Website security: weekly review (14.09.2026)
A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.
CryptoPayment Gateway WordPress: security vulnerability
CryptoPayment Gateway WordPress · CVSS 10 · threat: Critical
Security vulnerability in the CryptoPayment Gateway WordPress component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-81648.
GenieWords WordPress: security vulnerability
GenieWords WordPress · CVSS 8.8 · threat: High
Security vulnerability in the GenieWords WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-74933.
Hoo Companion WordPress: security vulnerability
Hoo Companion WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Hoo Companion WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85129.
YouTube Embed WordPress: security vulnerability
YouTube Embed WordPress · CVSS 8.8 · threat: High
Security vulnerability in the YouTube Embed WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-88793.
User Registration & Membership WordPress: privilege escalation
User Registration & Membership WordPress · CVSS 7.5 · threat: High
Privilege escalation in the User Registration & Membership WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-86406.
Really Simple Security WordPress: security vulnerability
Really Simple Security WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Really Simple Security WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-89080.
MDJM Event Management WordPress: security vulnerability
MDJM Event Management WordPress · CVSS 7.5 · threat: High
Security vulnerability in the MDJM Event Management WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-88802.
User Registration & Membership WordPress: security vulnerability
User Registration & Membership WordPress · CVSS 7.2 · threat: High
Security vulnerability in the User Registration & Membership WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-80071.
Masteriyo LMS WordPress: remote code execution (RCE)
Masteriyo LMS WordPress · CVSS 9.9 · threat: Critical
Remote code execution (RCE) in the Masteriyo LMS WordPress component. Threat level: Critical (CVSS 9.9).
Details and what to do: CVE-2026-82845.
Frontegg SAML SSO WordPress: security vulnerability
Frontegg SAML SSO WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the Frontegg SAML SSO WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-75800.
DS Ad Rotator WordPress: remote code execution (RCE)
DS Ad Rotator WordPress · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the DS Ad Rotator WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-81402.
WP images upload on piclect WordPress: security vulnerability
WP images upload on piclect WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the WP images upload on piclect WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-84171.
WP: security vulnerability
WP · CVSS 9.8 · threat: Critical
Security vulnerability in the WP component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-85681.
The Events Calendar: remote code execution (RCE)
The Events Calendar · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the The Events Calendar component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-78006.
The Events Calendar: remote code execution (RCE)
The Events Calendar · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the The Events Calendar component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-78159.
CODE MONKEYS PROPOSALS WordPress: security vulnerability
CODE MONKEYS PROPOSALS WordPress · CVSS 9.6 · threat: Critical
Security vulnerability in the CODE MONKEYS PROPOSALS WordPress component. Threat level: Critical (CVSS 9.6).
Details and what to do: CVE-2026-77005.
WebTotem Backups WordPress: CSRF (request forgery)
WebTotem Backups WordPress · CVSS 9.6 · threat: Critical
CSRF (request forgery) in the WebTotem Backups WordPress component. Threat level: Critical (CVSS 9.6).
Details and what to do: CVE-2026-77006.
BE REST Endpoints WordPress: security vulnerability
BE REST Endpoints WordPress · CVSS 8.8 · threat: High
Security vulnerability in the BE REST Endpoints WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-81742.
Add User Autocomplete WordPress: security vulnerability
Add User Autocomplete WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Add User Autocomplete WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-87759.
Tutor LMS - eLearning and online course solution: remote code execution (RCE)
Tutor LMS - eLearning and online course solution · CVSS 8.8 · threat: High
Remote code execution (RCE) in the Tutor LMS - eLearning and online course solution component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-78175.
MemberPress Corporate Accounts: privilege escalation
MemberPress Corporate Accounts · CVSS 8.8 · threat: High
Privilege escalation in the MemberPress Corporate Accounts component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-15451.
SAMO Forms WordPress: SQL injection
SAMO Forms WordPress · CVSS 8.6 · threat: High
SQL injection in the SAMO Forms WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-80491.
Yogeta WP Cloud WordPress: security vulnerability
Yogeta WP Cloud WordPress · CVSS 8.6 · threat: High
Security vulnerability in the Yogeta WP Cloud WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-80494.
Album Cover Finder WordPress: SQL injection
Album Cover Finder WordPress · CVSS 8.6 · threat: High
SQL injection in the Album Cover Finder WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-84047.
wpstorecart WordPress: security vulnerability
wpstorecart WordPress · CVSS 8.1 · threat: High
Security vulnerability in the wpstorecart WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-84099.
YayPricing WordPress: security vulnerability
YayPricing WordPress · CVSS 8 · threat: High
Security vulnerability in the YayPricing WordPress component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-87888.
Zonify WordPress: security vulnerability
Zonify WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Zonify WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-87842.
rtMedia for WordPress, BuddyPress and bbPress: SQL injection
rtMedia for WordPress, BuddyPress and bbPress · CVSS 7.5 · threat: High
SQL injection in the rtMedia for WordPress, BuddyPress and bbPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-16482.
GEO my WP: remote code execution (RCE)
GEO my WP · CVSS 7.5 · threat: High
Remote code execution (RCE) in the GEO my WP component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85200.
Booking for Appointments and Events Calendar WordPress: security vulnerability
Booking for Appointments and Events Calendar WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Booking for Appointments and Events Calendar WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-77705.
Temporary Login Without Password WordPress: security vulnerability
Temporary Login Without Password WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Temporary Login Without Password WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-77752.
Gpx2Graphics WordPress: remote code execution (RCE)
Gpx2Graphics WordPress · CVSS 7.2 · threat: High
Remote code execution (RCE) in the Gpx2Graphics WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-81090.
Export & Import WPBakery Page Builder WordPress: cross-site scripting (XSS)
Export & Import WPBakery Page Builder WordPress · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Export & Import WPBakery Page Builder WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-81429.
teddy-bear-customize-addon WordPress: security vulnerability
teddy-bear-customize-addon WordPress · CVSS 10 · threat: Critical
Security vulnerability in the teddy-bear-customize-addon WordPress component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-14560.
MIPL Grouped Checkout Fields for WooCommerce - Customize & Organize Checkout Fields.: remote code execution (RCE)
MIPL Grouped Checkout Fields for WooCommerce - Customize & Organize Checkout Fields. · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the MIPL Grouped Checkout Fields for WooCommerce - Customize & Organize Checkout Fields. component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-8778.
teddy-bear-customize-addon WordPress: security vulnerability
teddy-bear-customize-addon WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the teddy-bear-customize-addon WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-14559.
advanced-customized-prompts WordPress: security vulnerability
advanced-customized-prompts WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the advanced-customized-prompts WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-14563.
Gutenverse News WordPress: security vulnerability
Gutenverse News WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Gutenverse News WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85677.
UsersWP: arbitrary file deletion
UsersWP · CVSS 8.1 · threat: High
Arbitrary file deletion in the UsersWP component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-19991.
AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: directory traversal
AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress · CVSS 7.5 · threat: High
Directory traversal in the AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-77807.
Sticky Chat Widget: SQL injection
Sticky Chat Widget · CVSS 7.5 · threat: High
SQL injection in the Sticky Chat Widget component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-15462.
Unlimited Elements For Elementor: SQL injection
Unlimited Elements For Elementor · CVSS 7.5 · threat: High
SQL injection in the Unlimited Elements For Elementor component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-18561.
WP Photo Album Plus: cross-site scripting (XSS)
WP Photo Album Plus · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WP Photo Album Plus component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-18579.
Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…: cross-site scripting (XSS)
Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-81754.
Simple Ajax Chat - Add a Fast, Secure Chat Box: cross-site scripting (XSS)
Simple Ajax Chat - Add a Fast, Secure Chat Box · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Simple Ajax Chat - Add a Fast, Secure Chat Box component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-81825.
MultiVendorX WordPress: security vulnerability
MultiVendorX WordPress · CVSS 7.2 · threat: High
Security vulnerability in the MultiVendorX WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-74925.
Kirki - Freeform Page Builder, Website Builder & Customizer: cross-site scripting (XSS)
Kirki - Freeform Page Builder, Website Builder & Customizer · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Kirki - Freeform Page Builder, Website Builder & Customizer component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-17037.
miniOrange 2FA WordPress: security vulnerability
miniOrange 2FA WordPress · CVSS 10 · threat: Critical
Security vulnerability in the miniOrange 2FA WordPress component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-77770.
Drag and Drop File Upload for Elementor Forms: remote code execution (RCE)
Drag and Drop File Upload for Elementor Forms · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Drag and Drop File Upload for Elementor Forms component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-18351.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-78082.
zipMoney(Zip Co) Payments: security vulnerability
zipMoney(Zip Co) Payments · CVSS 9.1 · threat: Critical
Security vulnerability in the zipMoney(Zip Co) Payments component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-78361.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 8.6 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-78302.
Site Reviews WordPress: security vulnerability
Site Reviews WordPress · CVSS 8.1 · threat: High
Security vulnerability in the Site Reviews WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-82925.
Bulk Password Reset: account takeover
Bulk Password Reset · CVSS 8 · threat: High
Account takeover in the Bulk Password Reset component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-14873.
Direct Download for WooCommerce: directory traversal
Direct Download for WooCommerce · CVSS 7.5 · threat: High
Directory traversal in the Direct Download for WooCommerce component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-15019.
Ultimate Gift Cards for WooCommerce WordPress: security vulnerability
Ultimate Gift Cards for WooCommerce WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Ultimate Gift Cards for WooCommerce WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-19436.
Ultimate Gift Cards for WooCommerce WordPress: security vulnerability
Ultimate Gift Cards for WooCommerce WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Ultimate Gift Cards for WooCommerce WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-19439.
miniOrange 2FA WordPress: security vulnerability
miniOrange 2FA WordPress · CVSS 7.5 · threat: High
Security vulnerability in the miniOrange 2FA WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-77771.
Sidebar Manager Light: cross-site scripting (XSS)
Sidebar Manager Light · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Sidebar Manager Light component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-76562.
Registration Form for WooCommerce WordPress: security vulnerability
Registration Form for WooCommerce WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Registration Form for WooCommerce WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-81431.
Joomla: CSRF (request forgery)
Joomla · CVSS 7.1 · threat: High
CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-78083.
FireBox - WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment: remote code execution (RCE)
FireBox - WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment · CVSS 8.8 · threat: High
Remote code execution (RCE) in the FireBox - WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-76801.
YITH WooCommerce Waitlist Premium: privilege escalation
YITH WooCommerce Waitlist Premium · CVSS 8.8 · threat: High
Privilege escalation in the YITH WooCommerce Waitlist Premium component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-14359.
ELEX WooCommerce Request a Quote WordPress: SQL injection
ELEX WooCommerce Request a Quote WordPress · CVSS 8.6 · threat: High
SQL injection in the ELEX WooCommerce Request a Quote WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-14962.
Quentn WP WordPress: SQL injection
Quentn WP WordPress · CVSS 8.6 · threat: High
SQL injection in the Quentn WP WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-84068.
Next-Cart Store to WooCommerce Migration: arbitrary file deletion
Next-Cart Store to WooCommerce Migration · CVSS 8.1 · threat: High
Arbitrary file deletion in the Next-Cart Store to WooCommerce Migration component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-76009.
Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered): remote code execution (RCE)
Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 7.5 · threat: High
Remote code execution (RCE) in the Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-15406.
Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered): remote code execution (RCE)
Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 7.5 · threat: High
Remote code execution (RCE) in the Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-15667.
Loops & Logic WordPress: security vulnerability
Loops & Logic WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Loops & Logic WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-16960.
Contact Form to DB by BestWebSoft - Messages Database: cross-site scripting (XSS)
Contact Form to DB by BestWebSoft - Messages Database · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Contact Form to DB by BestWebSoft - Messages Database component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-13359.
WP EasyCart: privilege escalation
WP EasyCart · CVSS 7.2 · threat: High
Privilege escalation in the WP EasyCart component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-17553.
Repeater Fields for Gravity Forms: cross-site scripting (XSS)
Repeater Fields for Gravity Forms · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Repeater Fields for Gravity Forms component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-84293.
WPBot - AI ChatBot for Live Support, Lead Generation, AI Services: cross-site scripting (XSS)
WPBot - AI ChatBot for Live Support, Lead Generation, AI Services · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-83593.
PublishPress Capabilities - User Role Editor, Access Permissions, User Capabilities, Admin Menus: privilege escalation
PublishPress Capabilities - User Role Editor, Access Permissions, User Capabilities, Admin Menus · CVSS 7.2 · threat: High
Privilege escalation in the PublishPress Capabilities - User Role Editor, Access Permissions, User Capabilities, Admin Menus component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-75927.
Cookie Banner for GDPR / CCPA - WPLP Cookie Consent: cross-site scripting (XSS)
Cookie Banner for GDPR / CCPA - WPLP Cookie Consent · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Cookie Banner for GDPR / CCPA - WPLP Cookie Consent component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-14989.
Rara One Click Demo Import: remote code execution (RCE)
Rara One Click Demo Import · CVSS 7.2 · threat: High
Remote code execution (RCE) in the Rara One Click Demo Import component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-26212.
Live Composer - Free WordPress Website Builder: insecure deserialization
Live Composer - Free WordPress Website Builder · CVSS 8.8 · threat: High
Insecure deserialization in the Live Composer - Free WordPress Website Builder component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-16502.
Event Tickets and Registration: security vulnerability
Event Tickets and Registration · CVSS 7.5 · threat: High
Security vulnerability in the Event Tickets and Registration component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-3174.
EDD Product Catalog Feed by PixelYourSite: security vulnerability
EDD Product Catalog Feed by PixelYourSite · CVSS 7.1 · threat: High
Security vulnerability in the EDD Product Catalog Feed by PixelYourSite component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-9331.
WP Fusion (Pro): privilege escalation
WP Fusion (Pro) · CVSS 7.5 · threat: High
Privilege escalation in the WP Fusion (Pro) component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-14444.
User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor: cross-site scripting (XSS)
User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-6431.
You will find the full, continuously updated list on the Current threats page.
Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.