Website security: weekly review (07.09.2026)
A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.
MemberDash: security vulnerability
MemberDash · CVSS 9.8 · threat: Critical
Security vulnerability in the MemberDash component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-16310.
Frontend Admin by DynamiApps: authentication bypass
Frontend Admin by DynamiApps · CVSS 9.8 · threat: Critical
Authentication bypass in the Frontend Admin by DynamiApps component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-75816.
SureCart WordPress: security vulnerability
SureCart WordPress · CVSS 8.8 · threat: High
Security vulnerability in the SureCart WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-18480.
HivePress Authentication: authentication bypass
HivePress Authentication · CVSS 7.5 · threat: High
Authentication bypass in the HivePress Authentication component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-18056.
Kirki WordPress: security vulnerability
Kirki WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Kirki WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-84219.
Mstore Api: authentication bypass
Mstore Api · CVSS 9.8 · threat: Critical
Authentication bypass in the Mstore Api component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-13447.
Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN: remote code execution (RCE)
Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-83627.
Mail Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails: insecure deserialization
Mail Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails · CVSS 9.8 · threat: Critical
Insecure deserialization in the Mail Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-10196.
SEO Flow by LupsOnline WordPress: security vulnerability
SEO Flow by LupsOnline WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the SEO Flow by LupsOnline WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-78362.
Welcart e-Commerce: remote code execution (RCE)
Welcart e-Commerce · CVSS 8.8 · threat: High
Remote code execution (RCE) in the Welcart e-Commerce component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-19887.
Abandoned Cart Pro for WooCommerce: privilege escalation
Abandoned Cart Pro for WooCommerce · CVSS 8.8 · threat: High
Privilege escalation in the Abandoned Cart Pro for WooCommerce component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-81543.
Nokri - Job Board WordPress Theme: security vulnerability
Nokri - Job Board WordPress Theme · CVSS 8.8 · threat: High
Security vulnerability in the Nokri - Job Board WordPress Theme component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2025-9049.
RegistrationMagic WordPress: security vulnerability
RegistrationMagic WordPress · CVSS 8.8 · threat: High
Security vulnerability in the RegistrationMagic WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-77826.
Music Store WordPress: SQL injection
Music Store WordPress · CVSS 8.6 · threat: High
SQL injection in the Music Store WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-82304.
JCH Optimize WordPress: security vulnerability
JCH Optimize WordPress · CVSS 8 · threat: High
Security vulnerability in the JCH Optimize WordPress component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-84934.
HT Menu WordPress: security vulnerability
HT Menu WordPress · CVSS 8 · threat: High
Security vulnerability in the HT Menu WordPress component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-84935.
JetFormBuilder: Dynamic Blocks Form Builder WordPress: security vulnerability
JetFormBuilder: Dynamic Blocks Form Builder WordPress · CVSS 7.5 · threat: High
Security vulnerability in the JetFormBuilder: Dynamic Blocks Form Builder WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-19858.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more: cross-site scripting (XSS)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-77233.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more: cross-site scripting (XSS)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-77263.
QuickCal: cross-site scripting (XSS)
QuickCal · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the QuickCal component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-15984.
Gravity Forms: cross-site scripting (XSS)
Gravity Forms · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Gravity Forms component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-16649.
SureForms - Contact Form Builder, AI Forms, Payment Form, Survey & Quiz: cross-site scripting (XSS)
SureForms - Contact Form Builder, AI Forms, Payment Form, Survey & Quiz · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the SureForms - Contact Form Builder, AI Forms, Payment Form, Survey & Quiz component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-18406.
Ninja Forms - The Contact Form Builder That Grows With You: arbitrary file upload
Ninja Forms - The Contact Form Builder That Grows With You · CVSS 7.2 · threat: High
Arbitrary file upload in the Ninja Forms - The Contact Form Builder That Grows With You component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-19769.
Spam protection, Honeypot, Anti-Spam by CleanTalk: cross-site scripting (XSS)
Spam protection, Honeypot, Anti-Spam by CleanTalk · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Spam protection, Honeypot, Anti-Spam by CleanTalk component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-77830.
W3 Total Cache: cross-site scripting (XSS)
W3 Total Cache · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the W3 Total Cache component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-78438.
Contact Form by Supsystic: cross-site scripting (XSS)
Contact Form by Supsystic · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Contact Form by Supsystic component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-83625.
IPGP Visitors Origin WordPress: cross-site scripting (XSS)
IPGP Visitors Origin WordPress · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the IPGP Visitors Origin WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-81404.
Divi Ajax Filter: remote code execution (RCE)
Divi Ajax Filter · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Divi Ajax Filter component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-11613.
ACPT (Premium): privilege escalation
ACPT (Premium) · CVSS 9.8 · threat: Critical
Privilege escalation in the ACPT (Premium) component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-15354.
AI Website Builder WordPress: remote code execution (RCE)
AI Website Builder WordPress · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the AI Website Builder WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-82923.
LearnDash LMS: remote code execution (RCE)
LearnDash LMS · CVSS 7.5 · threat: High
Remote code execution (RCE) in the LearnDash LMS component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-12483.
Hummingbird Performance WordPress: security vulnerability
Hummingbird Performance WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Hummingbird Performance WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-19224.
Classified Listing WordPress: security vulnerability
Classified Listing WordPress · CVSS 7.1 · threat: High
Security vulnerability in the Classified Listing WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-16281.
Joomla: security vulnerability
Joomla · CVSS 9.5 · threat: Critical
Security vulnerability in the Joomla component. Threat level: Critical (CVSS 9.5).
Details and what to do: CVE-2026-78069.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-78080.
Joomla: CSRF (request forgery)
Joomla · CVSS 8.8 · threat: High
CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-78064.
Joomla: security vulnerability
Joomla · CVSS 8.7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-77999.
Joomla: security vulnerability
Joomla · CVSS 7.1 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-78065.
Embed HTML5 Game WordPress: security vulnerability
Embed HTML5 Game WordPress · CVSS 10 · threat: Critical
Security vulnerability in the Embed HTML5 Game WordPress component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-4357.
WatchMan-Site7 WordPress: security vulnerability
WatchMan-Site7 WordPress · CVSS 9.9 · threat: Critical
Security vulnerability in the WatchMan-Site7 WordPress component. Threat level: Critical (CVSS 9.9).
Details and what to do: CVE-2026-77009.
Booking for Appointments and Events Calendar - Amelia (Premium): privilege escalation
Booking for Appointments and Events Calendar - Amelia (Premium) · CVSS 9.8 · threat: Critical
Privilege escalation in the Booking for Appointments and Events Calendar - Amelia (Premium) component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-9055.
SigmaForms Pro - AI Generated Forms: remote code execution (RCE)
SigmaForms Pro - AI Generated Forms · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the SigmaForms Pro - AI Generated Forms component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-78657.
Developer Tools WordPress: arbitrary file upload
Developer Tools WordPress · CVSS 9.8 · threat: Critical
Arbitrary file upload in the Developer Tools WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2025-9314.
DevKit Pro: remote code execution (RCE)
DevKit Pro · CVSS 8.8 · threat: High
Remote code execution (RCE) in the DevKit Pro component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-14357.
User Frontend WordPress: remote code execution (RCE)
User Frontend WordPress · CVSS 8.8 · threat: High
Remote code execution (RCE) in the User Frontend WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-19116.
FAQ Builder AYS WordPress: cross-site scripting (XSS)
FAQ Builder AYS WordPress · CVSS 8.8 · threat: High
Cross-site scripting (XSS) in the FAQ Builder AYS WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-81737.
Simple Ajax Chat WordPress: security vulnerability
Simple Ajax Chat WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Simple Ajax Chat WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-81807.
Auto x LINE WordPress: security vulnerability
Auto x LINE WordPress · CVSS 8.2 · threat: High
Security vulnerability in the Auto x LINE WordPress component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2025-15485.
WP File Download: remote code execution (RCE)
WP File Download · CVSS 8.1 · threat: High
Remote code execution (RCE) in the WP File Download component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-14982.
Advanced Custom Fields: Extended WordPress: security vulnerability
Advanced Custom Fields: Extended WordPress · CVSS 8.1 · threat: High
Security vulnerability in the Advanced Custom Fields: Extended WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-12526.
Advanced Custom Fields: Extended WordPress: security vulnerability
Advanced Custom Fields: Extended WordPress · CVSS 8.1 · threat: High
Security vulnerability in the Advanced Custom Fields: Extended WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-80467.
OAuth Single Sign On WordPress: security vulnerability
OAuth Single Sign On WordPress · CVSS 8.1 · threat: High
Security vulnerability in the OAuth Single Sign On WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-82183.
RegistrationMagic WordPress: cross-site scripting (XSS)
RegistrationMagic WordPress · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the RegistrationMagic WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-77792.
Broken Link Checker: cross-site scripting (XSS)
Broken Link Checker · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Broken Link Checker component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-75528.
Photo Gallery by 10Web WordPress: security vulnerability
Photo Gallery by 10Web WordPress · CVSS 7.1 · threat: High
Security vulnerability in the Photo Gallery by 10Web WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-12865.
JetBackup WordPress: security vulnerability
JetBackup WordPress · CVSS 7.1 · threat: High
Security vulnerability in the JetBackup WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-19453.
Social Media Share Buttons & Social Sharing Icons WordPress: cross-site scripting (XSS)
Social Media Share Buttons & Social Sharing Icons WordPress · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Social Media Share Buttons & Social Sharing Icons WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-19723.
WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: remote code execution (RCE)
WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-75865.
Nokri - Job Board WordPress: account takeover
Nokri - Job Board WordPress · CVSS 9.8 · threat: Critical
Account takeover in the Nokri - Job Board WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-18550.
Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System: authentication bypass
Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System · CVSS 8.8 · threat: High
Authentication bypass in the Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-19806.
FS-Poster: remote code execution (RCE)
FS-Poster · CVSS 8.8 · threat: High
Remote code execution (RCE) in the FS-Poster component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-10195.
Gravity Forms: remote code execution (RCE)
Gravity Forms · CVSS 8.1 · threat: High
Remote code execution (RCE) in the Gravity Forms component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-19513.
Frontend Admin by DynamiApps: remote code execution (RCE)
Frontend Admin by DynamiApps · CVSS 7.5 · threat: High
Remote code execution (RCE) in the Frontend Admin by DynamiApps component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-19952.
Affiliate Super Assistent: cross-site scripting (XSS)
Affiliate Super Assistent · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Affiliate Super Assistent component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-19573.
Listdom: AI-powered Business Directory with Classifieds Ads Listings: cross-site scripting (XSS)
Listdom: AI-powered Business Directory with Classifieds Ads Listings · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Listdom: AI-powered Business Directory with Classifieds Ads Listings component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-19796.
Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits: remote code execution (RCE)
Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits · CVSS 7.2 · threat: High
Remote code execution (RCE) in the Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-75921.
Welcart e-Commerce: cross-site scripting (XSS)
Welcart e-Commerce · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Welcart e-Commerce component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-19914.
Joomla: arbitrary file upload
Joomla · CVSS 8.9 · threat: High
Arbitrary file upload in the Joomla component. Threat level: High (CVSS 8.9).
Details and what to do: CVE-2026-78078.
Joomla: authentication bypass
Joomla · CVSS 8.8 · threat: High
Authentication bypass in the Joomla component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-78074.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 8.6 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-78077.
ProfilePress (wp-user-avatar) WordPress: remote code execution (RCE)
ProfilePress (wp-user-avatar) WordPress · CVSS 8.1 · threat: High
Remote code execution (RCE) in the ProfilePress (wp-user-avatar) WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-66047.
Keep Backup Daily: sensitive data disclosure
Keep Backup Daily · CVSS 7.5 · threat: High
Sensitive data disclosure in the Keep Backup Daily component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-75133.
A vulnerability was found in Cozmoslabs Profile Builder: security vulnerability
A vulnerability was found in Cozmoslabs Profile Builder · CVSS 7.3 · threat: High
Security vulnerability in the A vulnerability was found in Cozmoslabs Profile Builder component. Threat level: High (CVSS 7.3).
Details and what to do: CVE-2026-82607.
WordPress: security vulnerability
WordPress · CVSS 7.1 · threat: High
Security vulnerability in the WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-82229.
You will find the full, continuously updated list on the Current threats page.
Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.