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


Forminator Forms – Missing Authorization to Unauthenticated Arbitrary Post Meta Injection

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Arbitrary Post Meta Injection
CVE: CVE-2026-87071
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2.0
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


Royal Addons for Elementor – Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in ‘wpr_keyword’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter
CVE: CVE-2026-17585
Number of Installations: 600,000+
Affected Software: Royal Addons for Elementor ≤ 1.7.1066
Patched Versions: 1.7.1067

Mitigation steps: Update to Royal Addons for Elementor version 1.7.1067 or greater.


MetForm – Unauthenticated Email Header Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Email Header Injection
CVE: CVE-2026-86813
Number of Installations: 600,000+
Affected Software: MetForm < 4.1.9
Patched Versions: 4.1.9

Mitigation steps: Update to MetForm version 4.1.9 or greater.


The Events Calendar – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-97285
Number of Installations: 600,000+
Affected Software: The Events Calendar ≤ 6.17.5
Patched Versions: 6.17.5.1

Mitigation steps: Update to The Events Calendar version 6.17.5.1 or greater.


Forminator Forms – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-87069
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.57.2.0
Patched Versions: 1.57.2.1

Mitigation steps: Update to Forminator Forms version 1.57.2.1 or greater.


The Events Calendar – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-84742
Number of Installations: 600,000+
Affected Software: The Events Calendar 6.15.0 - 6.17.4.1
Patched Versions: 6.17.5

Mitigation steps: Update to The Events Calendar version 6.17.5 or greater.


The Events Calendar – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-84743
Number of Installations: 600,000+
Affected Software: The Events Calendar 6.15.16.1 - 6.17.4.1
Patched Versions: 6.17.5

Mitigation steps: Update to The Events Calendar version 6.17.5 or greater.


The Events Calendar – Authenticated (Contributor+) Information Exposure

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Information Exposure
CVE: CVE-2026-84745
Number of Installations: 600,000+
Affected Software: The Events Calendar < 6.17.3.1
Patched Versions: 6.17.3.1

Mitigation steps: Update to The Events Calendar version 6.17.3.1 or greater.


Ninja Forms – Authenticated (Custom Role+) Information Exposure

Security Risk: High
Exploitation Level: Requires Custom Role or higher level authentication.
Vulnerability: Authenticated (Custom Role+) Information Exposure
CVE: CVE-2026-80438
Number of Installations: 600,000+
Affected Software: Ninja Forms 3.14.0 - 3.15.1
Patched Versions: 3.15.2

Mitigation steps: Update to Ninja Forms version 3.15.2 or greater.


Extendify – Unauthenticated Stored Cross-Site Scripting via ‘styles.blocks’ Block Type Key

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key
CVE: CVE-2026-85679
Number of Installations: 500,000+
Affected Software: Extendify ≤ 3.1.6
Patched Versions: 3.2.0

Mitigation steps: Update to Extendify version 3.2.0 or greater.


Ninja Forms – Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Stored Cross-Site Scripting
CVE: CVE-2026-94504
Number of Installations: 500,000+
Affected Software: Ninja Forms ≤ 3.15.3
Patched Versions: 3.15.4

Mitigation steps: Update to Ninja Forms version 3.15.4 or greater.


Kirki – Unauthenticated Stored Cross-Site Scripting via ‘comment’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter
CVE: CVE-2026-17037
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.2.0
Patched Versions: 6.2.1

Mitigation steps: Update to Kirki version 6.2.1 or greater.


Kirki – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84219
Number of Installations: 500,000+
Affected Software: Kirki 6.2.1 - 6.2.5
Patched Versions: 6.3.0

Mitigation steps: Update to Kirki version 6.3.0 or greater.


SureForms – Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload
CVE: CVE-2026-18406
Number of Installations: 500,000+
Affected Software: SureForms ≤ 2.12.2
Patched Versions: 2.12.3

Mitigation steps: Update to SureForms version 2.12.3 or greater.


Broken Link Checker – Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log
CVE: CVE-2026-75528
Number of Installations: 500,000+
Affected Software: Broken Link Checker ≤ 2.4.13
Patched Versions: 2.4.13.1

Mitigation steps: Update to Broken Link Checker version 2.4.13.1 or greater.


Ocean Extra – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-94684
Number of Installations: 500,000+
Affected Software: Ocean Extra ≤ 2.6.1
Patched Versions: 2.6.2

Mitigation steps: Update to Ocean Extra version 2.6.2 or greater.


Kirki – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-84223
Number of Installations: 500,000+
Affected Software: Kirki 6.0.0 - 6.3.0
Patched Versions: 6.3.1

Mitigation steps: Update to Kirki version 6.3.1 or greater.


Broken Link Checker – Authenticated (Editor+) Server-Side Request Forgery

Security Risk: Low
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Server-Side Request Forgery
CVE: CVE-2026-84772
Number of Installations: 500,000+
Affected Software: Broken Link Checker ≤ 2.4.14
Patched Versions: 2.4.14.1

Mitigation steps: Update to Broken Link Checker version 2.4.14.1 or greater.


Kirki – Unauthenticated Blind Server-Side Request Forgery via ‘kirki_data’ Parameter

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter
CVE: CVE-2026-18335
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.2.0
Patched Versions: 6.2.1

Mitigation steps: Update to Kirki version 6.2.1 or greater.


Kirki – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-84222
Number of Installations: 500,000+
Affected Software: Kirki 6.2.1 - 6.2.5
Patched Versions: 6.3.0

Mitigation steps: Update to Kirki version 6.3.0 or greater.


SureForms – Unauthenticated Insecure Direct Object Reference

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-85308
Number of Installations: 500,000+
Affected Software: SureForms ≤ 2.12.5
Patched Versions: 2.12.6

Mitigation steps: Update to SureForms version 2.12.6 or greater.


Kirki – Authenticated (Editor+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) SQL Injection
CVE: CVE-2026-84221
Number of Installations: 500,000+
Affected Software: Kirki 6.0.0 - 6.2.5
Patched Versions: 6.3.0

Mitigation steps: Update to Kirki version 6.3.0 or greater.


Kirki – Authenticated (Custom Role+) Insecure Direct Object Reference

Security Risk: High
Exploitation Level: Requires Custom Role or higher level authentication.
Vulnerability: Authenticated (Custom Role+) Insecure Direct Object Reference
CVE: CVE-2026-84225
Number of Installations: 500,000+
Affected Software: Kirki 6.0.0 - 6.2.5
Patched Versions: 6.3.0

Mitigation steps: Update to Kirki version 6.3.0 or greater.


TranslatePress – Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel
CVE: CVE-2026-89412
Number of Installations: 400,000+
Affected Software: TranslatePress ≤ 3.3.5
Patched Versions: 3.3.6

Mitigation steps: Update to TranslatePress version 3.3.6 or greater.


Template Kit – Authenticated (Editor+) Arbitrary File Deletion

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Arbitrary File Deletion
CVE: CVE-2026-96824
Number of Installations: 400,000+
Affected Software: Template Kit ≤ 1.0.16
Patched Versions: 1.0.17

Mitigation steps: Update to Template Kit version 1.0.17 or greater.


HappyAddons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-62080
Number of Installations: 400,000+
Affected Software: HappyAddons for Elementor ≤ 3.23.1
Patched Versions: 3.50.0

Mitigation steps: Update to HappyAddons for Elementor version 3.50.0 or greater.


PixelYourSite – Authenticated (Subscriber+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE: CVE-2026-95530
Number of Installations: 400,000+
Affected Software: PixelYourSite ≤ 11.4.1
Patched Versions: 11.4.2

Mitigation steps: Update to PixelYourSite version 11.4.2 or greater.


HappyAddons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-85006
Number of Installations: 400,000+
Affected Software: HappyAddons for Elementor ≤ 3.49.0
Patched Versions: 3.50.0

Mitigation steps: Update to HappyAddons for Elementor version 3.50.0 or greater.


SureRank SEO – Unauthenticated Information Exposure

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-78152
Number of Installations: 400,000+
Affected Software: SureRank SEO 1.6.2 - 1.10.0
Patched Versions: 1.10.1

Mitigation steps: Update to SureRank SEO version 1.10.1 or greater.


YITH WooCommerce Wishlist – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-82305
Number of Installations: 400,000+
Affected Software: YITH WooCommerce Wishlist < 4.18.1
Patched Versions: 4.18.1

Mitigation steps: Update to YITH WooCommerce Wishlist version 4.18.1 or greater.


BackWPup – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Missing Authorization
CVE: CVE-2026-86815
Number of Installations: 400,000+
Affected Software: BackWPup 5.2.2 - 5.7.4
Patched Versions: 5.7.5

Mitigation steps: Update to BackWPup version 5.7.5 or greater.


ShortPixel Image Optimizer – Authenticated (Author+) PHP Object Injection via Nested JSON Post Content

Security Risk: High
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) PHP Object Injection via Nested JSON Post Content
CVE: CVE-2026-17086
Number of Installations: 300,000+
Affected Software: ShortPixel Image Optimizer ≤ 6.5.5
Patched Versions: 6.5.6

Mitigation steps: Update to ShortPixel Image Optimizer version 6.5.6 or greater.


Photo Gallery, Sliders, Proofing and Themes – Unauthenticated Arbitrary File Read

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary File Read
CVE: CVE-2026-94123
Number of Installations: 300,000+
Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.5.0
Patched Versions: 4.5.1

Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.1 or greater.


ShortPixel Image Optimizer – Authenticated (Subscriber+) PHP Object Injection

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) PHP Object Injection
CVE: CVE-2026-97246
Number of Installations: 300,000+
Affected Software: ShortPixel Image Optimizer ≤ 6.5.5
Patched Versions: 6.5.6

Mitigation steps: Update to ShortPixel Image Optimizer version 6.5.6 or greater.


Unlimited Elements For Elementor – Authenticated (Subscriber+) PHP Object Injection

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) PHP Object Injection
CVE: CVE-2026-85017
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.19
Patched Versions: 2.0.20

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.20 or greater.


Unlimited Elements For Elementor – Unauthenticated SQL Injection

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-18561
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.16
Patched Versions: 2.0.17

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.17 or greater.


WP Go Maps – Unauthenticated Denial of Service

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-84780
Number of Installations: 300,000+
Affected Software: WP Go Maps ≤ 10.1.08
Patched Versions: 10.1.09

Mitigation steps: Update to WP Go Maps version 10.1.09 or greater.


PDF Invoices & Packing Slips for WooCommerce – Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields
CVE: CVE-2026-92244
Number of Installations: 300,000+
Affected Software: PDF Invoices & Packing Slips for WooCommerce ≤ 5.16.1
Patched Versions: 5.16.2

Mitigation steps: Update to PDF Invoices & Packing Slips for WooCommerce version 5.16.2 or greater.


Ad Inserter – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-97077
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.18
Patched Versions: 2.8.19

Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.


Photo Gallery, Sliders, Proofing and Themes – Authenticated (Admin+) Arbitrary File Upload

Security Risk: High
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) Arbitrary File Upload
CVE: CVE-2026-81650
Number of Installations: 300,000+
Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.4.0
Patched Versions: 4.5.0

Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.0 or greater.


Jeg Kit for Elementor – Unauthenticated Stored Cross-Site Scripting via Comment Content

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content
CVE: CVE-2026-18405
Number of Installations: 300,000+
Affected Software: Jeg Kit for Elementor ≤ 3.2.16
Patched Versions: 3.2.17

Mitigation steps: Update to Jeg Kit for Elementor version 3.2.17 or greater.


Unlimited Elements For Elementor – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84820
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.17
Patched Versions: 2.0.18

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.18 or greater.


Formidable Forms – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-19857
Number of Installations: 300,000+
Affected Software: Formidable Forms ≤ 6.34
Patched Versions: 6.35

Mitigation steps: Update to Formidable Forms version 6.35 or greater.


Duplicate Post – Authenticated (Subscriber+) Stored Cross-Site Scripting via ‘noti_token’ Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter
CVE: CVE-2026-89424
Number of Installations: 300,000+
Affected Software: Duplicate Post ≤ 1.5.6
Patched Versions: 1.5.7

Mitigation steps: Update to Duplicate Post version 1.5.7 or greater.


Ad Inserter – Authenticated (Subscriber+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE: CVE-2026-81655
Number of Installations: 300,000+
Affected Software: Ad Inserter 2.8.12 - 2.8.18
Patched Versions: 2.8.19

Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.


Unlimited Elements For Elementor – Authenticated (Contributor+) Server-Side Request Forgery

Security Risk: Low
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery
CVE: CVE-2026-66608
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.19
Patched Versions: 2.0.20

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.20 or greater.


SEOPress – Authenticated (Contributor+) Server-Side Request Forgery

Security Risk: Low
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery
CVE: CVE-2026-85305
Number of Installations: 300,000+
Affected Software: SEOPress ≤ 10.1
Patched Versions: 10.2

Mitigation steps: Update to SEOPress version 10.2 or greater.


Ad Inserter – Reflected Cross-Site Scripting via ‘s’ Search Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 's' Search Parameter
CVE: CVE-2026-89427
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.18
Patched Versions: 2.8.19

Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.


Ad Inserter – Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
CVE: CVE-2026-19902
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.18
Patched Versions: 2.8.19

Mitigation steps: Update to Ad Inserter version 2.8.19 or greater.


Unlimited Elements For Elementor – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-77150
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.16
Patched Versions: 2.0.17

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.17 or greater.


Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-18964
Number of Installations: 300,000+
Affected Software: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button ≤ 3.5.9
Patched Versions: 3.6.0

Mitigation steps: Update to Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button version 3.6.0 or greater.


Unlimited Elements For Elementor – Reflected Cross-Site Scripting via ‘formData[id]’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'formData[id]' Parameter
CVE: CVE-2026-75586
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.17
Patched Versions: 2.0.18

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.18 or greater.


Blocksy Companion – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-97247
Number of Installations: 300,000+
Affected Software: Blocksy Companion ≤ 2.1.55
Patched Versions: 2.1.56

Mitigation steps: Update to Blocksy Companion version 2.1.56 or greater.


Breeze Cache – Unauthenticated Cache Poisoning

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Cache Poisoning
CVE: CVE-2026-79713
Number of Installations: 300,000+
Affected Software: Breeze Cache ≤ 2.5.14
Patched Versions: 2.5.15

Mitigation steps: Update to Breeze Cache version 2.5.15 or greater.


Ad Inserter – Missing Authorization to Unauthenticated Header/Footer Code Disclosure via ‘ai-debug-code’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter
CVE: CVE-2026-11984
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.16
Patched Versions: 2.8.17

Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.


Formidable Forms – Unauthenticated Content Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Content Injection
CVE: CVE-2026-85641
Number of Installations: 300,000+
Affected Software: Formidable Forms ≤ 6.34
Patched Versions: 6.35

Mitigation steps: Update to Formidable Forms version 6.35 or greater.


Otter Blocks – Missing Authorization to Unauthenticated Purchase Verification Bypass

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Purchase Verification Bypass
CVE: CVE-2026-4945
Number of Installations: 300,000+
Affected Software: Otter Blocks ≤ 3.1.7
Patched Versions: 3.1.8

Mitigation steps: Update to Otter Blocks version 3.1.8 or greater.


Unlimited Elements For Elementor – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-85304
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.17
Patched Versions: 2.0.18

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.18 or greater.


WP Activity Log – Authenticated (Administrator+) SQL Injection

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection
CVE: CVE-2026-62085
Number of Installations: 300,000+
Affected Software: WP Activity Log ≤ 5.6.6
Patched Versions: 5.6.7

Mitigation steps: Update to WP Activity Log version 5.6.7 or greater.


CMB2 – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-80338
Number of Installations: 300,000+
Affected Software: CMB2 ≤ 2.12.0
Patched Versions: 2.13.0

Mitigation steps: Update to CMB2 version 2.13.0 or greater.


Photo Gallery, Sliders, Proofing and Themes – Authenticated (Admin+) Insecure Direct Object Reference

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) Insecure Direct Object Reference
CVE: CVE-2026-81654
Number of Installations: 300,000+
Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.4.0
Patched Versions: 4.5.0

Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.0 or greater.


Photo Gallery, Sliders, Proofing and Themes – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-81652
Number of Installations: 300,000+
Affected Software: Photo Gallery, Sliders, Proofing and Themes ≤ 4.4.0
Patched Versions: 4.5.0

Mitigation steps: Update to Photo Gallery, Sliders, Proofing and Themes version 4.5.0 or greater.


CartFlows – Authenticated (Contributor+) Remote Code Execution

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Remote Code Execution
CVE: CVE-2026-96837
Number of Installations: 200,000+
Affected Software: CartFlows ≤ 3.2.0
Patched Versions: 3.2.1

Mitigation steps: Update to CartFlows version 3.2.1 or greater.


Migrate Guru – Unauthenticated Denial of Service

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-84778
Number of Installations: 200,000+
Affected Software: Migrate Guru ≤ 6.65
Patched Versions: 6.72

Mitigation steps: Update to Migrate Guru version 6.72 or greater.


MalCare WordPress Security Plugin – Unauthenticated Denial of Service

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-84776
Number of Installations: 200,000+
Affected Software: MalCare WordPress Security Plugin ≤ 6.69
Patched Versions: 6.72

Mitigation steps: Update to MalCare WordPress Security Plugin version 6.72 or greater.


CMP – Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action

Security Risk: High
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action
CVE: CVE-2026-12470
Number of Installations: 200,000+
Affected Software: CMP ≤ 4.1.17
Patched Versions: 4.1.18

Mitigation steps: Update to CMP version 4.1.18 or greater.


Ultimate Member – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-85680
Number of Installations: 200,000+
Affected Software: Ultimate Member ≤ 2.13.0
Patched Versions: 2.13.1

Mitigation steps: Update to Ultimate Member version 2.13.1 or greater.


Optimole – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84829
Number of Installations: 200,000+
Affected Software: Optimole ≤ 4.2.11
Patched Versions: 4.2.12

Mitigation steps: Update to Optimole version 4.2.12 or greater.


Spam protection, Honeypot, Anti-Spam by CleanTalk – Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder
CVE: CVE-2026-77830
Number of Installations: 200,000+
Affected Software: Spam protection, Honeypot, Anti-Spam by CleanTalk ≤ 6.86
Patched Versions: 6.87

Mitigation steps: Update to Spam protection, Honeypot, Anti-Spam by CleanTalk version 6.87 or greater.


iubenda – Unauthenticated Stored Cross-Site Scripting via Comment Content

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content
CVE: CVE-2026-77263
Number of Installations: 200,000+
Affected Software: iubenda ≤ 3.13.4
Patched Versions: 3.13.5

Mitigation steps: Update to iubenda version 3.13.5 or greater.


iubenda – Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite
CVE: CVE-2026-77233
Number of Installations: 200,000+
Affected Software: iubenda ≤ 3.13.4
Patched Versions: 3.13.5

Mitigation steps: Update to iubenda version 3.13.5 or greater.


InfiniteWP Client – Authenticated (Admin+) SQL Injection via ‘iwp_get_comments_*’ Array Key

Security Risk: Low
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key
CVE: CVE-2026-17576
Number of Installations: 200,000+
Affected Software: InfiniteWP Client ≤ 1.13.9
Patched Versions: 1.13.10

Mitigation steps: Update to InfiniteWP Client version 1.13.10 or greater.


Spam protection, Honeypot, Anti-Spam by CleanTalk – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-19855
Number of Installations: 200,000+
Affected Software: Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87
Patched Versions: 6.87

Mitigation steps: Update to Spam protection, Honeypot, Anti-Spam by CleanTalk version 6.87 or greater.


Redirection for Contact Form 7 – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-80439
Number of Installations: 200,000+
Affected Software: Redirection for Contact Form 7 2.2.7 - 3.2.10
Patched Versions: 3.2.11

Mitigation steps: Update to Redirection for Contact Form 7 version 3.2.11 or greater.


Gutenberg Essential Blocks – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘marker’ Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute
CVE: CVE-2026-96256
Number of Installations: 200,000+
Affected Software: Gutenberg Essential Blocks ≤ 6.4.5
Patched Versions: 6.4.6

Mitigation steps: Update to Gutenberg Essential Blocks version 6.4.6 or greater.


Qi Addons For Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-62079
Number of Installations: 200,000+
Affected Software: Qi Addons For Elementor ≤ 1.11
Patched Versions: 1.11.1

Mitigation steps: Update to Qi Addons For Elementor version 1.11.1 or greater.


Supreme Modules Lite – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-102384
Number of Installations: 200,000+
Affected Software: Supreme Modules Lite ≤ 2.5.63
Patched Versions: 2.5.64

Mitigation steps: Update to Supreme Modules Lite version 2.5.64 or greater.


Optimole – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-96531
Number of Installations: 200,000+
Affected Software: Optimole 4.0.0 - 4.2.12
Patched Versions: 4.2.13

Mitigation steps: Update to Optimole version 4.2.13 or greater.


DearFlip – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘.dvcss’ Element Class Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute
CVE: CVE-2026-8623
Number of Installations: 200,000+
Affected Software: DearFlip ≤ 2.4.30
Patched Versions: 2.4.37

Mitigation steps: Update to DearFlip version 2.4.37 or greater.


Social Chat – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘consent_message’ JSON Attribute in .qlwapp data-box

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box
CVE: CVE-2026-18404
Number of Installations: 200,000+
Affected Software: Social Chat ≤ 8.6.2
Patched Versions: 8.6.3

Mitigation steps: Update to Social Chat version 8.6.3 or greater.


DearFlip – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘.df-element’ Element Inner HTML

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML
CVE: CVE-2026-8625
Number of Installations: 200,000+
Affected Software: DearFlip ≤ 2.4.30
Patched Versions: 2.4.37

Mitigation steps: Update to DearFlip version 2.4.37 or greater.


JetBackup – Authenticated (Subscriber+) Privilege Escalation

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Privilege Escalation
CVE: CVE-2026-19453
Number of Installations: 200,000+
Affected Software: JetBackup 3.1.7.9 - 3.1.23.3
Patched Versions: 3.1.23.5

Mitigation steps: Update to JetBackup version 3.1.23.5 or greater.


Qi Addons For Elementor – Reflected DOM-Based Cross-Site Scripting via ‘s’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Reflected DOM-Based Cross-Site Scripting via 's' Parameter
CVE: CVE-2026-92249
Number of Installations: 200,000+
Affected Software: Qi Addons For Elementor ≤ 1.11
Patched Versions: 1.11.1

Mitigation steps: Update to Qi Addons For Elementor version 1.11.1 or greater.


Newsletter – Reflected Cross-Site Scripting via ‘nn’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'nn' Parameter
CVE: CVE-2026-90981
Number of Installations: 200,000+
Affected Software: Newsletter ≤ 9.3.8
Patched Versions: 9.3.9

Mitigation steps: Update to Newsletter version 9.3.9 or greater.


Simple CAPTCHA with Cloudflare Turnstile – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-66632
Number of Installations: 200,000+
Affected Software: Simple CAPTCHA with Cloudflare Turnstile ≤ 1.42.1
Patched Versions: 1.42.3

Mitigation steps: Update to Simple CAPTCHA with Cloudflare Turnstile version 1.42.3 or greater.


FileBird – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-15004
Number of Installations: 200,000+
Affected Software: FileBird ≤ 6.5.6
Patched Versions: 6.5.7

Mitigation steps: Update to FileBird version 6.5.7 or greater.


Mailchimp for WooCommerce – Unauthenticated Insecure Direct Object Reference

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-92436
Number of Installations: 200,000+
Affected Software: Mailchimp for WooCommerce ≤ 6.2
Patched Versions: 6.3

Mitigation steps: Update to Mailchimp for WooCommerce version 6.3 or greater.


TikTok – Missing Authorization to Unauthenticated TikTok Integration Takeover via ‘auth_code’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter
CVE: CVE-2026-18346
Number of Installations: 200,000+
Affected Software: TikTok ≤ 1.4.1
Patched Versions: 1.4.2

Mitigation steps: Update to TikTok version 1.4.2 or greater.


TikTok – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-92965
Number of Installations: 200,000+
Affected Software: TikTok 1.2.0 - 1.4.1
Patched Versions: 1.4.2

Mitigation steps: Update to TikTok version 1.4.2 or greater.


Mailchimp for WooCommerce – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-92435
Number of Installations: 200,000+
Affected Software: Mailchimp for WooCommerce ≤ 6.1.0
Patched Versions: 6.1.1

Mitigation steps: Update to Mailchimp for WooCommerce version 6.1.1 or greater.


Simple CAPTCHA with Cloudflare Turnstile – Captcha Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Captcha Bypass
CVE: CVE-2026-66674
Number of Installations: 200,000+
Affected Software: Simple CAPTCHA with Cloudflare Turnstile ≤ 1.42.1
Patched Versions: 1.42.3

Mitigation steps: Update to Simple CAPTCHA with Cloudflare Turnstile version 1.42.3 or greater.


Appointment Booking Plugin – Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field
CVE: CVE-2026-92966
Number of Installations: 100,000+
Affected Software: Appointment Booking Plugin ≤ 5.7.0
Patched Versions: 5.7.1

Mitigation steps: Update to Appointment Booking Plugin version 5.7.1 or greater.


Tutor LMS – Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution
CVE: CVE-2026-78175
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.7
Patched Versions: 4.0.8

Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.


Modula Image Gallery – Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via ‘file’ Parameter

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter
CVE: CVE-2026-92713
Number of Installations: 100,000+
Affected Software: Modula Image Gallery ≤ 3.0.2
Patched Versions: 3.0.3

Mitigation steps: Update to Modula Image Gallery version 3.0.3 or greater.


Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Authenticated (Subscriber+) Arbitrary Shortcode Execution via ‘eup_bio’ Biography Field (Entity-Encoded Shortcode Bracket)

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)
CVE: CVE-2026-85658
Number of Installations: 100,000+
Affected Software: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content ≤ 4.17.2
Patched Versions: 4.17.3

Mitigation steps: Update to Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content version 4.17.3 or greater.


Two Factor – Unauthenticated Denial of Service

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-100508
Number of Installations: 100,000+
Affected Software: Two Factor ≤ 0.16.0
Patched Versions: 0.17.0

Mitigation steps: Update to Two Factor version 0.17.0 or greater.


Modula Image Gallery – Missing Authorization to Unauthenticated Private Gallery Image Disclosure via ‘modula_gallery_id’ and ‘modula_image_id’ Parameters

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters
CVE: CVE-2026-89406
Number of Installations: 100,000+
Affected Software: Modula Image Gallery ≤ 3.0.1
Patched Versions: 3.0.2

Mitigation steps: Update to Modula Image Gallery version 3.0.2 or greater.


GiveWP – Unauthenticated Privilege Escalation

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-85530
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.8.0
Patched Versions: 4.16.8.1

Mitigation steps: Update to GiveWP version 4.16.8.1 or greater.


Advanced Custom Fields: Extended – Unauthenticated Privilege Escalation

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-80467
Number of Installations: 100,000+
Affected Software: Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6
Patched Versions: 0.9.2.7

Mitigation steps: Update to Advanced Custom Fields: Extended version 0.9.2.7 or greater.


GiveWP – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-96830
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.9
Patched Versions: 4.17.0

Mitigation steps: Update to GiveWP version 4.17.0 or greater.


پارسی دیت – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-96836
Number of Installations: 100,000+
Affected Software: پارسی دیت ≤ 6.3
Patched Versions: 6.4

Mitigation steps: Update to پارسی دیت version 6.4 or greater.


WPS Limit Login – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-93622
Number of Installations: 100,000+
Affected Software: WPS Limit Login ≤ 1.5.9.3
Patched Versions: 1.5.9.4

Mitigation steps: Update to WPS Limit Login version 1.5.9.4 or greater.


Asset CleanUp: Page Speed Booster – Unauthenticated Stored Cross-Site Scripting via Comment Content

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content
CVE: CVE-2026-13354
Number of Installations: 100,000+
Affected Software: Asset CleanUp: Page Speed Booster ≤ 1.4.0.5
Patched Versions: 1.4.0.6

Mitigation steps: Update to Asset CleanUp: Page Speed Booster version 1.4.0.6 or greater.


User Role Editor – Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant
CVE: CVE-2026-75927
Number of Installations: 100,000+
Affected Software: User Role Editor ≤ 2.50.0
Patched Versions: 2.50.1

Mitigation steps: Update to User Role Editor version 2.50.1 or greater.


Hide My WP Ghost – Unauthenticated Server-Side Request Forgery

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Server-Side Request Forgery
CVE: CVE-2026-81806
Number of Installations: 100,000+
Affected Software: Hide My WP Ghost ≤ 7.0.09
Patched Versions: 7.0.10

Mitigation steps: Update to Hide My WP Ghost version 7.0.10 or greater.


Tutor LMS – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via ‘student_id’ Parameter

Security Risk: Low
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter
CVE: CVE-2026-89333
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.8
Patched Versions: 4.0.9

Mitigation steps: Update to Tutor LMS version 4.0.9 or greater.


GiveWP – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-85113
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.8
Patched Versions: 4.16.9

Mitigation steps: Update to GiveWP version 4.16.9 or greater.


Photo Gallery by 10Web – Authenticated (Author+) SQL Injection via ‘album_id’ Shortcode Attribute

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute
CVE: CVE-2026-85652
Number of Installations: 100,000+
Affected Software: Photo Gallery by 10Web ≤ 1.8.44
Patched Versions: 1.8.45

Mitigation steps: Update to Photo Gallery by 10Web version 1.8.45 or greater.


Download Manager – Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via ‘wpdm_duplicate’ Parameter

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter
CVE: CVE-2026-92714
Number of Installations: 100,000+
Affected Software: Download Manager ≤ 3.3.68
Patched Versions: 3.3.69

Mitigation steps: Update to Download Manager version 3.3.69 or greater.


AI Engine – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via ‘mediaId’ Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter
CVE: CVE-2026-89141
Number of Installations: 100,000+
Affected Software: AI Engine ≤ 3.7.7
Patched Versions: 3.7.8

Mitigation steps: Update to AI Engine version 3.7.8 or greater.


Beaver Builder Page Builder – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-18021
Number of Installations: 100,000+
Affected Software: Beaver Builder Page Builder ≤ 2.10.3.1
Patched Versions: 2.10.3.2

Mitigation steps: Update to Beaver Builder Page Builder version 2.10.3.2 or greater.


LukasApps CAPTCHA tools for Contact Form 7 – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-85117
Number of Installations: 100,000+
Affected Software: LukasApps CAPTCHA tools for Contact Form 7 0.1.7 - 0.1.8
Patched Versions: 0.1.9

Mitigation steps: Update to LukasApps CAPTCHA tools for Contact Form 7 version 0.1.9 or greater.


Pods – Authenticated (Author+) Arbitrary File Read

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Arbitrary File Read
CVE: CVE-2026-74853
Number of Installations: 100,000+
Affected Software: Pods 3.3 - 3.3.9.1
Patched Versions: 3.3.9.2

Mitigation steps: Update to Pods version 3.3.9.2 or greater.


EmbedPress – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-85002
Number of Installations: 100,000+
Affected Software: EmbedPress ≤ 4.6.6
Patched Versions: 4.6.7

Mitigation steps: Update to EmbedPress version 4.6.7 or greater.


The Plus Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-96829
Number of Installations: 100,000+
Affected Software: The Plus Addons for Elementor ≤ 6.5.1
Patched Versions: 6.5.2

Mitigation steps: Update to The Plus Addons for Elementor version 6.5.2 or greater.


The Post Grid – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-94680
Number of Installations: 100,000+
Affected Software: The Post Grid ≤ 7.9.5
Patched Versions: 7.9.6

Mitigation steps: Update to The Post Grid version 7.9.6 or greater.


The Post Grid – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-84151
Number of Installations: 100,000+
Affected Software: The Post Grid ≤ 7.9.4
Patched Versions: 7.9.5

Mitigation steps: Update to The Post Grid version 7.9.5 or greater.


VK All in One Expansion Unit – Authenticated (Author+) Stored Cross-Site Scripting via ‘vkExUnit_cta_img_position’ Post Meta

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta
CVE: CVE-2026-17586
Number of Installations: 100,000+
Affected Software: VK All in One Expansion Unit ≤ 9.118.0
Patched Versions: 9.119.0

Mitigation steps: Update to VK All in One Expansion Unit version 9.119.0 or greater.


Element Pack Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-66574
Number of Installations: 100,000+
Affected Software: Element Pack Addons for Elementor ≤ 8.8.3
Patched Versions: 8.8.4

Mitigation steps: Update to Element Pack Addons for Elementor version 8.8.4 or greater.


Custom Twitter Feeds – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘buttoncolor’ Shortcode Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute
CVE: CVE-2026-84909
Number of Installations: 100,000+
Affected Software: Custom Twitter Feeds ≤ 2.8.0
Patched Versions: 2.9.0

Mitigation steps: Update to Custom Twitter Feeds version 2.9.0 or greater.


Photo Gallery by 10Web – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
CVE: CVE-2026-86311
Number of Installations: 100,000+
Affected Software: Photo Gallery by 10Web ≤ 1.8.44
Patched Versions: 1.8.45

Mitigation steps: Update to Photo Gallery by 10Web version 1.8.45 or greater.


ShopEngine Elementor WooCommerce Builder Addon – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘shopengine_product_title_header_size’ Parameter

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'shopengine_product_title_header_size' Parameter
CVE: CVE-2026-85575
Number of Installations: 100,000+
Affected Software: ShopEngine Elementor WooCommerce Builder Addon ≤ 4.9.5
Patched Versions: 4.9.6

Mitigation steps: Update to ShopEngine Elementor WooCommerce Builder Addon version 4.9.6 or greater.


Aruba HiSpeed Cache – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content
CVE: CVE-2026-15889
Number of Installations: 100,000+
Affected Software: Aruba HiSpeed Cache ≤ 3.0.14
Patched Versions: 3.0.15

Mitigation steps: Update to Aruba HiSpeed Cache version 3.0.15 or greater.


Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-85418
Number of Installations: 100,000+
Affected Software: Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More ≤ 3.0.8
Patched Versions: 3.0.9

Mitigation steps: Update to Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More version 3.0.9 or greater.


Pods – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘not_found’ Shortcode Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute
CVE: CVE-2026-76573
Number of Installations: 100,000+
Affected Software: Pods ≤ 3.3.9.1
Patched Versions: 3.3.9.2

Mitigation steps: Update to Pods version 3.3.9.2 or greater.


Gallery : FooGallery – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘custom_settings’ Shortcode Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute
CVE: CVE-2026-85414
Number of Installations: 100,000+
Affected Software: Gallery : FooGallery ≤ 3.3.2
Patched Versions: 3.3.3

Mitigation steps: Update to Gallery : FooGallery version 3.3.3 or greater.


Social Media Share Buttons & Social Sharing Icons – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-19719
Number of Installations: 100,000+
Affected Software: Social Media Share Buttons & Social Sharing Icons < 3.0.1
Patched Versions: 3.0.1

Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.1 or greater.


Social Media Share Buttons & Social Sharing Icons – Reflected DOM-Based Cross-Site Scripting via URL

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Reflected DOM-Based Cross-Site Scripting via URL
CVE: CVE-2026-89047
Number of Installations: 100,000+
Affected Software: Social Media Share Buttons & Social Sharing Icons ≤ 3.0.1
Patched Versions: 3.0.2

Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.2 or greater.


Tutor LMS – Reflected Cross-Site Scripting via ‘back_url’ and ‘search’ Parameters

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters
CVE: CVE-2026-89081
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.8
Patched Versions: 4.0.9

Mitigation steps: Update to Tutor LMS version 4.0.9 or greater.


EmbedPress – Reflected Cross-Site Scripting via ‘hash’ and ‘unique’ Parameters

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters
CVE: CVE-2026-89330
Number of Installations: 100,000+
Affected Software: EmbedPress ≤ 4.6.5
Patched Versions: 4.6.6

Mitigation steps: Update to EmbedPress version 4.6.6 or greater.


Relevanssi – Reflected Cross-Site Scripting

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-19985
Number of Installations: 100,000+
Affected Software: Relevanssi ≤ 4.28.1
Patched Versions: 4.28.2

Mitigation steps: Update to Relevanssi version 4.28.2 or greater.


Social Media Share Buttons & Social Sharing Icons – Reflected Cross-Site Scripting

Security Risk: Low
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-19723
Number of Installations: 100,000+
Affected Software: Social Media Share Buttons & Social Sharing Icons < 3.0.1
Patched Versions: 3.0.1

Mitigation steps: Update to Social Media Share Buttons & Social Sharing Icons version 3.0.1 or greater.


Photo Gallery by 10Web – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-12865
Number of Installations: 100,000+
Affected Software: Photo Gallery by 10Web < 1.8.44
Patched Versions: 1.8.44

Mitigation steps: Update to Photo Gallery by 10Web version 1.8.44 or greater.


Asset CleanUp: Page Speed Booster – Authenticated (Administrator+) Server-Side Request Forgery via ‘page_url’ Parameter

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter
CVE: CVE-2026-12037
Number of Installations: 100,000+
Affected Software: Asset CleanUp: Page Speed Booster ≤ 1.4.0.5
Patched Versions: 1.4.0.6

Mitigation steps: Update to Asset CleanUp: Page Speed Booster version 1.4.0.6 or greater.


WP Popular Posts – Unauthenticated Information Disclosure in ‘post_type’ and ‘context’ Parameters

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters
CVE: CVE-2026-92548
Number of Installations: 100,000+
Affected Software: WP Popular Posts ≤ 7.4.2
Patched Versions: 7.4.3

Mitigation steps: Update to WP Popular Posts version 7.4.3 or greater.


GiveWP – Unauthenticated User Impersonation

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated User Impersonation
CVE: CVE-2026-97196
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.9
Patched Versions: 4.17.0

Mitigation steps: Update to GiveWP version 4.17.0 or greater.


GiveWP – Unauthenticated Insecure Direct Object Reference

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-97066
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.9
Patched Versions: 4.17.0

Mitigation steps: Update to GiveWP version 4.17.0 or greater.


Captcha Code – Unauthenticated Login Captcha Protection Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Login Captcha Protection Bypass
CVE: CVE-2026-94457
Number of Installations: 100,000+
Affected Software: Captcha Code ≤ 3.32
Patched Versions: 3.33

Mitigation steps: Update to Captcha Code version 3.33 or greater.


Secure Custom Fields – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-92403
Number of Installations: 100,000+
Affected Software: Secure Custom Fields ≤ 6.9.3
Patched Versions: 6.9.4

Mitigation steps: Update to Secure Custom Fields version 6.9.4 or greater.


Hide My WP Ghost – Unauthenticated Protection Mechanism Bypass

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Protection Mechanism Bypass
CVE: CVE-2026-86796
Number of Installations: 100,000+
Affected Software: Hide My WP Ghost ≤ 7.0.10
Patched Versions: 7.0.11

Mitigation steps: Update to Hide My WP Ghost version 7.0.11 or greater.


Hide My WP Ghost – Unauthenticated Login Protection Bypass

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Login Protection Bypass
CVE: CVE-2026-86800
Number of Installations: 100,000+
Affected Software: Hide My WP Ghost ≤ 7.0.10
Patched Versions: 7.0.11

Mitigation steps: Update to Hide My WP Ghost version 7.0.11 or greater.


Schema & Structured Data for WP & AMP – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-82124
Number of Installations: 100,000+
Affected Software: Schema & Structured Data for WP & AMP ≤ 1.65
Patched Versions: 1.66

Mitigation steps: Update to Schema & Structured Data for WP & AMP version 1.66 or greater.


Schema & Structured Data for WP & AMP – Unauthenticated Insecure Direct Object Reference

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-82125
Number of Installations: 100,000+
Affected Software: Schema & Structured Data for WP & AMP ≤ 1.65
Patched Versions: 1.66

Mitigation steps: Update to Schema & Structured Data for WP & AMP version 1.66 or greater.


bbPress – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-62137
Number of Installations: 100,000+
Affected Software: bbPress ≤ 2.6.14
Patched Versions: 2.6.15

Mitigation steps: Update to bbPress version 2.6.15 or greater.


Payment Plugins for Stripe WooCommerce – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-80339
Number of Installations: 100,000+
Affected Software: Payment Plugins for Stripe WooCommerce ≤ 4.0.11
Patched Versions: 4.0.12

Mitigation steps: Update to Payment Plugins for Stripe WooCommerce version 4.0.12 or greater.


Content Views – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-17517
Number of Installations: 100,000+
Affected Software: Content Views < 4.5.1.2
Patched Versions: 4.5.1.2

Mitigation steps: Update to Content Views version 4.5.1.2 or greater.


EmbedPress – Unauthenticated Paid API Consumption and Database Row Injection

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Paid API Consumption and Database Row Injection
CVE: CVE-2026-84936
Number of Installations: 100,000+
Affected Software: EmbedPress 4.6.0 - 4.6.3
Patched Versions: 4.6.4

Mitigation steps: Update to EmbedPress version 4.6.4 or greater.


FormLayer – Unauthenticated Information Exposure

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-78151
Number of Installations: 100,000+
Affected Software: FormLayer < 1.0.9
Patched Versions: 1.0.9

Mitigation steps: Update to FormLayer version 1.0.9 or greater.


WPML Multilingual & Multicurrency for WooCommerce – Authenticated (Shop Manager+) SQL Injection via Exchange Rate Field

Security Risk: High
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) SQL Injection via Exchange Rate Field
CVE: Not provided
Number of Installations: 100,000+
Affected Software: WPML Multilingual & Multicurrency for WooCommerce ≤ 5.5.7
Patched Versions: 5.5.8

Mitigation steps: Update to WPML Multilingual & Multicurrency for WooCommerce version 5.5.8 or greater.


Hide My WP Ghost – Unauthenticated Open Redirect via ‘redirect_to’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Open Redirect via 'redirect_to' Parameter
CVE: CVE-2026-7527
Number of Installations: 100,000+
Affected Software: Hide My WP Ghost ≤ 7.0.02
Patched Versions: 7.0.03

Mitigation steps: Update to Hide My WP Ghost version 7.0.03 or greater.


Temporary Login Without Password – Authenticated (Administrator+) Privilege Escalation

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Privilege Escalation
CVE: CVE-2026-77752
Number of Installations: 100,000+
Affected Software: Temporary Login Without Password 1.5 - 1.9.8
Patched Versions: 1.9.9

Mitigation steps: Update to Temporary Login Without Password version 1.9.9 or greater.


Newsletters, Email Marketing, SMS and Popups by Omnisend – Authenticated (Subscriber+) Insecure Direct Object Reference

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Insecure Direct Object Reference
CVE: CVE-2026-97074
Number of Installations: 100,000+
Affected Software: Newsletters, Email Marketing, SMS and Popups by Omnisend ≤ 1.9.0
Patched Versions: 1.9.1

Mitigation steps: Update to Newsletters, Email Marketing, SMS and Popups by Omnisend version 1.9.1 or greater.


GiveWP – Authenticated (Subscriber+) Information Exposure

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-96834
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.9
Patched Versions: 4.17.0

Mitigation steps: Update to GiveWP version 4.17.0 or greater.


MailerLite – Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion
CVE: CVE-2026-3253
Number of Installations: 100,000+
Affected Software: MailerLite ≤ 1.7.21
Patched Versions: 1.7.22

Mitigation steps: Update to MailerLite version 1.7.22 or greater.


Tutor LMS – Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via ‘payload’ Parameter

Security Risk: Low
Exploitation Level: Requires Custom or higher level authentication.
Vulnerability: Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter
CVE: CVE-2026-18439
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.7
Patched Versions: 4.0.8

Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.


Tutor LMS – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via ‘lesson_id’ Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter
CVE: CVE-2026-88944
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.8
Patched Versions: 4.0.9

Mitigation steps: Update to Tutor LMS version 4.0.9 or greater.


Appointment Booking Plugin – Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)

Security Risk: Low
Exploitation Level: Requires Custom or higher level authentication.
Vulnerability: Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)
CVE: CVE-2026-13471
Number of Installations: 100,000+
Affected Software: Appointment Booking Plugin ≤ 5.6.3
Patched Versions: 5.6.4

Mitigation steps: Update to Appointment Booking Plugin version 5.6.4 or greater.


Appointment Booking Plugin – Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via ‘customer[id]’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter
CVE: CVE-2026-18441
Number of Installations: 100,000+
Affected Software: Appointment Booking Plugin ≤ 5.6.9
Patched Versions: 5.6.10

Mitigation steps: Update to Appointment Booking Plugin version 5.6.10 or greater.


Tutor LMS – Authenticated (Subscriber+) Information Exposure

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-85572
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.7
Patched Versions: 4.0.8

Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.


Tutor LMS – REST API Authentication Confusion

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: REST API Authentication Confusion
CVE: CVE-2026-85569
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.7
Patched Versions: 4.0.8

Mitigation steps: Update to Tutor LMS version 4.0.8 or greater.


Schema & Structured Data for WP & AMP – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-82126
Number of Installations: 100,000+
Affected Software: Schema & Structured Data for WP & AMP ≤ 1.65
Patched Versions: 1.66

Mitigation steps: Update to Schema & Structured Data for WP & AMP version 1.66 or greater.


Temporary Login Without Password – Authenticated (Custom Role+) Persistent Access After Login Revocation

Security Risk: High
Exploitation Level: Requires custom cole.
Vulnerability: Authenticated (Custom Role+) Persistent Access After Login Revocation
CVE: CVE-2026-77753
Number of Installations: 100,000+
Affected Software: Temporary Login Without Password < 1.9.9
Patched Versions: 1.9.9

Mitigation steps: Update to Temporary Login Without Password version 1.9.9 or greater.


EmbedPress – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-84926
Number of Installations: 100,000+
Affected Software: EmbedPress 4.6.0 - 4.6.3
Patched Versions: 4.6.4

Mitigation steps: Update to EmbedPress version 4.6.4 or greater.


EmbedPress – Missing Authorization to Authenticated (Contributor+) Site-Wide Places Library Modification

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Site-Wide Places Library Modification
CVE: CVE-2026-84927
Number of Installations: 100,000+
Affected Software: EmbedPress 4.6.0 - 4.6.3
Patched Versions: 4.6.4

Mitigation steps: Update to EmbedPress version 4.6.4 or greater.


Everest Forms – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-62103
Number of Installations: 90,000+
Affected Software: Everest Forms ≤ 3.6.0
Patched Versions: 3.6.1

Mitigation steps: Update to Everest Forms version 3.6.1 or greater.


Go Live Update Urls – Authenticated (Contributor+) PHP Object Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) PHP Object Injection
CVE: CVE-2026-94678
Number of Installations: 90,000+
Affected Software: Go Live Update Urls ≤ 7.0.8
Patched Versions: 7.1.0

Mitigation steps: Update to Go Live Update Urls version 7.1.0 or greater.


Event Tickets and Registration – Missing Authorization to Unauthenticated Stripe Credentials Update

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Stripe Credentials Update
CVE: CVE-2026-3174
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration ≤ 5.27.4
Patched Versions: 5.27.4.1

Mitigation steps: Update to Event Tickets and Registration version 5.27.4.1 or greater.


AI Engine – Unauthenticated Stored Cross-Site Scripting via ‘model_’ Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection
CVE: CVE-2026-96561
Number of Installations: 90,000+
Affected Software: AI Engine ≤ 3.8.0
Patched Versions: 3.8.1

Mitigation steps: Update to AI Engine version 3.8.1 or greater.


Event Tickets and Registration – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-93526
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration ≤ 5.29.4
Patched Versions: 5.29.5

Mitigation steps: Update to Event Tickets and Registration version 5.29.5 or greater.


Kadence WooCommerce Email Designer – Authenticated (Shop Manager+) PHP Object Injection

Security Risk: TBC
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) PHP Object Injection
CVE: CVE-2026-94677
Number of Installations: 90,000+
Affected Software: Kadence WooCommerce Email Designer ≤ 1.5.19.1
Patched Versions: 1.5.19.2

Mitigation steps: Update to Kadence WooCommerce Email Designer version 1.5.19.2 or greater.


Event Tickets and Registration – Authenticated (Contributor+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) SQL Injection
CVE: CVE-2026-97287
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration ≤ 5.29.5
Patched Versions: 5.29.5.1

Mitigation steps: Update to Event Tickets and Registration version 5.29.5.1 or greater.


Hustle – Unauthenticated Arbitrary Shortcode Execution

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-80440
Number of Installations: 90,000+
Affected Software: Hustle < 7.8.14.2
Patched Versions: 7.8.14.2

Mitigation steps: Update to Hustle version 7.8.14.2 or greater.


Booking for Appointments and Events Calendar – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘load_manually’ Parameter

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter
CVE: CVE-2026-10148
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.9
Patched Versions: 2.4.10

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.10 or greater.


Booking for Appointments and Events Calendar – Authenticated (Custom Role+) Privilege Escalation

Security Risk: Medium
Exploitation Level: Requires Custom Role or higher level authentication.
Vulnerability: Authenticated (Custom Role+) Privilege Escalation
CVE: CVE-2026-77705
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar < 2.4.10
Patched Versions: 2.4.10

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.10 or greater.


Booking for Appointments and Events Calendar – Authenticated (Custom+) Missing Authorization to Limited Account Takeover

Security Risk: Medium
Exploitation Level: Requires Custom or higher level authentication.
Vulnerability: Authenticated (Custom+) Missing Authorization to Limited Account Takeover
CVE: CVE-2026-14311
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.4
Patched Versions: 2.4.5

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.5 or greater.


AI Engine – Unauthenticated Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-93623
Number of Installations: 90,000+
Affected Software: AI Engine ≤ 3.7.8
Patched Versions: 3.7.9

Mitigation steps: Update to AI Engine version 3.7.9 or greater.


Booking for Appointments and Events Calendar – Missing Authorization to Unauthenticated Payment Bypass

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Payment Bypass
CVE: CVE-2026-16582
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.5
Patched Versions: 2.4.6

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.6 or greater.


Booking for Appointments and Events Calendar – Unauthenticated Payment Bypass

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Payment Bypass
CVE: CVE-2026-77689
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar 9.0 - 9.8.0
Patched Versions: 9.8.1

Mitigation steps: Update to Booking for Appointments and Events Calendar version 9.8.1 or greater.


Booking for Appointments and Events Calendar – Authenticated (Editor+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) SQL Injection
CVE: CVE-2026-62112
Number of Installations: 90,000+
Affected Software: Booking for Appointments and Events Calendar ≤ 2.4.9
Patched Versions: 2.4.10

Mitigation steps: Update to Booking for Appointments and Events Calendar version 2.4.10 or greater.


BuddyPress – Insecure Direct Object Reference to Notifications Deletion

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Insecure Direct Object Reference to Notifications Deletion
CVE: CVE-2024-12145
Number of Installations: 90,000+
Affected Software: BuddyPress ≤ 14.3.3
Patched Versions: 14.3.4

Mitigation steps: Update to BuddyPress version 14.3.4 or greater.


JetFormBuilder – Unauthenticated Privilege Escalation via ‘_jet_engine_booking_form_id’ Parameter

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter
CVE: CVE-2026-12793
Number of Installations: 80,000+
Affected Software: JetFormBuilder ≤ 3.6.2
Patched Versions: 3.6.2.1

Mitigation steps: Update to JetFormBuilder version 3.6.2.1 or greater.


JetFormBuilder – Unauthenticated Arbitrary Shortcode Execution

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-19859
Number of Installations: 80,000+
Affected Software: JetFormBuilder < 3.6.5.2
Patched Versions: 3.6.5.2

Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.


Customer Reviews for WooCommerce – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via ‘items[][media]’ Parameter

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter
CVE: CVE-2026-89055
Number of Installations: 80,000+
Affected Software: Customer Reviews for WooCommerce ≤ 5.120.0
Patched Versions: 5.121.0

Mitigation steps: Update to Customer Reviews for WooCommerce version 5.121.0 or greater.


SureCart – Authenticated (Subscriber+) Arbitrary Account Email Takeover

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Arbitrary Account Email Takeover
CVE: CVE-2026-18480
Number of Installations: 80,000+
Affected Software: SureCart < 4.6.3
Patched Versions: 4.6.3

Mitigation steps: Update to SureCart version 4.6.3 or greater.


HUSKY – Unauthenticated Local File Inclusion via ‘custom_tpl’ Shortcode Attribute via ‘woof_draw_products’ AJAX

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX
CVE: CVE-2026-92969
Number of Installations: 80,000+
Affected Software: HUSKY ≤ 1.4.4
Patched Versions: 1.4.5

Mitigation steps: Update to HUSKY version 1.4.5 or greater.


JetFormBuilder – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84817
Number of Installations: 80,000+
Affected Software: JetFormBuilder ≤ 3.6.5.1
Patched Versions: 3.6.5.2

Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.


JetFormBuilder – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-19861
Number of Installations: 80,000+
Affected Software: JetFormBuilder < 3.6.5.2
Patched Versions: 3.6.5.2

Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.


JetFormBuilder – Authenticated (Administrator+) Arbitrary File Deletion

Security Risk: Medium
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Arbitrary File Deletion
CVE: CVE-2026-19860
Number of Installations: 80,000+
Affected Software: JetFormBuilder ≤ 3.6.5.2
Patched Versions: 3.6.5.3

Mitigation steps: Update to JetFormBuilder version 3.6.5.3 or greater.


Strong Testimonials – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-97286
Number of Installations: 80,000+
Affected Software: Strong Testimonials ≤ 3.3.11
Patched Versions: 3.3.12

Mitigation steps: Update to Strong Testimonials version 3.3.12 or greater.


Kubio AI Page Builder – Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via kubio/copyright Block Content
CVE: CVE-2026-14472
Number of Installations: 80,000+
Affected Software: Kubio AI Page Builder ≤ 2.8.4
Patched Versions: 2.8.5

Mitigation steps: Update to Kubio AI Page Builder version 2.8.5 or greater.


Strong Testimonials – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘lightbox_class’ Shortcode Attribute

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute
CVE: CVE-2026-92622
Number of Installations: 80,000+
Affected Software: Strong Testimonials ≤ 3.3.8
Patched Versions: 3.3.9

Mitigation steps: Update to Strong Testimonials version 3.3.9 or greater.


GutenKit – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘postBodyCss’

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss'
CVE: CVE-2026-2573
Number of Installations: 80,000+
Affected Software: GutenKit ≤ 2.4.4
Patched Versions: 2.4.5

Mitigation steps: Update to GutenKit version 2.4.5 or greater.


SureCart – Authenticated (Shop Worker+) Privilege Escalation

Security Risk: TBC
Exploitation Level: Requires Shop Worker or higher level authentication.
Vulnerability: Authenticated (Shop Worker+) Privilege Escalation
CVE: CVE-2026-97245
Number of Installations: 80,000+
Affected Software: SureCart ≤ 4.7.2
Patched Versions: 4.7.3

Mitigation steps: Update to SureCart version 4.7.3 or greater.


JetFormBuilder – Reflected Cross-Site Scripting via ‘jfb_xss’ (URL Query Variable) Parameter via Calculated Field

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field
CVE: CVE-2026-92212
Number of Installations: 80,000+
Affected Software: JetFormBuilder ≤ 3.6.5.3
Patched Versions: 3.6.5.4

Mitigation steps: Update to JetFormBuilder version 3.6.5.4 or greater.


ShopLentor – Reflected Cross-Site Scripting via Query-String Parameter Name

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via Query-String Parameter Name
CVE: CVE-2026-92554
Number of Installations: 80,000+
Affected Software: ShopLentor ≤ 3.5.1
Patched Versions: 3.5.2

Mitigation steps: Update to ShopLentor version 3.5.2 or greater.


HUSKY – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-18562
Number of Installations: 80,000+
Affected Software: HUSKY ≤ 1.4.3
Patched Versions: 1.4.3.1

Mitigation steps: Update to HUSKY version 1.4.3.1 or greater.


Customer Reviews for WooCommerce – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-96823
Number of Installations: 80,000+
Affected Software: Customer Reviews for WooCommerce ≤ 5.120.0
Patched Versions: 5.121.0

Mitigation steps: Update to Customer Reviews for WooCommerce version 5.121.0 or greater.


Payment Plugins for PayPal WooCommerce – Unauthenticated Insecure Direct Object Reference

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-80342
Number of Installations: 80,000+
Affected Software: Payment Plugins for PayPal WooCommerce ≤ 2.0.26
Patched Versions: 2.0.27

Mitigation steps: Update to Payment Plugins for PayPal WooCommerce version 2.0.27 or greater.


SureCart – Unauthorized WordPress Account Creation

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthorized WordPress Account Creation
CVE: CVE-2026-75793
Number of Installations: 80,000+
Affected Software: SureCart < 4.7.0
Patched Versions: 4.7.0

Mitigation steps: Update to SureCart version 4.7.0 or greater.


JetFormBuilder – Unauthenticated Information Exposure

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-19858
Number of Installations: 80,000+
Affected Software: JetFormBuilder < 3.6.5.2
Patched Versions: 3.6.5.2

Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.


Payment Plugins for PayPal WooCommerce – Unauthenticated Information Exposure

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-80340
Number of Installations: 80,000+
Affected Software: Payment Plugins for PayPal WooCommerce ≤ 2.0.25
Patched Versions: 2.0.26

Mitigation steps: Update to Payment Plugins for PayPal WooCommerce version 2.0.26 or greater.


JetFormBuilder – Missing Authorization to Unauthenticated JetEngine Options Page Modification

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated JetEngine Options Page Modification
CVE: Not provided
Number of Installations: 80,000+
Affected Software: JetFormBuilder ≤ 3.6.2
Patched Versions: 3.6.2.1

Mitigation steps: Update to JetFormBuilder version 3.6.2.1 or greater.


JetFormBuilder – Unauthenticated Email Header Injection

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Email Header Injection
CVE: CVE-2026-19862
Number of Installations: 80,000+
Affected Software: JetFormBuilder < 3.6.5.2
Patched Versions: 3.6.5.2

Mitigation steps: Update to JetFormBuilder version 3.6.5.2 or greater.


Email Log – Authenticated (Administrator+) SQL Injection

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection
CVE: CVE-2026-94174
Number of Installations: 80,000+
Affected Software: Email Log ≤ 2.63
Patched Versions: 2.64

Mitigation steps: Update to Email Log version 2.64 or greater.


Product Feed Manager for WooCommerce – Authenticated (Shop Manager+) Path Traversal to File Deletion via ‘provider’ Parameter

Security Risk: Medium
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter
CVE: CVE-2026-15095
Number of Installations: 80,000+
Affected Software: Product Feed Manager for WooCommerce ≤ 6.6.43
Patched Versions: 6.6.44

Mitigation steps: Update to Product Feed Manager for WooCommerce version 6.6.44 or greater.


Checkout Field Manager (Checkout Manager) for WooCommerce – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-87831
Number of Installations: 80,000+
Affected Software: Checkout Field Manager (Checkout Manager) for WooCommerce ≤ 7.9.6
Patched Versions: 7.9.7

Mitigation steps: Update to Checkout Field Manager (Checkout Manager) for WooCommerce version 7.9.7 or greater.


Checkout Field Manager (Checkout Manager) for WooCommerce – Authenticated (Subscriber+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Insecure Direct Object Reference
CVE: CVE-2026-87829
Number of Installations: 80,000+
Affected Software: Checkout Field Manager (Checkout Manager) for WooCommerce ≤ 7.9.6
Patched Versions: 7.9.7

Mitigation steps: Update to Checkout Field Manager (Checkout Manager) for WooCommerce version 7.9.7 or greater.


Payment Plugins for PayPal WooCommerce – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization
CVE: CVE-2026-80341
Number of Installations: 80,000+
Affected Software: Payment Plugins for PayPal WooCommerce ≤ 2.0.25
Patched Versions: 2.0.26

Mitigation steps: Update to Payment Plugins for PayPal WooCommerce version 2.0.26 or greater.


GutenKit – Authenticated (Contributor+) Arbitrary CSS Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Arbitrary CSS Injection
CVE: CVE-2026-19698
Number of Installations: 80,000+
Affected Software: GutenKit ≤ 2.5.0
Patched Versions: 2.5.1

Mitigation steps: Update to GutenKit version 2.5.1 or greater.


Hummingbird Performance – Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log
CVE: CVE-2026-83627
Number of Installations: 70,000+
Affected Software: Hummingbird Performance ≤ 3.21.0
Patched Versions: 3.21.1

Mitigation steps: Update to Hummingbird Performance version 3.21.1 or greater.


Import and export users and customers – Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields
CVE: CVE-2026-86583
Number of Installations: 70,000+
Affected Software: Import and export users and customers ≤ 2.4.17
Patched Versions: 2.4.18

Mitigation steps: Update to Import and export users and customers version 2.4.18 or greater.


LearnPress – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via ‘item_id’ Parameter

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
CVE: CVE-2026-93882
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.8
Patched Versions: 4.4.9

Mitigation steps: Update to LearnPress version 4.4.9 or greater.


10Web Booster – Authenticated (Contributor+) PHP Object Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) PHP Object Injection
CVE: CVE-2026-94121
Number of Installations: 70,000+
Affected Software: 10Web Booster ≤ 2.33.6
Patched Versions: 2.34.0

Mitigation steps: Update to 10Web Booster version 2.34.0 or greater.


AMP for WP – Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation
CVE: CVE-2026-83591
Number of Installations: 70,000+
Affected Software: AMP for WP ≤ 1.1.16
Patched Versions: 1.1.17

Mitigation steps: Update to AMP for WP version 1.1.17 or greater.


Import and export users and customers – Authenticated (Admin+) Privilege Escalation

Security Risk: Medium
Exploitation Level: Requires Administrator or higher level authentication.
Vulnerability: Authenticated (Admin+) Privilege Escalation
CVE: CVE-2026-92540
Number of Installations: 70,000+
Affected Software: Import and export users and customers ≤ 2.5.1
Patched Versions: 2.5.2

Mitigation steps: Update to Import and export users and customers version 2.5.2 or greater.


Hummingbird Performance – Authenticated (Administrator+) Remote Code Execution

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Remote Code Execution
CVE: CVE-2026-19224
Number of Installations: 70,000+
Affected Software: Hummingbird Performance < 3.21.2
Patched Versions: 3.21.2

Mitigation steps: Update to Hummingbird Performance version 3.21.2 or greater.


Media Library Assistant – Authenticated (Contributor+) SQL Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) SQL Injection
CVE: CVE-2026-97293
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.41
Patched Versions: 3.42

Mitigation steps: Update to Media Library Assistant version 3.42 or greater.


Ninja Tables – Unauthenticated Arbitrary Shortcode Execution

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-86612
Number of Installations: 70,000+
Affected Software: Ninja Tables ≤ 5.2.16
Patched Versions: 5.2.17

Mitigation steps: Update to Ninja Tables version 5.2.17 or greater.


HT Mega Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table ‘display_options’ Setting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting
CVE: CVE-2026-11895
Number of Installations: 70,000+
Affected Software: HT Mega Addons for Elementor ≤ 3.1.1
Patched Versions: 3.1.2

Mitigation steps: Update to HT Mega Addons for Elementor version 3.1.2 or greater.


HT Mega Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-86788
Number of Installations: 70,000+
Affected Software: HT Mega Addons for Elementor 3.2.0 - 3.2.5
Patched Versions: 3.2.6

Mitigation steps: Update to HT Mega Addons for Elementor version 3.2.6 or greater.


Media Library Assistant – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘mla_link_href’ Shortcode Parameter

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter
CVE: CVE-2026-6641
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.35
Patched Versions: 3.36

Mitigation steps: Update to Media Library Assistant version 3.36 or greater.


Media Library Assistant – Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import
CVE: CVE-2026-6642
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.35
Patched Versions: 3.36

Mitigation steps: Update to Media Library Assistant version 3.36 or greater.


Media Library Assistant – Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter
CVE: CVE-2026-6640
Number of Installations: 70,000+
Affected Software: Media Library Assistant ≤ 3.35
Patched Versions: 3.36

Mitigation steps: Update to Media Library Assistant version 3.36 or greater.


LearnPress – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘layout_custom_css’

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css'
CVE: CVE-2026-12230
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.3.9.1
Patched Versions: 4.4.0

Mitigation steps: Update to LearnPress version 4.4.0 or greater.


Greenshift – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-83544
Number of Installations: 70,000+
Affected Software: Greenshift < 13.2.0
Patched Versions: 13.2.0

Mitigation steps: Update to Greenshift version 13.2.0 or greater.


Greenshift – Authenticated (Contributor+) Server-Side Request Forgery

Security Risk: Low
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Server-Side Request Forgery
CVE: CVE-2026-83543
Number of Installations: 70,000+
Affected Software: Greenshift < 13.2.0
Patched Versions: 13.2.0

Mitigation steps: Update to Greenshift version 13.2.0 or greater.


LearnPress – Authenticated (Instructor+) Stored Cross-Site Scripting

Security Risk: TBC
Exploitation Level: Requires Instructor or higher level authentication.
Vulnerability: Authenticated (Instructor+) Stored Cross-Site Scripting
CVE: CVE-2026-82024
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.5
Patched Versions: 4.4.6

Mitigation steps: Update to LearnPress version 4.4.6 or greater.


Import and export users and customers – Authenticated (Subscriber+) Privilege Escalation

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Privilege Escalation
CVE: CVE-2026-94178
Number of Installations: 70,000+
Affected Software: Import and export users and customers ≤ 2.5.2
Patched Versions: 2.5.4

Mitigation steps: Update to Import and export users and customers version 2.5.4 or greater.


LearnPress – Reflected Cross-Site Scripting

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-86444
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.6
Patched Versions: 4.4.7

Mitigation steps: Update to LearnPress version 4.4.7 or greater.


Import and export users and customers – Authenticated (Administrator+) Server-Side Request Forgery

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Server-Side Request Forgery
CVE: CVE-2026-16542
Number of Installations: 70,000+
Affected Software: Import and export users and customers ≤ 2.4.4
Patched Versions: 2.4.5

Mitigation steps: Update to Import and export users and customers version 2.4.5 or greater.


10Web Booster – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-82195
Number of Installations: 70,000+
Affected Software: 10Web Booster ≤ 2.33.0
Patched Versions: 2.34.0

Mitigation steps: Update to 10Web Booster version 2.34.0 or greater.


WPC Smart Compare for WooCommerce – Unauthenticated Information Exposure

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-90985
Number of Installations: 70,000+
Affected Software: WPC Smart Compare for WooCommerce ≤ 6.6.0
Patched Versions: 6.6.1

Mitigation steps: Update to WPC Smart Compare for WooCommerce version 6.6.1 or greater.


LearnPress – Unauthenticated Information Exposure

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-86446
Number of Installations: 70,000+
Affected Software: LearnPress 4.4.3 - 4.4.6
Patched Versions: 4.4.7

Mitigation steps: Update to LearnPress version 4.4.7 or greater.


3D FlipBook – Unauthenticated Sensitive Information Exposure in ‘id’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Sensitive Information Exposure in 'id' Parameter
CVE: CVE-2026-15758
Number of Installations: 70,000+
Affected Software: 3D FlipBook ≤ 1.16.20
Patched Versions: 1.16.21

Mitigation steps: Update to 3D FlipBook version 1.16.21 or greater.


LearnPress – Unauthenticated Information Exposure

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-86448
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.6
Patched Versions: 4.4.7

Mitigation steps: Update to LearnPress version 4.4.7 or greater.


Slim SEO – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-62113
Number of Installations: 70,000+
Affected Software: Slim SEO ≤ 4.10.0
Patched Versions: 4.10.1

Mitigation steps: Update to Slim SEO version 4.10.1 or greater.


LearnPress – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Missing Authorization
CVE: CVE-2026-82023
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.5
Patched Versions: 4.4.6

Mitigation steps: Update to LearnPress version 4.4.6 or greater.


Ultra Addons for Contact Form 7 – Unauthenticated Arbitrary File Upload via Signature Form Field

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary File Upload via Signature Form Field
CVE: CVE-2026-82901
Number of Installations: 60,000+
Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.50
Patched Versions: 3.5.51

Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.51 or greater.


Ultra Addons for Contact Form 7 – Unauthenticated Arbitrary File Upload

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary File Upload
CVE: CVE-2026-84750
Number of Installations: 60,000+
Affected Software: Ultra Addons for Contact Form 7 3.2.4 - 3.5.50
Patched Versions: 3.5.51

Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.51 or greater.


Online Scheduling and Appointment Booking System – Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via ‘order_id’ Parameter

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter
CVE: CVE-2026-93399
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


WP Ultimate Review – Authenticated (Subscriber+) Arbitrary Shortcode Execution via ‘xs_submit_review_data[xs_reviw_summery]’ Parameter

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter
CVE: CVE-2026-92235
Number of Installations: 60,000+
Affected Software: WP Ultimate Review ≤ 2.4.2
Patched Versions: 2.4.3

Mitigation steps: Update to WP Ultimate Review version 2.4.3 or greater.


Site Reviews – Unauthenticated PHP Object Injection

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-82925
Number of Installations: 60,000+
Affected Software: Site Reviews 7.2.2 - 8.2.2
Patched Versions: 8.3.0

Mitigation steps: Update to Site Reviews version 8.3.0 or greater.


Online Scheduling and Appointment Booking System – Authenticated (Bookly Administrator+) PHP Object Injection

Security Risk: Low
Exploitation Level: Requires Bookly Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Bookly Administrator+) PHP Object Injection
CVE: CVE-2026-86841
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System 23.2 - 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


WP Maps – Authenticated (Subscriber+) Local File Inclusion via ‘page’ Parameter

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter
CVE: CVE-2026-13456
Number of Installations: 60,000+
Affected Software: WP Maps ≤ 4.9.8
Patched Versions: 5.0.0

Mitigation steps: Update to WP Maps version 5.0.0 or greater.


Online Scheduling and Appointment Booking System – Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via ‘conversation_id’ Parameter

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter
CVE: CVE-2026-89063
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.1
Patched Versions: 28.2

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.2 or greater.


Comments – Unauthenticated SQL Injection

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-19704
Number of Installations: 60,000+
Affected Software: Comments < 7.6.66
Patched Versions: 7.6.66

Mitigation steps: Update to Comments version 7.6.66 or greater.


Site Reviews – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-94078
Number of Installations: 60,000+
Affected Software: Site Reviews ≤ 8.3.1
Patched Versions: 8.3.2

Mitigation steps: Update to Site Reviews version 8.3.2 or greater.


Ultra Addons for Contact Form 7 – Authenticated (Editor+) PHP Object Injection

Security Risk: Medium
Exploitation Level: Requires Editor or higher level authentication.
Vulnerability: Authenticated (Editor+) PHP Object Injection
CVE: CVE-2026-96833
Number of Installations: 60,000+
Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.51
Patched Versions: 3.5.52

Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.52 or greater.


WP Maps – Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter
CVE: CVE-2026-13179
Number of Installations: 60,000+
Affected Software: WP Maps ≤ 4.9.8
Patched Versions: 5.0.0

Mitigation steps: Update to WP Maps version 5.0.0 or greater.


Ultra Addons for Contact Form 7 – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-95586
Number of Installations: 60,000+
Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.50
Patched Versions: 3.5.51

Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.51 or greater.


Master Slider – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-14844
Number of Installations: 60,000+
Affected Software: Master Slider ≤ 3.11.2
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Brizy – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘rootAttributes’ Parameter

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter
CVE: CVE-2026-2585
Number of Installations: 60,000+
Affected Software: Brizy ≤ 2.8.14
Patched Versions: 2.8.15

Mitigation steps: Update to Brizy version 2.8.15 or greater.


Advanced Popups – Authenticated (Author+) Stored Cross-Site Scripting via ‘Notification Button Link’ Field

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field
CVE: CVE-2026-11996
Number of Installations: 60,000+
Affected Software: Advanced Popups ≤ 1.2.3
Patched Versions: 1.2.4

Mitigation steps: Update to Advanced Popups version 1.2.4 or greater.


Theme My Login – Authenticated (Subscriber+) Privilege Escalation

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Privilege Escalation
CVE: CVE-2026-81583
Number of Installations: 60,000+
Affected Software: Theme My Login 7.0 - 7.1.15
Patched Versions: 7.2.0

Mitigation steps: Update to Theme My Login version 7.2.0 or greater.


Online Scheduling and Appointment Booking System – Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update
CVE: CVE-2026-2520
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 27.2
Patched Versions: 27.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 27.3 or greater.


Events Manager – Unauthenticated Stored Cross-Site Scripting via Event Attributes

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Event Attributes
CVE: CVE-2025-14945
Number of Installations: 60,000+
Affected Software: Events Manager ≤ 7.3.3
Patched Versions: 7.3.4

Mitigation steps: Update to Events Manager version 7.3.4 or greater.


Online Scheduling and Appointment Booking System – Unauthenticated Payment Bypass

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Payment Bypass
CVE: CVE-2026-86838
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


Online Scheduling and Appointment Booking System – Unauthenticated Insecure Direct Object Reference

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-86837
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


Online Scheduling and Appointment Booking System – Unauthenticated Authorization Bypass via PHP Type Juggling via ‘verification_code’ Parameter Type Juggling via json_data

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data
CVE: CVE-2026-92799
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


Online Scheduling and Appointment Booking System – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-96348
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


Online Scheduling and Appointment Booking System – Unauthenticated Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-91847
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.1
Patched Versions: 28.2

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.2 or greater.


WP Maps – Authenticated (Administrator+) SQL Injection

Security Risk: Low
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) SQL Injection
CVE: CVE-2026-66618
Number of Installations: 60,000+
Affected Software: WP Maps ≤ 4.9.9
Patched Versions: 5.0.0

Mitigation steps: Update to WP Maps version 5.0.0 or greater.


Online Scheduling and Appointment Booking System – Authenticated (Staff+) Insecure Direct Object Reference

Security Risk: TBC
Exploitation Level: Requires Staff or higher level authentication.
Vulnerability: Authenticated (Staff+) Insecure Direct Object Reference
CVE: CVE-2026-86839
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


Online Scheduling and Appointment Booking System – Authenticated (Subscriber+) Insecure Direct Object Reference

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Insecure Direct Object Reference
CVE: CVE-2026-96347
Number of Installations: 60,000+
Affected Software: Online Scheduling and Appointment Booking System ≤ 28.2
Patched Versions: 28.3

Mitigation steps: Update to Online Scheduling and Appointment Booking System version 28.3 or greater.


Events Manager – Authenticated (Subscriber+) Information Exposure

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-93662
Number of Installations: 60,000+
Affected Software: Events Manager 7.4.1 - 7.4.4
Patched Versions: 7.4.5

Mitigation steps: Update to Events Manager version 7.4.5 or greater.


Events Manager – Authenticated (Contributor+) Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Insecure Direct Object Reference
CVE: CVE-2026-93661
Number of Installations: 60,000+
Affected Software: Events Manager ≤ 7.4.4
Patched Versions: 7.4.5

Mitigation steps: Update to Events Manager version 7.4.5 or greater.


Theme My Login – Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via ‘gimmeanotherblog’ Signup Stage

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage
CVE: CVE-2026-83628
Number of Installations: 60,000+
Affected Software: Theme My Login ≤ 7.1.15
Patched Versions: 7.2.0

Mitigation steps: Update to Theme My Login version 7.2.0 or greater.


WP Recipe Maker – Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content
CVE: CVE-2026-89274
Number of Installations: 50,000+
Affected Software: WP Recipe Maker ≤ 10.8.1
Patched Versions: 10.8.2

Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.


Simply Schedule Appointments – Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via ‘recursive’ Parameter on the appointment_types REST Endpoint via Public Nonce

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce
CVE: CVE-2026-92245
Number of Installations: 50,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.32
Patched Versions: 1.6.12.33

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.


Simply Schedule Appointments – Authenticated (Subscriber+) Local File Inclusion via ‘ssa_locale’ Parameter

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
CVE: CVE-2026-89294
Number of Installations: 50,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.27
Patched Versions: 1.6.12.33

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.


WP Store Locator – Unauthenticated Denial of Service

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Denial of Service
CVE: CVE-2026-94681
Number of Installations: 50,000+
Affected Software: WP Store Locator < 3.0.0
Patched Versions: 3.0.0

Mitigation steps: Update to WP Store Locator version 3.0.0 or greater.


Product Filter for WooCommerce by WBW – Unauthenticated SQL Injection

Security Risk: Critical
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-95601
Number of Installations: 50,000+
Affected Software: Product Filter for WooCommerce by WBW ≤ 3.1.7
Patched Versions: 3.1.8

Mitigation steps: Update to Product Filter for WooCommerce by WBW version 3.1.8 or greater.


RTMKit – Authenticated (Contributor+) PHP Object Injection

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) PHP Object Injection
CVE: CVE-2026-84752
Number of Installations: 50,000+
Affected Software: RTMKit ≤ 2.1.5
Patched Versions: 2.1.6

Mitigation steps: Update to RTMKit version 2.1.6 or greater.


User Registration & Membership – Unauthenticated Open Redirect

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Open Redirect
CVE: CVE-2026-80072
Number of Installations: 50,000+
Affected Software: User Registration & Membership < 5.2.8
Patched Versions: 5.2.8

Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.


RTMKit – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-84763
Number of Installations: 50,000+
Affected Software: RTMKit ≤ 2.1.5
Patched Versions: 2.1.6

Mitigation steps: Update to RTMKit version 2.1.6 or greater.


WP Table Builder – Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via ‘ids’ Parameter

Security Risk: High
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter
CVE: CVE-2026-6922
Number of Installations: 50,000+
Affected Software: WP Table Builder ≤ 2.2.1
Patched Versions: 2.2.2

Mitigation steps: Update to WP Table Builder version 2.2.2 or greater.


Simply Schedule Appointments – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via ‘complete_group’ Parameter

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter
CVE: CVE-2026-91109
Number of Installations: 50,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.31
Patched Versions: 1.6.12.33

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.


WP Recipe Maker – Unauthenticated Arbitrary Shortcode Execution

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2026-86601
Number of Installations: 50,000+
Affected Software: WP Recipe Maker ≤ 10.8.1
Patched Versions: 10.8.2

Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.


Email Subscribers & Newsletters – Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field
CVE: CVE-2026-12757
Number of Installations: 50,000+
Affected Software: Email Subscribers & Newsletters ≤ 5.9.27
Patched Versions: 5.9.28

Mitigation steps: Update to Email Subscribers & Newsletters version 5.9.28 or greater.


Contextual Related Posts – Authenticated (Author+) Stored Cross-Site Scripting via ‘other_attributes’ Block Parameter

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter
CVE: CVE-2026-85653
Number of Installations: 50,000+
Affected Software: Contextual Related Posts ≤ 4.4.1
Patched Versions: 4.4.2

Mitigation steps: Update to Contextual Related Posts version 4.4.2 or greater.


Gum Addon for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘pop_tag’ Widget Setting

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting
CVE: CVE-2026-8354
Number of Installations: 50,000+
Affected Software: Gum Addon for Elementor ≤ 1.3.15
Patched Versions: 1.3.16

Mitigation steps: Update to Gum Addon for Elementor version 1.3.16 or greater.


Getwid – Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps ‘customStyle’

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle'
CVE: CVE-2026-5924
Number of Installations: 50,000+
Affected Software: Getwid 2.1.3
Patched Versions: 2.2.0

Mitigation steps: Update to Getwid version 2.2.0 or greater.


User Registration & Membership – Authenticated (Author+) Privilege Escalation

Security Risk: Medium
Exploitation Level: Requires Author or higher level authentication.
Vulnerability: Authenticated (Author+) Privilege Escalation
CVE: CVE-2026-80071
Number of Installations: 50,000+
Affected Software: User Registration & Membership < 5.2.8
Patched Versions: 5.2.8

Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.


User Registration & Membership – Authenticated (Subscriber+) Privilege Escalation

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Privilege Escalation
CVE: CVE-2026-86406
Number of Installations: 50,000+
Affected Software: User Registration & Membership 4.4.6 - 5.2.7
Patched Versions: 5.2.8

Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.


WP-Members Membership Plugin – Reflected Cross-Site Scripting

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-84960
Number of Installations: 50,000+
Affected Software: WP-Members Membership Plugin ≤ 3.5.6
Patched Versions: 3.5.7

Mitigation steps: Update to WP-Members Membership Plugin version 3.5.7 or greater.


Product Filter for WooCommerce by WBW – Reflected Cross-Site Scripting via ‘wpf_fid’ Parameter

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Reflected Cross-Site Scripting via 'wpf_fid' Parameter
CVE: CVE-2026-7804
Number of Installations: 50,000+
Affected Software: Product Filter for WooCommerce by WBW ≤ 3.4.2
Patched Versions: 3.4.3

Mitigation steps: Update to Product Filter for WooCommerce by WBW version 3.4.3 or greater.


WP Recipe Maker – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘notes’ Parameter via REST Preview Endpoint

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint
CVE: CVE-2026-90884
Number of Installations: 50,000+
Affected Software: WP Recipe Maker ≤ 10.8.1
Patched Versions: 10.8.2

Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.


Simply Schedule Appointments – Unauthenticated Insecure Direct Object Reference

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-94673
Number of Installations: 50,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.31
Patched Versions: 1.6.12.33

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.33 or greater.


Simply Schedule Appointments – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-94074
Number of Installations: 50,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.29
Patched Versions: 1.6.12.31

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.31 or greater.


Email Subscribers & Newsletters – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-83555
Number of Installations: 50,000+
Affected Software: Email Subscribers & Newsletters ≤ 5.9.34
Patched Versions: 5.9.35

Mitigation steps: Update to Email Subscribers & Newsletters version 5.9.35 or greater.


WP Recipe Maker – Unauthenticated Arbitrary User Meta Corruption

Security Risk: TBC
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Arbitrary User Meta Corruption
CVE: CVE-2026-86608
Number of Installations: 50,000+
Affected Software: WP Recipe Maker 9.8.0 - 10.8.1
Patched Versions: 10.8.2

Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.


User Registration & Membership – Missing Authorization

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Missing Authorization
CVE: CVE-2026-74017
Number of Installations: 50,000+
Affected Software: User Registration & Membership ≤ 5.2.7
Patched Versions: 5.2.8

Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.


User Registration & Membership – Unauthenticated Information Exposure

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-86407
Number of Installations: 50,000+
Affected Software: User Registration & Membership 5.0 - 5.2.7
Patched Versions: 5.2.8

Mitigation steps: Update to User Registration & Membership version 5.2.8 or greater.


المنتور فارسی – Payment Bypass to Unauthenticated Unauthorized Order Completion

Security Risk: Medium
Exploitation Level: No authentication required.
Vulnerability: Payment Bypass to Unauthenticated Unauthorized Order Completion
CVE: CVE-2026-86809
Number of Installations: 50,000+
Affected Software: المنتور فارسی 2.7.10 - 2.8.1
Patched Versions: 2.8.2

Mitigation steps: Update to المنتور فارسی version 2.8.2 or greater.


Email Subscribers & Newsletters – Authenticated (Administrator+) Stored Cross-Site Scripting

Security Risk: Minimal
Exploitation Level: Requires Administratoristrator or higher level authentication.
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting
CVE: CVE-2025-15692
Number of Installations: 50,000+
Affected Software: Email Subscribers & Newsletters ≤ 5.8.5
Patched Versions: 5.8.6

Mitigation steps: Update to Email Subscribers & Newsletters version 5.8.6 or greater.


Blog2Social: Social Media Auto Post & Scheduler – Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers
CVE: CVE-2026-92829
Number of Installations: 50,000+
Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.1.0
Patched Versions: 9.1.1

Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.1 or greater.


WP Recipe Maker – Authenticated (Subscriber+) Information Exposure

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-86603
Number of Installations: 50,000+
Affected Software: WP Recipe Maker ≤ 10.8.1
Patched Versions: 10.8.2

Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.


WP Recipe Maker – Authenticated (Subscriber+) Information Exposure

Security Risk: TBC
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Information Exposure
CVE: CVE-2026-86602
Number of Installations: 50,000+
Affected Software: WP Recipe Maker 10.3.0 - 10.8.1
Patched Versions: 10.8.2

Mitigation steps: Update to WP Recipe Maker version 10.8.2 or greater.


Blog2Social: Social Media Auto Post & Scheduler – Insecure Direct Object Reference

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Insecure Direct Object Reference
CVE: CVE-2026-89031
Number of Installations: 50,000+
Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.0.0
Patched Versions: 9.1.0

Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.0 or greater.


Blog2Social: Social Media Auto Post & Scheduler – Authenticated (Subscriber+) Username Enumeration

Security Risk: Medium
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Username Enumeration
CVE: CVE-2026-89029
Number of Installations: 50,000+
Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.0.0
Patched Versions: 9.1.0

Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.0 or greater.


Blog2Social: Social Media Auto Post & Scheduler – Missing Authorization

Security Risk: Medium
Exploitation Level: Requires custom role.
Vulnerability: Missing Authorization
CVE: CVE-2026-89030
Number of Installations: 50,000+
Affected Software: Blog2Social: Social Media Auto Post & Scheduler ≤ 9.0.0
Patched Versions: 9.1.0

Mitigation steps: Update to Blog2Social: Social Media Auto Post & Scheduler version 9.1.0 or greater.


Seraphinite Accelerator – Authenticated (Subscriber+) Full Admin Area Denial of Service

Security Risk: Low
Exploitation Level: Requires Subscriber or higher level authentication.
Vulnerability: Authenticated (Subscriber+) Full Admin Area Denial of Service
CVE: CVE-2026-87828
Number of Installations: 50,000+
Affected Software: Seraphinite Accelerator ≤ 2.29.23
Patched Versions: 2.29.24

Mitigation steps: Update to Seraphinite Accelerator version 2.29.24 or greater.


WP Recipe Maker – Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via ‘[wprm-recipe]’ Shortcode

Security Risk: Medium
Exploitation Level: Requires Contributor or higher level authentication.
Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via '[wprm-recipe]' Shortcode
CVE: CVE-2026-75905
Number of Installations: 50,000+
Affected Software: WP Recipe Maker ≤ 10.8.0
Patched Versions: 10.8.1

Mitigation steps: Update to WP Recipe Maker version 10.8.1 or greater.


Themes


Astra – Authenticated (Shop Manager+) Arbitrary CSS Injection

Security Risk: High
Exploitation Level: Requires Shop Manager or higher level authentication.
Vulnerability: Authenticated (Shop Manager+) Arbitrary CSS Injection
CVE: CVE-2026-27085
Number of Installations: 1,000,000+
Affected Software: Astra ≤ 4.13.12
Patched Versions: 4.14.0

Mitigation steps: Update to Astra version 4.14.0 or greater.


Update your website software to reduce risk. Users unable to upgrade to the latest version are advised to implement a web application firewall, which can virtually patch known vulnerabilities and safeguard their website.

Chat with Sucuri


文章来源: https://blog.sucuri.net/2026/09/vulnerability-patch-roundup-september-2026.html
如有侵权请联系:admin#unsafe.sh