Vulnerability & Patch Roundup — July 2026

Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already.

To keep you protected from these threats, we’ve compiled this month’s key security updates and vulnerability patches for the WordPress ecosystem.

If you’re already using the Sucuri Firewall, you’re protected. These vulnerabilities are virtually patched for all clients. If not, consider putting a web application firewall in front of your site to block attacks before they reach your environment.


Plugins


Yoast SEO – Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)

Security Risk: Medium
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)
CVE: CVE-2026-15425
Number of Installations: 10,000,000+
Affected Software: Yoast SEO ≤ 28.0
Patched Versions: 28.1

Mitigation steps: Update to Yoast SEO version 28.1 or greater.


WPForms – Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content
CVE: CVE-2026-15782
Number of Installations: 5,000,000+
Affected Software: WPForms ≤ 2.0.0.1
Patched Versions: 2.0.0.2

Mitigation steps: Update to WPForms version 2.0.0.2 or greater.


Essential Addons for Elementor – Authenticated (Contributor+) Account Takeover via Email Header Injection

Security Risk: High
Vulnerability: Authenticated (Contributor+) Account Takeover via Email Header Injection
CVE: CVE-2026-15155
Number of Installations: 2,000,000+
Affected Software: Essential Addons for Elementor ≤ 6.6.10
Patched Versions: 6.6.11

Mitigation steps: Update to Essential Addons for Elementor version 6.6.11 or greater.


Ultimate Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes
CVE: CVE-2026-15787
Number of Installations: 2,000,000+
Affected Software: Ultimate Addons for Elementor ≤ 2.9.1
Patched Versions: 2.9.2

Mitigation steps: Update to Ultimate Addons for Elementor version 2.9.2 or greater.


Essential Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
CVE: CVE-2026-15145
Number of Installations: 2,000,000+
Affected Software: Essential Addons for Elementor ≤ 6.6.11
Patched Versions: 6.7.0

Mitigation steps: Update to Essential Addons for Elementor version 6.7.0 or greater.


Essential Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings
CVE: CVE-2026-15156
Number of Installations: 2,000,000+
Affected Software: Essential Addons for Elementor ≤ 6.6.11
Patched Versions: 6.7.0

Mitigation steps: Update to Essential Addons for Elementor version 6.7.0 or greater.


Essential Addons for Elementor – Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup

Security Risk: Medium
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup
CVE: CVE-2026-6459
Number of Installations: 2,000,000+
Affected Software: Essential Addons for Elementor ≤ 6.6.2
Patched Versions: 6.6.3

Mitigation steps: Update to Essential Addons for Elementor version 6.6.3 or greater.


Loco Translate – Cross-Site Request Forgery to Remote Code Execution via ‘template’ Parameter

Security Risk: High
Vulnerability: Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter
CVE: CVE-2026-15005
Number of Installations: 1,000,000+
Affected Software: Loco Translate ≤ 2.8.5
Patched Versions: 2.8.6

Mitigation steps: Update to Loco Translate version 2.8.6 or greater.


Image Optimizer – Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection

Security Risk: High
Vulnerability: Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection
CVE: CVE-2026-5821
Number of Installations: 1,000,000+
Affected Software: Image Optimizer ≤ 1.7.4
Patched Versions: 1.7.5

Mitigation steps: Update to Image Optimizer version 1.7.5 or greater.


Complianz – Authenticated (Administrator+) PHP Object Injection

Security Risk: Low
Vulnerability: Authenticated (Administrator+) PHP Object Injection
CVE: CVE-2026-65497
Number of Installations: 1,000,000+
Affected Software: Complianz ≤ 7.5.1
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Complianz – Authenticated (Author+) Server-Side Request Forgery

Security Risk: Low
Vulnerability: Authenticated (Author+) Server-Side Request Forgery
CVE: CVE-2026-65496
Number of Installations: 1,000,000+
Affected Software: Complianz ≤ 7.5.1
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Spectra Legacy – Gutenberg Blocks – Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block
CVE: CVE-2026-12900
Number of Installations: 1,000,000+
Affected Software: Spectra Legacy – Gutenberg Blocks ≤ 2.19.28
Patched Versions: 2.19.29

Mitigation steps: Update to Spectra Legacy – Gutenberg Blocks version 2.19.29 or greater.


Complianz – Unauthenticated Information Exposure

Security Risk: High
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-65498
Number of Installations: 1,000,000+
Affected Software: Complianz ≤ 7.5.1
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Smash Balloon Social Photo Feed – Cross-Site Request Forgery to oEmbed Access Token Overwrite via ‘sbi_access_token’ Parameter

Security Risk: Low
Vulnerability: Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter
CVE: CVE-2026-12002
Number of Installations: 1,000,000+
Affected Software: Smash Balloon Social Photo Feed ≤ 6.11.1
Patched Versions: 6.11.2

Mitigation steps: Update to Smash Balloon Social Photo Feed version 6.11.2 or greater.


W3 Total Cache – Unauthenticated Arbitrary File Read via ‘f_array[]’ Parameter

Security Risk: High
Vulnerability: Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
CVE: CVE-2026-9282
Number of Installations: 900,000+
Affected Software: W3 Total Cache ≤ 2.9.4
Patched Versions: 2.10.0

Mitigation steps: Update to W3 Total Cache version 2.10.0 or greater.


WPvivid – Authenticated (Administrator+) SQL Injection via ‘export_data’ Parameter

Security Risk: Low
Vulnerability: Authenticated (Administrator+) SQL Injection via 'export_data' Parameter
CVE: CVE-2026-17555
Number of Installations: 900,000+
Affected Software: WPvivid ≤ 0.9.131
Patched Versions: 0.9.132

Mitigation steps: Update to WPvivid version 0.9.132 or greater.


Widgets for Google Reviews – Authenticated (Editor+) Stored Cross-Site Scripting via ‘fomo-title’ and ‘fomo-text’ Parameters

Security Risk: Medium
Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
CVE: CVE-2026-11591
Number of Installations: 900,000+
Affected Software: Widgets for Google Reviews ≤ 13.3
Patched Versions: 13.3.1

Mitigation steps: Update to Widgets for Google Reviews version 13.3.1 or greater.


WooCommerce PayPal Payments – Unauthenticated Sensitive Information Disclosure

Security Risk: High
Vulnerability: Unauthenticated Sensitive Information Disclosure
CVE: CVE-2025-14073
Number of Installations: 800,000+
Affected Software: WooCommerce PayPal Payments ≤ 3.3.2
Patched Versions: 3.4.0

Mitigation steps: Update to WooCommerce PayPal Payments version 3.4.0 or greater.


Polylang – Authenticated (Contributor+) Sensitive Information Exposure

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Sensitive Information Exposure
CVE: CVE-2026-65458
Number of Installations: 800,000+
Affected Software: Polylang ≤ 3.8.5
Patched Versions: 3.8.6

Mitigation steps: Update to Polylang version 3.8.6 or greater.


Smart Slider 3 – Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via ‘keyword’ Parameter

Security Risk: Medium
Vulnerability: Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
CVE: CVE-2026-12385
Number of Installations: 800,000+
Affected Software: Smart Slider 3 ≤ 3.5.1.37
Patched Versions: 3.5.1.38

Mitigation steps: Update to Smart Slider 3 version 3.5.1.38 or greater.


Fluent Forms – Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member
CVE: CVE-2026-16655
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.7
Patched Versions: 6.2.8

Mitigation steps: Update to Fluent Forms version 6.2.8 or greater.


GTM4WP – Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields
CVE: CVE-2026-16597
Number of Installations: 700,000+
Affected Software: GTM4WP ≤ 1.22.3
Patched Versions: 1.22.4

Mitigation steps: Update to GTM4WP version 1.22.4 or greater.


Popup Maker – Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation

Security Risk: High
Vulnerability: Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
CVE: CVE-2026-8848
Number of Installations: 700,000+
Affected Software: Popup Maker ≤ 1.22.0
Patched Versions: 1.23.0

Mitigation steps: Update to Popup Maker version 1.23.0 or greater.


Website Builder by SeedProd – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘seedprodnestedmenuwidget’ Shortcode

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode
CVE: CVE-2025-14785
Number of Installations: 700,000+
Affected Software: Website Builder by SeedProd ≤ 6.20.2
Patched Versions: 6.20.3

Mitigation steps: Update to Website Builder by SeedProd version 6.20.3 or greater.


Fluent Forms – Reflected Cross-Site Scripting via ‘param’

Security Risk: Low
Vulnerability: Reflected Cross-Site Scripting via 'param'
CVE: CVE-2026-17571
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.8
Patched Versions: 6.2.9

Mitigation steps: Update to Fluent Forms version 6.2.9 or greater.


Fluent Forms – Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via ‘subscription_id’

Security Risk: Medium
Vulnerability: Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'
CVE: CVE-2026-5069
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.1
Patched Versions: 6.2.2

Mitigation steps: Update to Fluent Forms version 6.2.2 or greater.


Fluent Forms – Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in ‘transaction’ Parameter

Security Risk: High
Vulnerability: Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter
CVE: CVE-2026-17567
Number of Installations: 700,000+
Affected Software: Fluent Forms ≤ 6.2.8
Patched Versions: 6.2.9

Mitigation steps: Update to Fluent Forms version 6.2.9 or greater.


Premium Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘premium_tooltip_text’ Parameter

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter
CVE: CVE-2026-12141
Number of Installations: 700,000+
Affected Software: Premium Addons for Elementor ≤ 4.11.84
Patched Versions: 4.11.85

Mitigation steps: Update to Premium Addons for Elementor 4.11.85 or greater.


Forminator Forms – Unauthenticated Arbitrary File Download

Security Risk: High
Vulnerability: Unauthenticated Arbitrary File Download
CVE: CVE-2026-57815
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.55.0.2
Patched Versions: 1.55.1

Mitigation steps: Update to Forminator Forms version 1.55.1 or greater.


Forminator Forms – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-57814
Number of Installations: 600,000+
Affected Software: Forminator Forms ≤ 1.55.0.1
Patched Versions: 1.55.0.2

Mitigation steps: Update to Forminator Forms version 1.55.0.2 or greater.


Under Construction Page (Pro) – Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter

Security Risk: High
Vulnerability: Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
CVE: CVE-2026-11426
Number of Installations: 600,000+
Affected Software: Under Construction Page (Pro) ≤ 5.76
Patched Versions: 5.81

Mitigation steps: Update to Under Construction Page (Pro) version 5.81 or greater.


Kadence Blocks – Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content
CVE: CVE-2026-18062
Number of Installations: 600,000+
Affected Software: Kadence Blocks ≤ 3.7.8.1
Patched Versions: 3.7.8.2

Mitigation steps: Update to Kadence Blocks version 3.7.8.2 or greater.


Kadence Blocks – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘toggleIcon’ Block Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute
CVE: CVE-2026-18435
Number of Installations: 600,000+
Affected Software: Kadence Blocks ≤ 3.7.8
Patched Versions: 3.7.8.1

Mitigation steps: Update to Kadence Blocks version 3.7.8.1 or greater.


The Events Calendar – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-13390
Number of Installations: 600,000+
Affected Software: The Events Calendar ≤ 6.16.5.0
Patched Versions: 6.16.5.1

Mitigation steps: Update to The Events Calendar version 6.16.5.1 or greater.


SpeedyCache – Authenticated (Administrator+) Arbitrary File Read

Security Risk: Low
Vulnerability: Authenticated (Administrator+) Arbitrary File Read
CVE: CVE-2026-5114
Number of Installations: 600,000+
Affected Software: SpeedyCache ≤ 1.3.8
Patched Versions: 1.3.9

Mitigation steps: Update to SpeedyCache version 1.3.9 or greater.


Ninja Forms – Authenticated (Administrator+) SQL Injection via Import File ‘settings’ Key

Security Risk: Low
Vulnerability: Authenticated (Administrator+) SQL Injection via Import File 'settings' Key
CVE: CVE-2026-15663
Number of Installations: 600,000+
Affected Software: Ninja Forms ≤ 3.14.9
Patched Versions: 3.14.10

Mitigation steps: Update to Ninja Forms version 3.14.10 or greater.


Enable Media Replace – Authenticated (Editor+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting
CVE: CVE-2026-57722
Number of Installations: 600,000+
Affected Software: Enable Media Replace ≤ 4.2.1
Patched Versions: 4.2.2

Mitigation steps: Update to Enable Media Replace version 4.2.2 or greater.


Kirki – Unauthenticated PHP Object Injection

Security Risk: High
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-57724
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.12
Patched Versions: 6.0.13

Mitigation steps: Update to Kirki version 6.0.13 or greater.


Kirki – Unauthenticated SQL Injection

Security Risk: Critical
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-57726
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.12
Patched Versions: 6.0.13

Mitigation steps: Update to Kirki version 6.0.13 or greater.


BackWPup – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-65443
Number of Installations: 500,000+
Affected Software: BackWPup ≤ 5.7.4
Patched Versions: 5.7.5

Mitigation steps: Update to BackWPup version 5.7.5 or greater.


Kirki – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-57725
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.11
Patched Versions: 6.0.12

Mitigation steps: Update to Kirki – Freeform Page Builder, Website Builder & Customizer version 6.0.12 or greater.


SureForms – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘headingWrapper’ Block Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute
CVE: CVE-2026-7623
Number of Installations: 500,000+
Affected Software: SureForms Quiz ≤ 2.8.1
Patched Versions: 2.8.2

Mitigation steps: Update to SureForms version 2.8.2 or greater.


Kirki – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via ‘context’ Parameter

Security Risk: High
Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
CVE: CVE-2026-13464
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.14
Patched Versions: 6.1.0

Mitigation steps: Update to Kirki version 6.1.0 or greater.


Kirki – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-57727
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.13
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Kirki – Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action

Security Risk: Medium
Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action
CVE: CVE-2026-12122
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.11
Patched Versions: 6.0.12

Mitigation steps: Update to Kirki version 6.0.12 or greater.


Kirki – Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via ’emailBody’ and ’emailSubject’ Parameters

Security Risk: Medium
Vulnerability: Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters
CVE: CVE-2026-12472
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.11
Patched Versions: 6.0.12

Mitigation steps: Update to Kirki version 6.0.12 or greater.


Kirki – Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)

Security Risk: High
Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)
CVE: CVE-2026-15601
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.13
Patched Versions: 6.1.0

Mitigation steps: Update to Kirki version 6.1.0 or greater.


Kirki – Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via ‘family’ Parameter

Security Risk: Medium
Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
CVE: CVE-2026-15457
Number of Installations: 500,000+
Affected Software: Kirki ≤ 6.0.13
Patched Versions: 6.0.14

Mitigation steps: Update to Kirki version 6.0.14 or greater.


MailPoet – Cross-Site Request Forgery

Security Risk: Low
Vulnerability: Cross-Site Request Forgery
CVE: CVE-2026-57626
Number of Installations: 500,000+
Affected Software: MailPoet 5.30.0 - 5.33.0
Patched Versions: 5.33.1

Mitigation steps: Update to MailPoet version 5.33.1 or greater.


Blocksy Companion – Unauthenticated Arbitrary File Upload via ‘blc-review-images[]’ Parameter

Security Risk: High
Vulnerability: Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
CVE: Not provided
Number of Installations: 300,000+
Affected Software: Blocksy Companion ≤ 2.1.46
Patched Versions: 2.1.47

Mitigation steps: Update to Blocksy Companion version 2.1.47 or greater.


Unlimited Elements For Elementor – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-57718
Number of Installations: 300,000+
Affected Software: Unlimited Elements For Elementor ≤ 2.0.12
Patched Versions: 2.0.13

Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.13 or greater.


Jeg Kit for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘sg_body_description’ Parameter via ‘jkit_image_box’ Shortcode/Widget

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget
CVE: CVE-2026-13710
Number of Installations: 300,000+
Affected Software: Jeg Kit for Elementor ≤ 3.2.6
Patched Versions: 3.2.7

Mitigation steps: Update to Jeg Kit for Elementor version 3.2.7 or greater.


Ad Inserter – Authenticated (Subscriber+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE: CVE-2026-57693
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.11
Patched Versions: 2.8.12

Mitigation steps: Update to Ad Inserter version 2.8.12 or greater.


WP Go Maps – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-25466
Number of Installations: 300,000+
Affected Software: WP Go Maps ≤ 10.1.05
Patched Versions: 10.1.06

Mitigation steps: Update to WP Go Maps version 10.1.06 or greater.


Members – Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel

Security Risk: Medium
Vulnerability: Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
CVE: CVE-2026-12426
Number of Installations: 300,000+
Affected Software: Members ≤ 3.2.22
Patched Versions: 3.2.23

Mitigation steps: Update to Members 3.2.23 or greater.


Jeg Kit for Elementor – Authenticated (Contributor+) Exposure of Sensitive Information via ‘JkitDashboardOption’ Inline Script

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script
CVE: CVE-2026-2916
Number of Installations: 300,000+
Affected Software: Jeg Kit for Elementor ≤ 3.1.1
Patched Versions: 3.1.2

Mitigation steps: Update to Jeg Kit for Elementor version 3.1.2 or greater.


WP Activity Log – Cross-Site Request Forgery

Security Risk: Low
Vulnerability: Cross-Site Request Forgery
CVE: CVE-2026-65512
Number of Installations: 300,000+
Affected Software: WP Activity Log ≤ 5.6.4
Patched Versions: 5.6.5

Mitigation steps: Update to WP Activity Log version 5.6.5 or greater.


PDF Invoices & Packing Slips for WooCommerce – Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via ‘order_id’ Shortcode Attribute

Security Risk: Medium
Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute
CVE: CVE-2026-13116
Number of Installations: 300,000+
Affected Software: PDF Invoices & Packing Slips for WooCommerce ≤ 5.14.0
Patched Versions: 5.15.0

Mitigation steps: Update to PDF Invoices & Packing Slips for WooCommerce version 5.15.0 or greater.


Ad Inserter – Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via ‘data’ Shortcode Attribute

Security Risk: Medium
Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
CVE: CVE-2026-11900
Number of Installations: 300,000+
Affected Software: Ad Inserter ≤ 2.8.16
Patched Versions: 2.8.17

Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.


CleanTalk Anti-Spam. Spam Firewall & Bot protection – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-65437
Number of Installations: 200,000+
Affected Software: CleanTalk Anti-Spam. Spam Firewall & Bot protection ≤ 6.82
Patched Versions: 6.83

Mitigation steps: Update to CleanTalk Anti-Spam. Spam Firewall & Bot protection version 6.83 or greater.


GenerateBlocks – Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes
CVE: CVE-2026-13458
Number of Installations: 200,000+
Affected Software: GenerateBlocks ≤ 2.3.0
Patched Versions: 2.4.0

Mitigation steps: Update to GenerateBlocks version 2.4.0 or greater.


Firelight Lightbox – Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad ‘href’ Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute
CVE: CVE-2026-6454
Number of Installations: 200,000+
Affected Software: Firelight Lightbox ≤ 2.3.20
Patched Versions: 2.3.21

Mitigation steps: Update to Firelight Lightbox version 2.3.21 or greater.


Ultimate Member – Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field

Security Risk: Medium
Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field
CVE: CVE-2026-8489
Number of Installations: 200,000+
Affected Software: Ultimate Member ≤ 2.11.4
Patched Versions: 2.12.0

Mitigation steps: Update to Ultimate Member version 2.12.0 or greater.


GenerateBlocks – Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block ‘linkMetaFieldType’ Dynamic Link Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute
CVE: CVE-2026-9756
Number of Installations: 200,000+
Affected Software: GenerateBlocks ≤ 2.2.1
Patched Versions: 2.3.0

Mitigation steps: Update to GenerateBlocks version 2.3.0 or greater.


White Label CMS – Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings

Security Risk: Low
Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings
CVE: CVE-2026-11898
Number of Installations: 200,000+
Affected Software: White Label CMS ≤ 2.7.12
Patched Versions: 2.7.13

Mitigation steps: Update to White Label CMS version 2.7.13 or greater.


HubSpot All-In-One Marketing – Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script
CVE: CVE-2026-9656
Number of Installations: 200,000+
Affected Software: HubSpot All-In-One Marketing ≤ 11.3.62
Patched Versions: 11.3.64

Mitigation steps: Update to HubSpot All-In-One Marketing version 11.3.64 or greater.


HubSpot All-In-One Marketing – Authenticated (Contributor+) Information Exposure

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Information Exposure
CVE: CVE-2026-57736
Number of Installations: 200,000+
Affected Software: HubSpot All-In-One Marketing ≤ 11.3.56
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


ProfilePress – Unauthenticated Privilege Escalation

Security Risk: High
Vulnerability: Unauthenticated Privilege Escalation
CVE: CVE-2026-12497
Number of Installations: 100,000+
Affected Software: ProfilePress ≤ 4.16.17
Patched Versions: 4.16.18

Mitigation steps: Update to ProfilePress version 4.16.18 or greater.


AI Engine – Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match

Security Risk: Low
Vulnerability: Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match
CVE: CVE-2026-15988
Number of Installations: 100,000+
Affected Software: AI Engine ≤ 3.6.5
Patched Versions: 3.6.6

Mitigation steps: Update to AI Engine version 3.6.6 or greater.


ProfilePress – Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

Security Risk: High
Vulnerability: Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
CVE: CVE-2026-13352
Number of Installations: 100,000+
Affected Software: ProfilePress ≤ 4.16.18
Patched Versions: 4.16.19

Mitigation steps: Update to ProfilePress version 4.16.19 or greater.


TinyPNG – Authenticated (Author+) Arbitrary File Deletion via ‘convert.path’ in ‘tiny_compress_images’ Post Meta

Security Risk: High
Vulnerability: Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta
CVE: CVE-2026-7311
Number of Installations: 100,000+
Affected Software: TinyPNG ≤ 3.6.13
Patched Versions: 3.6.14

Mitigation steps: Update to TinyPNG version 3.6.14 or greater.


Appointment Booking Plugin – Unauthenticated SQL Injection

Security Risk: Critical
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-57714
Number of Installations: 100,000+
Affected Software: Appointment Booking Plugin ≤ 5.6.3
Patched Versions: 5.6.4

Mitigation steps: Update to Appointment Booking Plugin version 5.6.4 or greater.


LatePoint – Unauthenticated Stripe PaymentIntent Amount-Binding Bypass

Security Risk: High
Vulnerability: Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
CVE: CVE-2026-5356
Number of Installations: 100,000+
Affected Software: LatePoint ≤ 5.4.0
Patched Versions: 5.4.1

Mitigation steps: Update to LatePoint version 5.4.1 or greater.


GiveWP – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-65441
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.3
Patched Versions: 4.16.4

Mitigation steps: Update to GiveWP version 4.16.4 or greater.


Anti-Malware Security and Brute-Force Firewall – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-57691
Number of Installations: 100,000+
Affected Software: Anti-Malware Security and Brute-Force Firewall ≤ 4.23.89
Patched Versions: 4.23.90

Mitigation steps: Update to Anti-Malware Security and Brute-Force Firewall version 4.23.90 or greater.


Contact Form 7 – Unauthenticated Arbitrary Shortcode Execution

Security Risk: High
Vulnerability: Unauthenticated Arbitrary Shortcode Execution
CVE: CVE-2025-13146
Number of Installations: 100,000+
Affected Software: Contact Form 7 ≤ 5.0.3
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Tutor LMS – Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array

Security Risk: High
Vulnerability: Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array
CVE: CVE-2026-15022
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.0
Patched Versions: 4.0.1

Mitigation steps: Update to Tutor LMS version 4.0.1 or greater.


Download Manager – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘icon’ Shortcode Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute
CVE: CVE-2026-16685
Number of Installations: 100,000+
Affected Software: Download Manager ≤ 3.3.66
Patched Versions: 3.3.67

Mitigation steps: Update to Download Manager version 3.3.67 or greater.


Orbit Fox – Authenticated (Author+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting
CVE: CVE-2026-65563
Number of Installations: 100,000+
Affected Software: Orbit Fox ≤ 3.0.7
Patched Versions: 3.0.8

Mitigation steps: Update to Orbit Fox version 3.0.8 or greater.


Rich Showcase for Google Reviews – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘pagination’ Shortcode Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute
CVE: CVE-2026-15739
Number of Installations: 100,000+
Affected Software: Rich Showcase for Google Reviews ≤ 6.9.9
Patched Versions: 6.9.10

Mitigation steps: Update to Rich Showcase for Google Reviews version 6.9.10 or greater.


Modula Image Gallery – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-65475
Number of Installations: 100,000+
Affected Software: Modula Image Gallery 2.14.25 - 2.14.30
Patched Versions: 2.14.31

Mitigation steps: Update to Modula Image Gallery version 2.14.31 or greater.


GiveWP – Authenticated (Give Worker+) Stored Cross-Site Scripting via ‘twitter_message’ Sequoia Template Setting

Security Risk: Medium
Vulnerability: Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
CVE: CVE-2026-14987
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.3
Patched Versions: 4.16.4

Mitigation steps: Update to GiveWP version 4.16.4 or greater.


Download Manager – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘note_before’ and ‘note_after’ Shortcode Attributes

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes
CVE: CVE-2026-14343
Number of Installations: 100,000+
Affected Software: Download Manager ≤ 3.3.61
Patched Versions: 3.3.62

Mitigation steps: Update to Download Manager version 3.3.62 or greater.


Advanced Ads – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-10082
Number of Installations: 100,000+
Affected Software: Advanced Ads ≤ 2.0.22
Patched Versions: 2.0.23

Mitigation steps: Update to Advanced Ads version 2.0.23 or greater.


GiveWP – Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

Security Risk: Medium
Vulnerability: Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
CVE: CVE-2026-13704
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.1
Patched Versions: 4.16.2

Mitigation steps: Update to GiveWP version 4.16.2 or greater.


Payment Plugins for Stripe WooCommerce – Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret

Security Risk: Medium
Vulnerability: Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret
CVE: CVE-2026-12654
Number of Installations: 100,000+
Affected Software: Payment Plugins for Stripe WooCommerce ≤ 4.0.7
Patched Versions: 4.0.8

Mitigation steps: Update to Payment Plugins for Stripe WooCommerce version 4.0.8 or greater.


Payment Plugins for Stripe WooCommerce – Missing Authorization

Security Risk: High
Vulnerability: Missing Authorization
CVE: CVE-2026-59530
Number of Installations: 100,000+
Affected Software: Payment Plugins for Stripe WooCommerce ≤ 4.0.7
Patched Versions: 4.0.8

Mitigation steps: Update to Payment Plugins for Stripe WooCommerce version 4.0.8 or greater.


LatePoint – Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step

Security Risk: Medium
Vulnerability: Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
CVE: CVE-2026-11398
Number of Installations: 100,000+
Affected Software: LatePoint ≤ 5.6.1
Patched Versions: 5.6.2

Mitigation steps: Update to LatePoint version 5.6.2 or greater.


LatePoint – Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via ‘service_id’ Parameter

Security Risk: Medium
Vulnerability: Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
CVE: CVE-2026-12657
Number of Installations: 100,000+
Affected Software: LatePoint ≤ 5.6.2
Patched Versions: 5.6.3

Mitigation steps: Update to LatePoint version 5.6.3 or greater.


Tutor LMS – Authenticated (Administrator+) SQL Injection via ‘coupon_code’ Parameter

Security Risk: Low
Vulnerability: Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
CVE: CVE-2026-15444
Number of Installations: 100,000+
Affected Software: Tutor LMS ≤ 4.0.1
Patched Versions: 4.0.2

Mitigation steps: Update to Tutor LMS 4.0.2 or greater.


WP Bulk Delete – Authenticated (Administrator+) SQL Injection via ‘delete_user_roles’ Parameter

Security Risk: Low
Vulnerability: Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter
CVE: CVE-2026-15727
Number of Installations: 100,000+
Affected Software: WP Bulk Delete ≤ 1.4.2
Patched Versions: 1.4.3

Mitigation steps: Update to WP Bulk Delete version 1.4.3 or greater.


GiveWP – Cross-Site Request Forgery

Security Risk: Low
Vulnerability: Cross-Site Request Forgery
CVE: CVE-2026-65464
Number of Installations: 100,000+
Affected Software: GiveWP ≤ 4.16.3
Patched Versions: 4.16.4

Mitigation steps: Update to GiveWP version 4.16.4 or greater.


Tutor LMS – Unauthenticated Insecure Direct Object Reference

Security Risk: High
Vulnerability: Unauthenticated Insecure Direct Object Reference
CVE: CVE-2026-57694
Number of Installations: 100,000+
Affected Software: Tutor LMS – eLearning and online course solution ≤ 3.9.13
Patched Versions: 3.9.14

Mitigation steps: Update to Tutor LMS – eLearning and online course solution version 3.9.14 or greater.


SureCart – Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook

Security Risk: High
Vulnerability: Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook
CVE: CVE-2026-7655
Number of Installations: 90,000+
Affected Software: SureCart ≤ 4.2.3
Patched Versions: 4.3.0

Mitigation steps: Update to SureCart version 4.3.0 or greater.


BuddyPress – Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data

Security Risk: High
Vulnerability: Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data
CVE: CVE-2026-1360
Number of Installations: 90,000+
Affected Software: BuddyPress ≤ 14.5.0
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Amelia – Unauthenticated SQL Injection

Security Risk: Critical
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-57702
Number of Installations: 90,000+
Affected Software: Amelia ≤ 2.4.2
Patched Versions: 2.4.3

Mitigation steps: Update to Amelia version 2.4.3 or greater.


Shortcodes and extra features for Phlox theme – Authenticated (Contributor+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting
CVE: CVE-2026-57737
Number of Installations: 90,000+
Affected Software: Shortcodes and extra features for Phlox theme ≤ 2.17.21
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Event Tickets and Registration – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-65567
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration ≤ 5.29.0.1
Patched Versions: 5.29.1

Mitigation steps: Update to Event Tickets and Registration version 5.29.1 or greater.


Event Tickets and Registration – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-57705
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration ≤ 5.28.5
Patched Versions: 5.28.5.1

Mitigation steps: Update to Event Tickets and Registration version 5.28.5.1 or greater.


JetFormBuilder – Missing Authorization to Unauthenticated Sensitive Information Disclosure via ‘context’ Parameter

Security Risk: Medium
Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
CVE: CVE-2026-13459
Number of Installations: 90,000+
Affected Software: JetFormBuilder ≤ 3.6.3
Patched Versions: 3.6.3.1

Mitigation steps: Update to JetFormBuilder version 3.6.3.1 or greater.


ShopLentor – Authenticated (Administrator+) SQL Injection via ‘orderby’ Parameter

Security Risk: Low
Vulnerability: Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVE: CVE-2026-16811
Number of Installations: 90,000+
Affected Software: ShopLentor ≤ 3.4.5
Patched Versions: 3.4.6

Mitigation steps: Update to ShopLentor version 3.4.6 or greater.


Amelia – Authenticated (Custom+) SQL Injection via Customer Import

Security Risk: Medium
Vulnerability: Authenticated (Custom+) SQL Injection via Customer Import
CVE: CVE-2026-14782
Number of Installations: 90,000+
Affected Software: Amelia ≤ 2.4.3
Patched Versions: 2.4.4

Mitigation steps: Update to Amelia version 2.4.4 or greater.


Event Tickets and Registration – Authenticated (Editor+) Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting
CVE: CVE-2026-14819
Number of Installations: 90,000+
Affected Software: Event Tickets and Registration ≤ 5.28.3
Patched Versions: 5.28.4

Mitigation steps: Update to Event Tickets and Registration version 5.28.4 or greater.


ShopLentor – Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via ‘optionSection’ Parameter

Security Risk: Medium
Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
CVE: CVE-2026-16797
Number of Installations: 90,000+
Affected Software: ShopLentor ≤ 3.4.5
Patched Versions: 3.4.6

Mitigation steps: Update to ShopLentor version 3.4.6 or greater.


Media Cleaner: Clean your WordPress! – Authenticated (Administrator+) Server-Side Request Forgery

Security Risk: Low
Vulnerability: Authenticated (Administrator+) Server-Side Request Forgery
CVE: CVE-2026-4912
Number of Installations: 90,000+
Affected Software: Media Cleaner: Clean your WordPress! ≤ 7.0.3
Patched Versions: 7.0.6

Mitigation steps: Update to Media Cleaner: Clean your WordPress! version 7.0.6 or greater.


AMP for WP – Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload

Security Risk: Medium
Vulnerability: Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload
CVE: CVE-2026-6101
Number of Installations: 80,000+
Affected Software: AMP for WP ≤ 1.1.12
Patched Versions: 1.1.13

Mitigation steps: Update to AMP for WP version 1.1.13 or greater.


GetGenie – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-65440
Number of Installations: 80,000+
Affected Software: GetGenie ≤ 4.4.3
Patched Versions: 4.5.0

Mitigation steps: Update to GetGenie version 4.5.0 or greater.


FluentCRM – Unauthenticated Stored Cross-Site Scripting

Security Risk: Medium
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-57715
Number of Installations: 80,000+
Affected Software: FluentCRM ≤ 3.1.7
Patched Versions: 3.1.8

Mitigation steps: Update to FluentCRM version 3.1.8 or greater.


Customer Reviews for WooCommerce – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘color’ Shortcode Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute
CVE: CVE-2026-13771
Number of Installations: 80,000+
Affected Software: Customer Reviews for WooCommerce ≤ 5.113.0
Patched Versions: 5.114.0

Mitigation steps: Update to Customer Reviews for WooCommerce version 5.114.0 or greater.


GutenKit – Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints

Security Risk: Medium
Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints
CVE: CVE-2026-15827
Number of Installations: 80,000+
Affected Software: GutenKit ≤ 2.4.12
Patched Versions: 2.4.13

Mitigation steps: Update to GutenKit version 2.4.13 or greater.


WP Ghost (Hide My WP Ghost) – Two-Factor Authentication Bypass

Security Risk: Medium
Vulnerability: Two-Factor Authentication Bypass
CVE: CVE-2026-59546
Number of Installations: 80,000+
Affected Software: WP Ghost (Hide My WP Ghost) ≤ 7.0.06
Patched Versions: 7.0.07

Mitigation steps: Update to WP Ghost (Hide My WP Ghost) version 7.0.07 or greater.


List category posts – Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via ‘post_status’ Shortcode Attribute

Security Risk: Medium
Vulnerability: Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute
CVE: CVE-2026-12434
Number of Installations: 80,000+
Affected Software: List category posts ≤ 0.95.0
Patched Versions: 0.96.0

Mitigation steps: Update to List category posts version 0.96.0 or greater.


Events Manager – Unauthenticated PHP Object Injection

Security Risk: High
Vulnerability: Unauthenticated PHP Object Injection
CVE: CVE-2026-57713
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.3.6
Patched Versions: 7.3.7

Mitigation steps: Update to Events Manager version 7.3.7 or greater.


LearnPress – Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

Security Risk: High
Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
CVE: CVE-2026-13765
Number of Installations: 70,000+
Affected Software: LearnPress ≤ 4.4.1
Patched Versions: 4.4.2

Mitigation steps: Update to LearnPress version 4.4.2 or greater.


Events Manager – Unauthenticated SQL Injection

Security Risk: Critical
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-12987
Number of Installations: 70,000+
Affected Software: Events Manager ≤ 7.3.6
Patched Versions: 7.3.7

Mitigation steps: Update to Events Manager version 7.3.7 or greater.


Comments – wpDiscuz – Unauthenticated Stored Cross-Site Scripting via ‘Website’ Field

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'Website' Field
CVE: CVE-2026-9148
Number of Installations: 70,000+
Affected Software: Comments – wpDiscuz ≤ 7.6.56
Patched Versions: 7.6.57

Mitigation steps: Update to Comments – wpDiscuz version 7.6.57 or greater.


Easy Accordion – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘align’ Block Attribute

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
CVE: CVE-2026-15652
Number of Installations: 70,000+
Affected Software: Easy Accordion ≤ 3.1.6
Patched Versions: 3.1.7

Mitigation steps: Update to Easy Accordion version 3.1.7 or greater.


Ninja Tables – Unauthenticated Information Exposure

Security Risk: TBC
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-65474
Number of Installations: 70,000+
Affected Software: Ninja Tables – Easy Data Table Builder ≤ 5.2.10
Patched Versions: 5.2.11

Mitigation steps: Update to Ninja Tables version 5.2.11 or greater.


Import and export users and customers – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action

Security Risk: Low
Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
CVE: CVE-2026-15026
Number of Installations: 70,000+
Affected Software: Import and export users and customers ≤ 2.4.0
Patched Versions: 2.4.1

Mitigation steps: Update to Import and export users and customers version 2.4.1 or greater.


Bookly – Unauthenticated SQL Injection

Security Risk: Critical
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-14516
Number of Installations: 60,000+
Affected Software: Bookly ≤ 27.5
Patched Versions: None

Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.


Bookly – Unauthenticated SQL Injection

Security Risk: Critical
Vulnerability: Unauthenticated SQL Injection
CVE: CVE-2026-61949
Number of Installations: 60,000+
Affected Software: Bookly ≤ 27.7
Patched Versions: 27.8

Mitigation steps: Update to Bookly version 27.8 or greater.


Advanced Shipment Tracking for WooCommerce – Authenticated (Shop Manager+) SQL Injection via ‘tracking_provider’ Parameter

Security Risk: Low
Vulnerability: Authenticated (Shop Manager+) SQL Injection via 'tracking_provider' Parameter
CVE: Not provided
Number of Installations: 60,000+
Affected Software: Advanced Shipment Tracking for WooCommerce ≤ 3.9
Patched Versions: 3.9.1

Mitigation steps: Update to Advanced Shipment Tracking for WooCommerce version 3.9.1 or greater.


Ultra Addons for Contact Form 7 – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-65439
Number of Installations: 60,000+
Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.45
Patched Versions: 3.5.46

Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.46 or greater.


Bookly – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-61944
Number of Installations: 60,000+
Affected Software: Bookly ≤ 27.7
Patched Versions: 27.8

Mitigation steps: Update to Bookly version 27.8 or greater.


Database for Contact Form 7, WPforms, Elementor forms – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-57708
Number of Installations: 60,000+
Affected Software: Database for Contact Form 7, WPforms, Elementor forms ≤ 1.5.2
Patched Versions: 1.5.3

Mitigation steps: Update to Database for Contact Form 7, WPforms, Elementor forms version 1.5.3 or greater.


Simply Schedule Appointments – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-13400
Number of Installations: 60,000+
Affected Software: Simply Schedule Appointments ≤ 1.6.12.3
Patched Versions: 1.6.12.4

Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.4 or greater.


Database for Contact Form 7, WPforms, Elementor forms – Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field ‘raw_value’

Security Risk: TBC
Vulnerability: Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'
CVE: CVE-2026-9145
Number of Installations: 60,000+
Affected Software: Database for Contact Form 7, WPforms, Elementor forms ≤ 1.5.1
Patched Versions: 1.5.2

Mitigation steps: Update to Database for Contact Form 7, WPforms, Elementor forms version 1.5.2 or greater.


Database for Contact Form 7, WPforms, Elementor forms – Reflected Cross-Site Scripting

Security Risk: TBC
Vulnerability: Reflected Cross-Site Scripting
CVE: CVE-2026-14870
Number of Installations: 60,000+
Affected Software: Database for Contact Form 7, WPforms, Elementor forms ≤ 1.5.2
Patched Versions: 1.5.3

Mitigation steps: Update to Database for Contact Form 7, WPforms, Elementor forms version 1.5.3 or greater.


Appointment Booking Calendar – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-57812
Number of Installations: 60,000+
Affected Software: Appointment Booking Calendar ≤ 1.6.12.4
Patched Versions: 1.6.12.6

Mitigation steps: Update to Appointment Booking Calendar version 1.6.12.6 or greater.


Appointment Booking Calendar – Missing Authorization

Security Risk: Medium
Vulnerability: Missing Authorization
CVE: CVE-2026-59523
Number of Installations: 60,000+
Affected Software: Appointment Booking Calendar ≤ 1.6.11.11
Patched Versions: 1.6.12.0

Mitigation steps: Update to Appointment Booking Calendar version 1.6.12.0 or greater.


Advanced Shipment Tracking for WooCommerce – Authenticated (Shop manager+) SQL Injection

Security Risk: Medium
Vulnerability: Authenticated (Shop manager+) SQL Injection
CVE: CVE-2026-57773
Number of Installations: 60,000+
Affected Software: Advanced Shipment Tracking for WooCommerce ≤ 4.0
Patched Versions: 4.0.1

Mitigation steps: Update to Advanced Shipment Tracking for WooCommerce version 4.0.1 or greater.


Email Subscribers & Newsletters – Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action

Security Risk: Medium
Vulnerability: Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action
CVE: CVE-2026-11592
Number of Installations: 60,000+
Affected Software: Email Subscribers & Newsletters ≤ 5.9.27
Patched Versions: 5.9.28

Mitigation steps: Update to Email Subscribers & Newsletters version 5.9.28 or greater.


Divi Torque Lite – Cross-Site Request Forgery to Arbitrary Plugin Installation via ‘install_plugin’ REST Endpoint

Security Risk: Low
Vulnerability: Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint
CVE: CVE-2026-4275
Number of Installations: 50,000+
Affected Software: Divi Torque Lite ≤ 4.2.3
Patched Versions: 4.3.0

Mitigation steps: Update to Divi Torque Lite version 4.3.0 or greater.


Booking Calendar – Unauthenticated Stored Cross-Site Scripting

Security Risk: High
Vulnerability: Unauthenticated Stored Cross-Site Scripting
CVE: CVE-2026-59558
Number of Installations: 50,000+
Affected Software: Booking Calendar ≤ 11.4.2
Patched Versions: 11.4.3

Mitigation steps: Update to Booking Calendar version 11.4.3 or greater.


Smart Custom Fields – Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

Security Risk: Medium
Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
CVE: CVE-2026-2594
Number of Installations: 50,000+
Affected Software: Smart Custom Fields ≤ 5.0.7
Patched Versions: 5.0.8

Mitigation steps: Update to Smart Custom Fields version 5.0.8 or greater.


Exclusive Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title
CVE: CVE-2026-11328
Number of Installations: 50,000+
Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.8
Patched Versions: 2.7.9.9

Mitigation steps: Update to Exclusive Addons for Elementor version 2.7.9.9 or greater.


RTMKit – Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget ‘Background Text’ Parameter

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter
CVE: CVE-2026-8351
Number of Installations: 50,000+
Affected Software: RTMKit ≤ 2.0.7
Patched Versions: 2.0.8

Mitigation steps: Update to RTMKit version 2.0.8 or greater.


Exclusive Addons for Elementor – Unauthenticated Information Exposure

Security Risk: Medium
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-66438
Number of Installations: 50,000+
Affected Software: Exclusive Addons for Elementor ≤ 2.8.0
Patched Versions: 2.8.1

Mitigation steps: Update to Exclusive Addons for Elementor version 2.8.1 or greater.


FormLayer – Unauthenticated Information Exposure

Security Risk: TBC
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-59519
Number of Installations: 50,000+
Affected Software: FormLayer ≤ 1.0.6
Patched Versions: 1.0.7

Mitigation steps: Update to FormLayer version 1.0.7 or greater.


Exclusive Addons for Elementor – Unauthenticated Information Exposure

Security Risk: TBC
Vulnerability: Unauthenticated Information Exposure
CVE: CVE-2026-59511
Number of Installations: 50,000+
Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.9
Patched Versions: 2.8.0

Mitigation steps: Update to Exclusive Addons for Elementor version 2.8.0 or greater.


WP Encryption – Authenticated (Administrator+) Arbitrary File Write via ‘imploded’ Parameter

Security Risk: Low
Vulnerability: Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter
CVE: CVE-2026-15786
Number of Installations: 50,000+
Affected Software: WP Encryption ≤ 7.8.6.6
Patched Versions: 7.8.6.7

Mitigation steps: Update to WP Encryption version 7.8.6.7 or greater.


Theme Editor – Cross-Site Request Forgery to CSS Modification

Security Risk: Low
Vulnerability: Cross-Site Request Forgery to CSS Modification
CVE: CVE-2025-14469
Number of Installations: 50,000+
Affected Software: Theme Editor ≤ 3.1
Patched Versions: 3.2

Mitigation steps: Update to Theme Editor version 3.2 or greater.


ZarinPal for WooCommerce – Cross-Site Request Forgery

Security Risk: Low
Vulnerability: Cross-Site Request Forgery
CVE: CVE-2026-65460
Number of Installations: 50,000+
Affected Software: ZarinPal for WooCommerce ≤ 5.1.0
Patched Versions: 5.1.1

Mitigation steps: Update to ZarinPal for WooCommerce version 5.1.1 or greater.


RTMKit – Authenticated (Contributor+) Limited Local File Inclusion via ‘template’ Parameter

Security Risk: Medium
Vulnerability: Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter
CVE: CVE-2026-5137
Number of Installations: 50,000+
Affected Software: RTMKit ≤ 2.0.7
Patched Versions: 2.0.8

Mitigation steps: Update to RTMKit version 2.0.8 or greater.


Update your website software to reduce risk. If you cannot update to the latest version, consider using a web application firewall to patch known vulnerabilities and safeguard your site.

Chat with Sucuri

You May Also Like