Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already.
To keep you protected from these threats, we’ve compiled this month’s key security updates and vulnerability patches for the WordPress ecosystem.
If you’re already using the Sucuri Firewall, you’re protected. These vulnerabilities are virtually patched for all clients. If not, consider putting a web application firewall in front of your site to block attacks before they reach your environment.
Security Risk: Medium Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name) CVE: CVE-2026-15425 Number of Installations: 10,000,000+ Affected Software: Yoast SEO ≤ 28.0 Patched Versions: 28.1
Mitigation steps: Update to Yoast SEO version 28.1 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content CVE: CVE-2026-15782 Number of Installations: 5,000,000+ Affected Software: WPForms ≤ 2.0.0.1 Patched Versions: 2.0.0.2
Mitigation steps: Update to WPForms version 2.0.0.2 or greater.
Security Risk: High Vulnerability: Authenticated (Contributor+) Account Takeover via Email Header Injection CVE: CVE-2026-15155 Number of Installations: 2,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.6.10 Patched Versions: 6.6.11
Mitigation steps: Update to Essential Addons for Elementor version 6.6.11 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes CVE: CVE-2026-15787 Number of Installations: 2,000,000+ Affected Software: Ultimate Addons for Elementor ≤ 2.9.1 Patched Versions: 2.9.2
Mitigation steps: Update to Ultimate Addons for Elementor version 2.9.2 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget CVE: CVE-2026-15145 Number of Installations: 2,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.6.11 Patched Versions: 6.7.0
Mitigation steps: Update to Essential Addons for Elementor version 6.7.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings CVE: CVE-2026-15156 Number of Installations: 2,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.6.11 Patched Versions: 6.7.0
Mitigation steps: Update to Essential Addons for Elementor version 6.7.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup CVE: CVE-2026-6459 Number of Installations: 2,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.6.2 Patched Versions: 6.6.3
Mitigation steps: Update to Essential Addons for Elementor version 6.6.3 or greater.
Security Risk: High Vulnerability: Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter CVE: CVE-2026-15005 Number of Installations: 1,000,000+ Affected Software: Loco Translate ≤ 2.8.5 Patched Versions: 2.8.6
Mitigation steps: Update to Loco Translate version 2.8.6 or greater.
Security Risk: High Vulnerability: Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection CVE: CVE-2026-5821 Number of Installations: 1,000,000+ Affected Software: Image Optimizer ≤ 1.7.4 Patched Versions: 1.7.5
Mitigation steps: Update to Image Optimizer version 1.7.5 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) PHP Object Injection CVE: CVE-2026-65497 Number of Installations: 1,000,000+ Affected Software: Complianz ≤ 7.5.1 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Low Vulnerability: Authenticated (Author+) Server-Side Request Forgery CVE: CVE-2026-65496 Number of Installations: 1,000,000+ Affected Software: Complianz ≤ 7.5.1 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block CVE: CVE-2026-12900 Number of Installations: 1,000,000+ Affected Software: Spectra Legacy – Gutenberg Blocks ≤ 2.19.28 Patched Versions: 2.19.29
Mitigation steps: Update to Spectra Legacy – Gutenberg Blocks version 2.19.29 or greater.
Security Risk: High Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-65498 Number of Installations: 1,000,000+ Affected Software: Complianz ≤ 7.5.1 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Low Vulnerability: Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter CVE: CVE-2026-12002 Number of Installations: 1,000,000+ Affected Software: Smash Balloon Social Photo Feed ≤ 6.11.1 Patched Versions: 6.11.2
Mitigation steps: Update to Smash Balloon Social Photo Feed version 6.11.2 or greater.
Security Risk: High Vulnerability: Unauthenticated Arbitrary File Read via 'f_array[]' Parameter CVE: CVE-2026-9282 Number of Installations: 900,000+ Affected Software: W3 Total Cache ≤ 2.9.4 Patched Versions: 2.10.0
Mitigation steps: Update to W3 Total Cache version 2.10.0 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) SQL Injection via 'export_data' Parameter CVE: CVE-2026-17555 Number of Installations: 900,000+ Affected Software: WPvivid ≤ 0.9.131 Patched Versions: 0.9.132
Mitigation steps: Update to WPvivid version 0.9.132 or greater.
Security Risk: Medium Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters CVE: CVE-2026-11591 Number of Installations: 900,000+ Affected Software: Widgets for Google Reviews ≤ 13.3 Patched Versions: 13.3.1
Mitigation steps: Update to Widgets for Google Reviews version 13.3.1 or greater.
Security Risk: High Vulnerability: Unauthenticated Sensitive Information Disclosure CVE: CVE-2025-14073 Number of Installations: 800,000+ Affected Software: WooCommerce PayPal Payments ≤ 3.3.2 Patched Versions: 3.4.0
Mitigation steps: Update to WooCommerce PayPal Payments version 3.4.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Sensitive Information Exposure CVE: CVE-2026-65458 Number of Installations: 800,000+ Affected Software: Polylang ≤ 3.8.5 Patched Versions: 3.8.6
Mitigation steps: Update to Polylang version 3.8.6 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter CVE: CVE-2026-12385 Number of Installations: 800,000+ Affected Software: Smart Slider 3 ≤ 3.5.1.37 Patched Versions: 3.5.1.38
Mitigation steps: Update to Smart Slider 3 version 3.5.1.38 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member CVE: CVE-2026-16655 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.7 Patched Versions: 6.2.8
Mitigation steps: Update to Fluent Forms version 6.2.8 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields CVE: CVE-2026-16597 Number of Installations: 700,000+ Affected Software: GTM4WP ≤ 1.22.3 Patched Versions: 1.22.4
Mitigation steps: Update to GTM4WP version 1.22.4 or greater.
Security Risk: High Vulnerability: Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation CVE: CVE-2026-8848 Number of Installations: 700,000+ Affected Software: Popup Maker ≤ 1.22.0 Patched Versions: 1.23.0
Mitigation steps: Update to Popup Maker version 1.23.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode CVE: CVE-2025-14785 Number of Installations: 700,000+ Affected Software: Website Builder by SeedProd ≤ 6.20.2 Patched Versions: 6.20.3
Mitigation steps: Update to Website Builder by SeedProd version 6.20.3 or greater.
Security Risk: Low Vulnerability: Reflected Cross-Site Scripting via 'param' CVE: CVE-2026-17571 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.8 Patched Versions: 6.2.9
Mitigation steps: Update to Fluent Forms version 6.2.9 or greater.
Security Risk: Medium Vulnerability: Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' CVE: CVE-2026-5069 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.1 Patched Versions: 6.2.2
Mitigation steps: Update to Fluent Forms version 6.2.2 or greater.
Security Risk: High Vulnerability: Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter CVE: CVE-2026-17567 Number of Installations: 700,000+ Affected Software: Fluent Forms ≤ 6.2.8 Patched Versions: 6.2.9
Mitigation steps: Update to Fluent Forms version 6.2.9 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter CVE: CVE-2026-12141 Number of Installations: 700,000+ Affected Software: Premium Addons for Elementor ≤ 4.11.84 Patched Versions: 4.11.85
Mitigation steps: Update to Premium Addons for Elementor 4.11.85 or greater.
Security Risk: High Vulnerability: Unauthenticated Arbitrary File Download CVE: CVE-2026-57815 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.55.0.2 Patched Versions: 1.55.1
Mitigation steps: Update to Forminator Forms version 1.55.1 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-57814 Number of Installations: 600,000+ Affected Software: Forminator Forms ≤ 1.55.0.1 Patched Versions: 1.55.0.2
Mitigation steps: Update to Forminator Forms version 1.55.0.2 or greater.
Security Risk: High Vulnerability: Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter CVE: CVE-2026-11426 Number of Installations: 600,000+ Affected Software: Under Construction Page (Pro) ≤ 5.76 Patched Versions: 5.81
Mitigation steps: Update to Under Construction Page (Pro) version 5.81 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content CVE: CVE-2026-18062 Number of Installations: 600,000+ Affected Software: Kadence Blocks ≤ 3.7.8.1 Patched Versions: 3.7.8.2
Mitigation steps: Update to Kadence Blocks version 3.7.8.2 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute CVE: CVE-2026-18435 Number of Installations: 600,000+ Affected Software: Kadence Blocks ≤ 3.7.8 Patched Versions: 3.7.8.1
Mitigation steps: Update to Kadence Blocks version 3.7.8.1 or greater.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-13390 Number of Installations: 600,000+ Affected Software: The Events Calendar ≤ 6.16.5.0 Patched Versions: 6.16.5.1
Mitigation steps: Update to The Events Calendar version 6.16.5.1 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) Arbitrary File Read CVE: CVE-2026-5114 Number of Installations: 600,000+ Affected Software: SpeedyCache ≤ 1.3.8 Patched Versions: 1.3.9
Mitigation steps: Update to SpeedyCache version 1.3.9 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) SQL Injection via Import File 'settings' Key CVE: CVE-2026-15663 Number of Installations: 600,000+ Affected Software: Ninja Forms ≤ 3.14.9 Patched Versions: 3.14.10
Mitigation steps: Update to Ninja Forms version 3.14.10 or greater.
Security Risk: Medium Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting CVE: CVE-2026-57722 Number of Installations: 600,000+ Affected Software: Enable Media Replace ≤ 4.2.1 Patched Versions: 4.2.2
Mitigation steps: Update to Enable Media Replace version 4.2.2 or greater.
Security Risk: High Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-57724 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.12 Patched Versions: 6.0.13
Mitigation steps: Update to Kirki version 6.0.13 or greater.
Security Risk: Critical Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-57726 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.12 Patched Versions: 6.0.13
Mitigation steps: Update to Kirki version 6.0.13 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-65443 Number of Installations: 500,000+ Affected Software: BackWPup ≤ 5.7.4 Patched Versions: 5.7.5
Mitigation steps: Update to BackWPup version 5.7.5 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-57725 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.11 Patched Versions: 6.0.12
Mitigation steps: Update to Kirki – Freeform Page Builder, Website Builder & Customizer version 6.0.12 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute CVE: CVE-2026-7623 Number of Installations: 500,000+ Affected Software: SureForms Quiz ≤ 2.8.1 Patched Versions: 2.8.2
Mitigation steps: Update to SureForms version 2.8.2 or greater.
Security Risk: High Vulnerability: Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter CVE: CVE-2026-13464 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.14 Patched Versions: 6.1.0
Mitigation steps: Update to Kirki version 6.1.0 or greater.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-57727 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.13 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Medium Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action CVE: CVE-2026-12122 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.11 Patched Versions: 6.0.12
Mitigation steps: Update to Kirki version 6.0.12 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters CVE: CVE-2026-12472 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.11 Patched Versions: 6.0.12
Mitigation steps: Update to Kirki version 6.0.12 or greater.
Security Risk: High Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip) CVE: CVE-2026-15601 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.13 Patched Versions: 6.1.0
Mitigation steps: Update to Kirki version 6.1.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter CVE: CVE-2026-15457 Number of Installations: 500,000+ Affected Software: Kirki ≤ 6.0.13 Patched Versions: 6.0.14
Mitigation steps: Update to Kirki version 6.0.14 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery CVE: CVE-2026-57626 Number of Installations: 500,000+ Affected Software: MailPoet 5.30.0 - 5.33.0 Patched Versions: 5.33.1
Mitigation steps: Update to MailPoet version 5.33.1 or greater.
Security Risk: High Vulnerability: Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter CVE: Not provided Number of Installations: 300,000+ Affected Software: Blocksy Companion ≤ 2.1.46 Patched Versions: 2.1.47
Mitigation steps: Update to Blocksy Companion version 2.1.47 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-57718 Number of Installations: 300,000+ Affected Software: Unlimited Elements For Elementor ≤ 2.0.12 Patched Versions: 2.0.13
Mitigation steps: Update to Unlimited Elements For Elementor version 2.0.13 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget CVE: CVE-2026-13710 Number of Installations: 300,000+ Affected Software: Jeg Kit for Elementor ≤ 3.2.6 Patched Versions: 3.2.7
Mitigation steps: Update to Jeg Kit for Elementor version 3.2.7 or greater.
Security Risk: Medium Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting CVE: CVE-2026-57693 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.11 Patched Versions: 2.8.12
Mitigation steps: Update to Ad Inserter version 2.8.12 or greater.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-25466 Number of Installations: 300,000+ Affected Software: WP Go Maps ≤ 10.1.05 Patched Versions: 10.1.06
Mitigation steps: Update to WP Go Maps version 10.1.06 or greater.
Security Risk: Medium Vulnerability: Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel CVE: CVE-2026-12426 Number of Installations: 300,000+ Affected Software: Members ≤ 3.2.22 Patched Versions: 3.2.23
Mitigation steps: Update to Members 3.2.23 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script CVE: CVE-2026-2916 Number of Installations: 300,000+ Affected Software: Jeg Kit for Elementor ≤ 3.1.1 Patched Versions: 3.1.2
Mitigation steps: Update to Jeg Kit for Elementor version 3.1.2 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery CVE: CVE-2026-65512 Number of Installations: 300,000+ Affected Software: WP Activity Log ≤ 5.6.4 Patched Versions: 5.6.5
Mitigation steps: Update to WP Activity Log version 5.6.5 or greater.
Security Risk: Medium Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute CVE: CVE-2026-13116 Number of Installations: 300,000+ Affected Software: PDF Invoices & Packing Slips for WooCommerce ≤ 5.14.0 Patched Versions: 5.15.0
Mitigation steps: Update to PDF Invoices & Packing Slips for WooCommerce version 5.15.0 or greater.
Security Risk: Medium Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute CVE: CVE-2026-11900 Number of Installations: 300,000+ Affected Software: Ad Inserter ≤ 2.8.16 Patched Versions: 2.8.17
Mitigation steps: Update to Ad Inserter version 2.8.17 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-65437 Number of Installations: 200,000+ Affected Software: CleanTalk Anti-Spam. Spam Firewall & Bot protection ≤ 6.82 Patched Versions: 6.83
Mitigation steps: Update to CleanTalk Anti-Spam. Spam Firewall & Bot protection version 6.83 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes CVE: CVE-2026-13458 Number of Installations: 200,000+ Affected Software: GenerateBlocks ≤ 2.3.0 Patched Versions: 2.4.0
Mitigation steps: Update to GenerateBlocks version 2.4.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute CVE: CVE-2026-6454 Number of Installations: 200,000+ Affected Software: Firelight Lightbox ≤ 2.3.20 Patched Versions: 2.3.21
Mitigation steps: Update to Firelight Lightbox version 2.3.21 or greater.
Security Risk: Medium Vulnerability: Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field CVE: CVE-2026-8489 Number of Installations: 200,000+ Affected Software: Ultimate Member ≤ 2.11.4 Patched Versions: 2.12.0
Mitigation steps: Update to Ultimate Member version 2.12.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute CVE: CVE-2026-9756 Number of Installations: 200,000+ Affected Software: GenerateBlocks ≤ 2.2.1 Patched Versions: 2.3.0
Mitigation steps: Update to GenerateBlocks version 2.3.0 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings CVE: CVE-2026-11898 Number of Installations: 200,000+ Affected Software: White Label CMS ≤ 2.7.12 Patched Versions: 2.7.13
Mitigation steps: Update to White Label CMS version 2.7.13 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script CVE: CVE-2026-9656 Number of Installations: 200,000+ Affected Software: HubSpot All-In-One Marketing ≤ 11.3.62 Patched Versions: 11.3.64
Mitigation steps: Update to HubSpot All-In-One Marketing version 11.3.64 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Information Exposure CVE: CVE-2026-57736 Number of Installations: 200,000+ Affected Software: HubSpot All-In-One Marketing ≤ 11.3.56 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: High Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-12497 Number of Installations: 100,000+ Affected Software: ProfilePress ≤ 4.16.17 Patched Versions: 4.16.18
Mitigation steps: Update to ProfilePress version 4.16.18 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match CVE: CVE-2026-15988 Number of Installations: 100,000+ Affected Software: AI Engine ≤ 3.6.5 Patched Versions: 3.6.6
Mitigation steps: Update to AI Engine version 3.6.6 or greater.
Security Risk: High Vulnerability: Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion CVE: CVE-2026-13352 Number of Installations: 100,000+ Affected Software: ProfilePress ≤ 4.16.18 Patched Versions: 4.16.19
Mitigation steps: Update to ProfilePress version 4.16.19 or greater.
Security Risk: High Vulnerability: Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta CVE: CVE-2026-7311 Number of Installations: 100,000+ Affected Software: TinyPNG ≤ 3.6.13 Patched Versions: 3.6.14
Mitigation steps: Update to TinyPNG version 3.6.14 or greater.
Security Risk: Critical Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-57714 Number of Installations: 100,000+ Affected Software: Appointment Booking Plugin ≤ 5.6.3 Patched Versions: 5.6.4
Mitigation steps: Update to Appointment Booking Plugin version 5.6.4 or greater.
Security Risk: High Vulnerability: Unauthenticated Stripe PaymentIntent Amount-Binding Bypass CVE: CVE-2026-5356 Number of Installations: 100,000+ Affected Software: LatePoint ≤ 5.4.0 Patched Versions: 5.4.1
Mitigation steps: Update to LatePoint version 5.4.1 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-65441 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.3 Patched Versions: 4.16.4
Mitigation steps: Update to GiveWP version 4.16.4 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-57691 Number of Installations: 100,000+ Affected Software: Anti-Malware Security and Brute-Force Firewall ≤ 4.23.89 Patched Versions: 4.23.90
Mitigation steps: Update to Anti-Malware Security and Brute-Force Firewall version 4.23.90 or greater.
Security Risk: High Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2025-13146 Number of Installations: 100,000+ Affected Software: Contact Form 7 ≤ 5.0.3 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: High Vulnerability: Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array CVE: CVE-2026-15022 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.0 Patched Versions: 4.0.1
Mitigation steps: Update to Tutor LMS version 4.0.1 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute CVE: CVE-2026-16685 Number of Installations: 100,000+ Affected Software: Download Manager ≤ 3.3.66 Patched Versions: 3.3.67
Mitigation steps: Update to Download Manager version 3.3.67 or greater.
Security Risk: Medium Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting CVE: CVE-2026-65563 Number of Installations: 100,000+ Affected Software: Orbit Fox ≤ 3.0.7 Patched Versions: 3.0.8
Mitigation steps: Update to Orbit Fox version 3.0.8 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute CVE: CVE-2026-15739 Number of Installations: 100,000+ Affected Software: Rich Showcase for Google Reviews ≤ 6.9.9 Patched Versions: 6.9.10
Mitigation steps: Update to Rich Showcase for Google Reviews version 6.9.10 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-65475 Number of Installations: 100,000+ Affected Software: Modula Image Gallery 2.14.25 - 2.14.30 Patched Versions: 2.14.31
Mitigation steps: Update to Modula Image Gallery version 2.14.31 or greater.
Security Risk: Medium Vulnerability: Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting CVE: CVE-2026-14987 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.3 Patched Versions: 4.16.4
Mitigation steps: Update to GiveWP version 4.16.4 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes CVE: CVE-2026-14343 Number of Installations: 100,000+ Affected Software: Download Manager ≤ 3.3.61 Patched Versions: 3.3.62
Mitigation steps: Update to Download Manager version 3.3.62 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-10082 Number of Installations: 100,000+ Affected Software: Advanced Ads ≤ 2.0.22 Patched Versions: 2.0.23
Mitigation steps: Update to Advanced Ads version 2.0.23 or greater.
Security Risk: Medium Vulnerability: Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form CVE: CVE-2026-13704 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.1 Patched Versions: 4.16.2
Mitigation steps: Update to GiveWP version 4.16.2 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret CVE: CVE-2026-12654 Number of Installations: 100,000+ Affected Software: Payment Plugins for Stripe WooCommerce ≤ 4.0.7 Patched Versions: 4.0.8
Mitigation steps: Update to Payment Plugins for Stripe WooCommerce version 4.0.8 or greater.
Security Risk: High Vulnerability: Missing Authorization CVE: CVE-2026-59530 Number of Installations: 100,000+ Affected Software: Payment Plugins for Stripe WooCommerce ≤ 4.0.7 Patched Versions: 4.0.8
Mitigation steps: Update to Payment Plugins for Stripe WooCommerce version 4.0.8 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step CVE: CVE-2026-11398 Number of Installations: 100,000+ Affected Software: LatePoint ≤ 5.6.1 Patched Versions: 5.6.2
Mitigation steps: Update to LatePoint version 5.6.2 or greater.
Security Risk: Medium Vulnerability: Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter CVE: CVE-2026-12657 Number of Installations: 100,000+ Affected Software: LatePoint ≤ 5.6.2 Patched Versions: 5.6.3
Mitigation steps: Update to LatePoint version 5.6.3 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter CVE: CVE-2026-15444 Number of Installations: 100,000+ Affected Software: Tutor LMS ≤ 4.0.1 Patched Versions: 4.0.2
Mitigation steps: Update to Tutor LMS 4.0.2 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter CVE: CVE-2026-15727 Number of Installations: 100,000+ Affected Software: WP Bulk Delete ≤ 1.4.2 Patched Versions: 1.4.3
Mitigation steps: Update to WP Bulk Delete version 1.4.3 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery CVE: CVE-2026-65464 Number of Installations: 100,000+ Affected Software: GiveWP ≤ 4.16.3 Patched Versions: 4.16.4
Mitigation steps: Update to GiveWP version 4.16.4 or greater.
Security Risk: High Vulnerability: Unauthenticated Insecure Direct Object Reference CVE: CVE-2026-57694 Number of Installations: 100,000+ Affected Software: Tutor LMS – eLearning and online course solution ≤ 3.9.13 Patched Versions: 3.9.14
Mitigation steps: Update to Tutor LMS – eLearning and online course solution version 3.9.14 or greater.
Security Risk: High Vulnerability: Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook CVE: CVE-2026-7655 Number of Installations: 90,000+ Affected Software: SureCart ≤ 4.2.3 Patched Versions: 4.3.0
Mitigation steps: Update to SureCart version 4.3.0 or greater.
Security Risk: High Vulnerability: Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data CVE: CVE-2026-1360 Number of Installations: 90,000+ Affected Software: BuddyPress ≤ 14.5.0 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Critical Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-57702 Number of Installations: 90,000+ Affected Software: Amelia ≤ 2.4.2 Patched Versions: 2.4.3
Mitigation steps: Update to Amelia version 2.4.3 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting CVE: CVE-2026-57737 Number of Installations: 90,000+ Affected Software: Shortcodes and extra features for Phlox theme ≤ 2.17.21 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-65567 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration ≤ 5.29.0.1 Patched Versions: 5.29.1
Mitigation steps: Update to Event Tickets and Registration version 5.29.1 or greater.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-57705 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration ≤ 5.28.5 Patched Versions: 5.28.5.1
Mitigation steps: Update to Event Tickets and Registration version 5.28.5.1 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter CVE: CVE-2026-13459 Number of Installations: 90,000+ Affected Software: JetFormBuilder ≤ 3.6.3 Patched Versions: 3.6.3.1
Mitigation steps: Update to JetFormBuilder version 3.6.3.1 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) SQL Injection via 'orderby' Parameter CVE: CVE-2026-16811 Number of Installations: 90,000+ Affected Software: ShopLentor ≤ 3.4.5 Patched Versions: 3.4.6
Mitigation steps: Update to ShopLentor version 3.4.6 or greater.
Security Risk: Medium Vulnerability: Authenticated (Custom+) SQL Injection via Customer Import CVE: CVE-2026-14782 Number of Installations: 90,000+ Affected Software: Amelia ≤ 2.4.3 Patched Versions: 2.4.4
Mitigation steps: Update to Amelia version 2.4.4 or greater.
Security Risk: Medium Vulnerability: Authenticated (Editor+) Stored Cross-Site Scripting CVE: CVE-2026-14819 Number of Installations: 90,000+ Affected Software: Event Tickets and Registration ≤ 5.28.3 Patched Versions: 5.28.4
Mitigation steps: Update to Event Tickets and Registration version 5.28.4 or greater.
Security Risk: Medium Vulnerability: Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter CVE: CVE-2026-16797 Number of Installations: 90,000+ Affected Software: ShopLentor ≤ 3.4.5 Patched Versions: 3.4.6
Mitigation steps: Update to ShopLentor version 3.4.6 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) Server-Side Request Forgery CVE: CVE-2026-4912 Number of Installations: 90,000+ Affected Software: Media Cleaner: Clean your WordPress! ≤ 7.0.3 Patched Versions: 7.0.6
Mitigation steps: Update to Media Cleaner: Clean your WordPress! version 7.0.6 or greater.
Security Risk: Medium Vulnerability: Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload CVE: CVE-2026-6101 Number of Installations: 80,000+ Affected Software: AMP for WP ≤ 1.1.12 Patched Versions: 1.1.13
Mitigation steps: Update to AMP for WP version 1.1.13 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-65440 Number of Installations: 80,000+ Affected Software: GetGenie ≤ 4.4.3 Patched Versions: 4.5.0
Mitigation steps: Update to GetGenie version 4.5.0 or greater.
Security Risk: Medium Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-57715 Number of Installations: 80,000+ Affected Software: FluentCRM ≤ 3.1.7 Patched Versions: 3.1.8
Mitigation steps: Update to FluentCRM version 3.1.8 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute CVE: CVE-2026-13771 Number of Installations: 80,000+ Affected Software: Customer Reviews for WooCommerce ≤ 5.113.0 Patched Versions: 5.114.0
Mitigation steps: Update to Customer Reviews for WooCommerce version 5.114.0 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints CVE: CVE-2026-15827 Number of Installations: 80,000+ Affected Software: GutenKit ≤ 2.4.12 Patched Versions: 2.4.13
Mitigation steps: Update to GutenKit version 2.4.13 or greater.
Security Risk: Medium Vulnerability: Two-Factor Authentication Bypass CVE: CVE-2026-59546 Number of Installations: 80,000+ Affected Software: WP Ghost (Hide My WP Ghost) ≤ 7.0.06 Patched Versions: 7.0.07
Mitigation steps: Update to WP Ghost (Hide My WP Ghost) version 7.0.07 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute CVE: CVE-2026-12434 Number of Installations: 80,000+ Affected Software: List category posts ≤ 0.95.0 Patched Versions: 0.96.0
Mitigation steps: Update to List category posts version 0.96.0 or greater.
Security Risk: High Vulnerability: Unauthenticated PHP Object Injection CVE: CVE-2026-57713 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.3.6 Patched Versions: 7.3.7
Mitigation steps: Update to Events Manager version 7.3.7 or greater.
Security Risk: High Vulnerability: Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints CVE: CVE-2026-13765 Number of Installations: 70,000+ Affected Software: LearnPress ≤ 4.4.1 Patched Versions: 4.4.2
Mitigation steps: Update to LearnPress version 4.4.2 or greater.
Security Risk: Critical Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-12987 Number of Installations: 70,000+ Affected Software: Events Manager ≤ 7.3.6 Patched Versions: 7.3.7
Mitigation steps: Update to Events Manager version 7.3.7 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting via 'Website' Field CVE: CVE-2026-9148 Number of Installations: 70,000+ Affected Software: Comments – wpDiscuz ≤ 7.6.56 Patched Versions: 7.6.57
Mitigation steps: Update to Comments – wpDiscuz version 7.6.57 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute CVE: CVE-2026-15652 Number of Installations: 70,000+ Affected Software: Easy Accordion ≤ 3.1.6 Patched Versions: 3.1.7
Mitigation steps: Update to Easy Accordion version 3.1.7 or greater.
Security Risk: TBC Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-65474 Number of Installations: 70,000+ Affected Software: Ninja Tables – Easy Data Table Builder ≤ 5.2.10 Patched Versions: 5.2.11
Mitigation steps: Update to Ninja Tables version 5.2.11 or greater.
Security Risk: Low Vulnerability: Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action CVE: CVE-2026-15026 Number of Installations: 70,000+ Affected Software: Import and export users and customers ≤ 2.4.0 Patched Versions: 2.4.1
Mitigation steps: Update to Import and export users and customers version 2.4.1 or greater.
Security Risk: Critical Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-14516 Number of Installations: 60,000+ Affected Software: Bookly ≤ 27.5 Patched Versions: None
Mitigation steps: No patched version listed. Review vendor guidance and apply compensating controls.
Security Risk: Critical Vulnerability: Unauthenticated SQL Injection CVE: CVE-2026-61949 Number of Installations: 60,000+ Affected Software: Bookly ≤ 27.7 Patched Versions: 27.8
Mitigation steps: Update to Bookly version 27.8 or greater.
Security Risk: Low Vulnerability: Authenticated (Shop Manager+) SQL Injection via 'tracking_provider' Parameter CVE: Not provided Number of Installations: 60,000+ Affected Software: Advanced Shipment Tracking for WooCommerce ≤ 3.9 Patched Versions: 3.9.1
Mitigation steps: Update to Advanced Shipment Tracking for WooCommerce version 3.9.1 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-65439 Number of Installations: 60,000+ Affected Software: Ultra Addons for Contact Form 7 ≤ 3.5.45 Patched Versions: 3.5.46
Mitigation steps: Update to Ultra Addons for Contact Form 7 version 3.5.46 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-61944 Number of Installations: 60,000+ Affected Software: Bookly ≤ 27.7 Patched Versions: 27.8
Mitigation steps: Update to Bookly version 27.8 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-57708 Number of Installations: 60,000+ Affected Software: Database for Contact Form 7, WPforms, Elementor forms ≤ 1.5.2 Patched Versions: 1.5.3
Mitigation steps: Update to Database for Contact Form 7, WPforms, Elementor forms version 1.5.3 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-13400 Number of Installations: 60,000+ Affected Software: Simply Schedule Appointments ≤ 1.6.12.3 Patched Versions: 1.6.12.4
Mitigation steps: Update to Simply Schedule Appointments version 1.6.12.4 or greater.
Security Risk: TBC Vulnerability: Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' CVE: CVE-2026-9145 Number of Installations: 60,000+ Affected Software: Database for Contact Form 7, WPforms, Elementor forms ≤ 1.5.1 Patched Versions: 1.5.2
Mitigation steps: Update to Database for Contact Form 7, WPforms, Elementor forms version 1.5.2 or greater.
Security Risk: TBC Vulnerability: Reflected Cross-Site Scripting CVE: CVE-2026-14870 Number of Installations: 60,000+ Affected Software: Database for Contact Form 7, WPforms, Elementor forms ≤ 1.5.2 Patched Versions: 1.5.3
Mitigation steps: Update to Database for Contact Form 7, WPforms, Elementor forms version 1.5.3 or greater.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-57812 Number of Installations: 60,000+ Affected Software: Appointment Booking Calendar ≤ 1.6.12.4 Patched Versions: 1.6.12.6
Mitigation steps: Update to Appointment Booking Calendar version 1.6.12.6 or greater.
Security Risk: Medium Vulnerability: Missing Authorization CVE: CVE-2026-59523 Number of Installations: 60,000+ Affected Software: Appointment Booking Calendar ≤ 1.6.11.11 Patched Versions: 1.6.12.0
Mitigation steps: Update to Appointment Booking Calendar version 1.6.12.0 or greater.
Security Risk: Medium Vulnerability: Authenticated (Shop manager+) SQL Injection CVE: CVE-2026-57773 Number of Installations: 60,000+ Affected Software: Advanced Shipment Tracking for WooCommerce ≤ 4.0 Patched Versions: 4.0.1
Mitigation steps: Update to Advanced Shipment Tracking for WooCommerce version 4.0.1 or greater.
Security Risk: Medium Vulnerability: Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action CVE: CVE-2026-11592 Number of Installations: 60,000+ Affected Software: Email Subscribers & Newsletters ≤ 5.9.27 Patched Versions: 5.9.28
Mitigation steps: Update to Email Subscribers & Newsletters version 5.9.28 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint CVE: CVE-2026-4275 Number of Installations: 50,000+ Affected Software: Divi Torque Lite ≤ 4.2.3 Patched Versions: 4.3.0
Mitigation steps: Update to Divi Torque Lite version 4.3.0 or greater.
Security Risk: High Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: CVE-2026-59558 Number of Installations: 50,000+ Affected Software: Booking Calendar ≤ 11.4.2 Patched Versions: 11.4.3
Mitigation steps: Update to Booking Calendar version 11.4.3 or greater.
Security Risk: Medium Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title CVE: CVE-2026-2594 Number of Installations: 50,000+ Affected Software: Smart Custom Fields ≤ 5.0.7 Patched Versions: 5.0.8
Mitigation steps: Update to Smart Custom Fields version 5.0.8 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title CVE: CVE-2026-11328 Number of Installations: 50,000+ Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.8 Patched Versions: 2.7.9.9
Mitigation steps: Update to Exclusive Addons for Elementor version 2.7.9.9 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter CVE: CVE-2026-8351 Number of Installations: 50,000+ Affected Software: RTMKit ≤ 2.0.7 Patched Versions: 2.0.8
Mitigation steps: Update to RTMKit version 2.0.8 or greater.
Security Risk: Medium Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-66438 Number of Installations: 50,000+ Affected Software: Exclusive Addons for Elementor ≤ 2.8.0 Patched Versions: 2.8.1
Mitigation steps: Update to Exclusive Addons for Elementor version 2.8.1 or greater.
Security Risk: TBC Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-59519 Number of Installations: 50,000+ Affected Software: FormLayer ≤ 1.0.6 Patched Versions: 1.0.7
Mitigation steps: Update to FormLayer version 1.0.7 or greater.
Security Risk: TBC Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-59511 Number of Installations: 50,000+ Affected Software: Exclusive Addons for Elementor ≤ 2.7.9.9 Patched Versions: 2.8.0
Mitigation steps: Update to Exclusive Addons for Elementor version 2.8.0 or greater.
Security Risk: Low Vulnerability: Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter CVE: CVE-2026-15786 Number of Installations: 50,000+ Affected Software: WP Encryption ≤ 7.8.6.6 Patched Versions: 7.8.6.7
Mitigation steps: Update to WP Encryption version 7.8.6.7 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery to CSS Modification CVE: CVE-2025-14469 Number of Installations: 50,000+ Affected Software: Theme Editor ≤ 3.1 Patched Versions: 3.2
Mitigation steps: Update to Theme Editor version 3.2 or greater.
Security Risk: Low Vulnerability: Cross-Site Request Forgery CVE: CVE-2026-65460 Number of Installations: 50,000+ Affected Software: ZarinPal for WooCommerce ≤ 5.1.0 Patched Versions: 5.1.1
Mitigation steps: Update to ZarinPal for WooCommerce version 5.1.1 or greater.
Security Risk: Medium Vulnerability: Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter CVE: CVE-2026-5137 Number of Installations: 50,000+ Affected Software: RTMKit ≤ 2.0.7 Patched Versions: 2.0.8
Mitigation steps: Update to RTMKit version 2.0.8 or greater.
Update your website software to reduce risk. If you cannot update to the latest version, consider using a web application firewall to patch known vulnerabilities and safeguard your site.