Security

Website security: weekly review (07.09.2026)

Website security: weekly review (07.09.2026)

A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.

MemberDash: security vulnerability

MemberDash · CVSS 9.8 · threat: Critical

Security vulnerability in the MemberDash component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-16310.

Frontend Admin by DynamiApps: authentication bypass

Frontend Admin by DynamiApps · CVSS 9.8 · threat: Critical

Authentication bypass in the Frontend Admin by DynamiApps component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-75816.

SureCart WordPress: security vulnerability

SureCart WordPress · CVSS 8.8 · threat: High

Security vulnerability in the SureCart WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-18480.

HivePress Authentication: authentication bypass

HivePress Authentication · CVSS 7.5 · threat: High

Authentication bypass in the HivePress Authentication component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-18056.

Kirki WordPress: security vulnerability

Kirki WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Kirki WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-84219.

Mstore Api: authentication bypass

Mstore Api · CVSS 9.8 · threat: Critical

Authentication bypass in the Mstore Api component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-13447.

Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN: remote code execution (RCE)

Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Hummingbird - Speed Optimization, Caching, Minify, Compress & CDN component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-83627.

Mail Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails: insecure deserialization

Mail Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails · CVSS 9.8 · threat: Critical

Insecure deserialization in the Mail Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-10196.

SEO Flow by LupsOnline WordPress: security vulnerability

SEO Flow by LupsOnline WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the SEO Flow by LupsOnline WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-78362.

Welcart e-Commerce: remote code execution (RCE)

Welcart e-Commerce · CVSS 8.8 · threat: High

Remote code execution (RCE) in the Welcart e-Commerce component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-19887.

Abandoned Cart Pro for WooCommerce: privilege escalation

Abandoned Cart Pro for WooCommerce · CVSS 8.8 · threat: High

Privilege escalation in the Abandoned Cart Pro for WooCommerce component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-81543.

Nokri - Job Board WordPress Theme: security vulnerability

Nokri - Job Board WordPress Theme · CVSS 8.8 · threat: High

Security vulnerability in the Nokri - Job Board WordPress Theme component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2025-9049.

RegistrationMagic WordPress: security vulnerability

RegistrationMagic WordPress · CVSS 8.8 · threat: High

Security vulnerability in the RegistrationMagic WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-77826.

Music Store WordPress: SQL injection

Music Store WordPress · CVSS 8.6 · threat: High

SQL injection in the Music Store WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-82304.

JCH Optimize WordPress: security vulnerability

JCH Optimize WordPress · CVSS 8 · threat: High

Security vulnerability in the JCH Optimize WordPress component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-84934.

HT Menu WordPress: security vulnerability

HT Menu WordPress · CVSS 8 · threat: High

Security vulnerability in the HT Menu WordPress component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-84935.

JetFormBuilder: Dynamic Blocks Form Builder WordPress: security vulnerability

JetFormBuilder: Dynamic Blocks Form Builder WordPress · CVSS 7.5 · threat: High

Security vulnerability in the JetFormBuilder: Dynamic Blocks Form Builder WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-19858.

iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more: cross-site scripting (XSS)

iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-77233.

iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more: cross-site scripting (XSS)

iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-77263.

QuickCal: cross-site scripting (XSS)

QuickCal · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the QuickCal component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-15984.

Gravity Forms: cross-site scripting (XSS)

Gravity Forms · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Gravity Forms component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-16649.

SureForms - Contact Form Builder, AI Forms, Payment Form, Survey & Quiz: cross-site scripting (XSS)

SureForms - Contact Form Builder, AI Forms, Payment Form, Survey & Quiz · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the SureForms - Contact Form Builder, AI Forms, Payment Form, Survey & Quiz component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-18406.

Ninja Forms - The Contact Form Builder That Grows With You: arbitrary file upload

Ninja Forms - The Contact Form Builder That Grows With You · CVSS 7.2 · threat: High

Arbitrary file upload in the Ninja Forms - The Contact Form Builder That Grows With You component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-19769.

Spam protection, Honeypot, Anti-Spam by CleanTalk: cross-site scripting (XSS)

Spam protection, Honeypot, Anti-Spam by CleanTalk · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Spam protection, Honeypot, Anti-Spam by CleanTalk component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-77830.

W3 Total Cache: cross-site scripting (XSS)

W3 Total Cache · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the W3 Total Cache component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-78438.

Contact Form by Supsystic: cross-site scripting (XSS)

Contact Form by Supsystic · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Contact Form by Supsystic component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-83625.

IPGP Visitors Origin WordPress: cross-site scripting (XSS)

IPGP Visitors Origin WordPress · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the IPGP Visitors Origin WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-81404.

Divi Ajax Filter: remote code execution (RCE)

Divi Ajax Filter · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Divi Ajax Filter component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-11613.

ACPT (Premium): privilege escalation

ACPT (Premium) · CVSS 9.8 · threat: Critical

Privilege escalation in the ACPT (Premium) component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-15354.

AI Website Builder WordPress: remote code execution (RCE)

AI Website Builder WordPress · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the AI Website Builder WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-82923.

LearnDash LMS: remote code execution (RCE)

LearnDash LMS · CVSS 7.5 · threat: High

Remote code execution (RCE) in the LearnDash LMS component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-12483.

Hummingbird Performance WordPress: security vulnerability

Hummingbird Performance WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Hummingbird Performance WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-19224.

Classified Listing WordPress: security vulnerability

Classified Listing WordPress · CVSS 7.1 · threat: High

Security vulnerability in the Classified Listing WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-16281.

Joomla: security vulnerability

Joomla · CVSS 9.5 · threat: Critical

Security vulnerability in the Joomla component. Threat level: Critical (CVSS 9.5).

Details and what to do: CVE-2026-78069.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-78080.

Joomla: CSRF (request forgery)

Joomla · CVSS 8.8 · threat: High

CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-78064.

Joomla: security vulnerability

Joomla · CVSS 8.7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-77999.

Joomla: security vulnerability

Joomla · CVSS 7.1 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-78065.

Embed HTML5 Game WordPress: security vulnerability

Embed HTML5 Game WordPress · CVSS 10 · threat: Critical

Security vulnerability in the Embed HTML5 Game WordPress component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-4357.

WatchMan-Site7 WordPress: security vulnerability

WatchMan-Site7 WordPress · CVSS 9.9 · threat: Critical

Security vulnerability in the WatchMan-Site7 WordPress component. Threat level: Critical (CVSS 9.9).

Details and what to do: CVE-2026-77009.

Booking for Appointments and Events Calendar - Amelia (Premium): privilege escalation

Booking for Appointments and Events Calendar - Amelia (Premium) · CVSS 9.8 · threat: Critical

Privilege escalation in the Booking for Appointments and Events Calendar - Amelia (Premium) component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-9055.

SigmaForms Pro - AI Generated Forms: remote code execution (RCE)

SigmaForms Pro - AI Generated Forms · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the SigmaForms Pro - AI Generated Forms component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-78657.

Developer Tools WordPress: arbitrary file upload

Developer Tools WordPress · CVSS 9.8 · threat: Critical

Arbitrary file upload in the Developer Tools WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2025-9314.

DevKit Pro: remote code execution (RCE)

DevKit Pro · CVSS 8.8 · threat: High

Remote code execution (RCE) in the DevKit Pro component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-14357.

User Frontend WordPress: remote code execution (RCE)

User Frontend WordPress · CVSS 8.8 · threat: High

Remote code execution (RCE) in the User Frontend WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-19116.

FAQ Builder AYS WordPress: cross-site scripting (XSS)

FAQ Builder AYS WordPress · CVSS 8.8 · threat: High

Cross-site scripting (XSS) in the FAQ Builder AYS WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-81737.

Simple Ajax Chat WordPress: security vulnerability

Simple Ajax Chat WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Simple Ajax Chat WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-81807.

Auto x LINE WordPress: security vulnerability

Auto x LINE WordPress · CVSS 8.2 · threat: High

Security vulnerability in the Auto x LINE WordPress component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2025-15485.

WP File Download: remote code execution (RCE)

WP File Download · CVSS 8.1 · threat: High

Remote code execution (RCE) in the WP File Download component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-14982.

Advanced Custom Fields: Extended WordPress: security vulnerability

Advanced Custom Fields: Extended WordPress · CVSS 8.1 · threat: High

Security vulnerability in the Advanced Custom Fields: Extended WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-12526.

Advanced Custom Fields: Extended WordPress: security vulnerability

Advanced Custom Fields: Extended WordPress · CVSS 8.1 · threat: High

Security vulnerability in the Advanced Custom Fields: Extended WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-80467.

OAuth Single Sign On WordPress: security vulnerability

OAuth Single Sign On WordPress · CVSS 8.1 · threat: High

Security vulnerability in the OAuth Single Sign On WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-82183.

RegistrationMagic WordPress: cross-site scripting (XSS)

RegistrationMagic WordPress · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the RegistrationMagic WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-77792.

Broken Link Checker: cross-site scripting (XSS)

Broken Link Checker · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Broken Link Checker component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-75528.

Photo Gallery by 10Web WordPress: security vulnerability

Photo Gallery by 10Web WordPress · CVSS 7.1 · threat: High

Security vulnerability in the Photo Gallery by 10Web WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-12865.

JetBackup WordPress: security vulnerability

JetBackup WordPress · CVSS 7.1 · threat: High

Security vulnerability in the JetBackup WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-19453.

Social Media Share Buttons & Social Sharing Icons WordPress: cross-site scripting (XSS)

Social Media Share Buttons & Social Sharing Icons WordPress · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Social Media Share Buttons & Social Sharing Icons WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-19723.

WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: remote code execution (RCE)

WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-75865.

Nokri - Job Board WordPress: account takeover

Nokri - Job Board WordPress · CVSS 9.8 · threat: Critical

Account takeover in the Nokri - Job Board WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-18550.

Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System: authentication bypass

Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System · CVSS 8.8 · threat: High

Authentication bypass in the Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-19806.

FS-Poster: remote code execution (RCE)

FS-Poster · CVSS 8.8 · threat: High

Remote code execution (RCE) in the FS-Poster component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-10195.

Gravity Forms: remote code execution (RCE)

Gravity Forms · CVSS 8.1 · threat: High

Remote code execution (RCE) in the Gravity Forms component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-19513.

Frontend Admin by DynamiApps: remote code execution (RCE)

Frontend Admin by DynamiApps · CVSS 7.5 · threat: High

Remote code execution (RCE) in the Frontend Admin by DynamiApps component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-19952.

Affiliate Super Assistent: cross-site scripting (XSS)

Affiliate Super Assistent · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Affiliate Super Assistent component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-19573.

Listdom: AI-powered Business Directory with Classifieds Ads Listings: cross-site scripting (XSS)

Listdom: AI-powered Business Directory with Classifieds Ads Listings · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Listdom: AI-powered Business Directory with Classifieds Ads Listings component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-19796.

Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits: remote code execution (RCE)

Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits · CVSS 7.2 · threat: High

Remote code execution (RCE) in the Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-75921.

Welcart e-Commerce: cross-site scripting (XSS)

Welcart e-Commerce · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Welcart e-Commerce component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-19914.

Joomla: arbitrary file upload

Joomla · CVSS 8.9 · threat: High

Arbitrary file upload in the Joomla component. Threat level: High (CVSS 8.9).

Details and what to do: CVE-2026-78078.

Joomla: authentication bypass

Joomla · CVSS 8.8 · threat: High

Authentication bypass in the Joomla component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-78074.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 8.6 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-78077.

ProfilePress (wp-user-avatar) WordPress: remote code execution (RCE)

ProfilePress (wp-user-avatar) WordPress · CVSS 8.1 · threat: High

Remote code execution (RCE) in the ProfilePress (wp-user-avatar) WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-66047.

Keep Backup Daily: sensitive data disclosure

Keep Backup Daily · CVSS 7.5 · threat: High

Sensitive data disclosure in the Keep Backup Daily component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-75133.

A vulnerability was found in Cozmoslabs Profile Builder: security vulnerability

A vulnerability was found in Cozmoslabs Profile Builder · CVSS 7.3 · threat: High

Security vulnerability in the A vulnerability was found in Cozmoslabs Profile Builder component. Threat level: High (CVSS 7.3).

Details and what to do: CVE-2026-82607.

WordPress: security vulnerability

WordPress · CVSS 7.1 · threat: High

Security vulnerability in the WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-82229.


You will find the full, continuously updated list on the Current threats page.

Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.