Security

Website security: weekly review (14.09.2026)

Website security: weekly review (14.09.2026)

A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.

CryptoPayment Gateway WordPress: security vulnerability

CryptoPayment Gateway WordPress · CVSS 10 · threat: Critical

Security vulnerability in the CryptoPayment Gateway WordPress component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-81648.

GenieWords WordPress: security vulnerability

GenieWords WordPress · CVSS 8.8 · threat: High

Security vulnerability in the GenieWords WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-74933.

Hoo Companion WordPress: security vulnerability

Hoo Companion WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Hoo Companion WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85129.

YouTube Embed WordPress: security vulnerability

YouTube Embed WordPress · CVSS 8.8 · threat: High

Security vulnerability in the YouTube Embed WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-88793.

User Registration & Membership WordPress: privilege escalation

User Registration & Membership WordPress · CVSS 7.5 · threat: High

Privilege escalation in the User Registration & Membership WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-86406.

Really Simple Security WordPress: security vulnerability

Really Simple Security WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Really Simple Security WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-89080.

MDJM Event Management WordPress: security vulnerability

MDJM Event Management WordPress · CVSS 7.5 · threat: High

Security vulnerability in the MDJM Event Management WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-88802.

User Registration & Membership WordPress: security vulnerability

User Registration & Membership WordPress · CVSS 7.2 · threat: High

Security vulnerability in the User Registration & Membership WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-80071.

Masteriyo LMS WordPress: remote code execution (RCE)

Masteriyo LMS WordPress · CVSS 9.9 · threat: Critical

Remote code execution (RCE) in the Masteriyo LMS WordPress component. Threat level: Critical (CVSS 9.9).

Details and what to do: CVE-2026-82845.

Frontegg SAML SSO WordPress: security vulnerability

Frontegg SAML SSO WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the Frontegg SAML SSO WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-75800.

DS Ad Rotator WordPress: remote code execution (RCE)

DS Ad Rotator WordPress · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the DS Ad Rotator WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-81402.

WP images upload on piclect WordPress: security vulnerability

WP images upload on piclect WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the WP images upload on piclect WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-84171.

WP: security vulnerability

WP · CVSS 9.8 · threat: Critical

Security vulnerability in the WP component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-85681.

The Events Calendar: remote code execution (RCE)

The Events Calendar · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the The Events Calendar component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-78006.

The Events Calendar: remote code execution (RCE)

The Events Calendar · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the The Events Calendar component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-78159.

CODE MONKEYS PROPOSALS WordPress: security vulnerability

CODE MONKEYS PROPOSALS WordPress · CVSS 9.6 · threat: Critical

Security vulnerability in the CODE MONKEYS PROPOSALS WordPress component. Threat level: Critical (CVSS 9.6).

Details and what to do: CVE-2026-77005.

WebTotem Backups WordPress: CSRF (request forgery)

WebTotem Backups WordPress · CVSS 9.6 · threat: Critical

CSRF (request forgery) in the WebTotem Backups WordPress component. Threat level: Critical (CVSS 9.6).

Details and what to do: CVE-2026-77006.

BE REST Endpoints WordPress: security vulnerability

BE REST Endpoints WordPress · CVSS 8.8 · threat: High

Security vulnerability in the BE REST Endpoints WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-81742.

Add User Autocomplete WordPress: security vulnerability

Add User Autocomplete WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Add User Autocomplete WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-87759.

Tutor LMS - eLearning and online course solution: remote code execution (RCE)

Tutor LMS - eLearning and online course solution · CVSS 8.8 · threat: High

Remote code execution (RCE) in the Tutor LMS - eLearning and online course solution component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-78175.

MemberPress Corporate Accounts: privilege escalation

MemberPress Corporate Accounts · CVSS 8.8 · threat: High

Privilege escalation in the MemberPress Corporate Accounts component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-15451.

SAMO Forms WordPress: SQL injection

SAMO Forms WordPress · CVSS 8.6 · threat: High

SQL injection in the SAMO Forms WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-80491.

Yogeta WP Cloud WordPress: security vulnerability

Yogeta WP Cloud WordPress · CVSS 8.6 · threat: High

Security vulnerability in the Yogeta WP Cloud WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-80494.

Album Cover Finder WordPress: SQL injection

Album Cover Finder WordPress · CVSS 8.6 · threat: High

SQL injection in the Album Cover Finder WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-84047.

wpstorecart WordPress: security vulnerability

wpstorecart WordPress · CVSS 8.1 · threat: High

Security vulnerability in the wpstorecart WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-84099.

YayPricing WordPress: security vulnerability

YayPricing WordPress · CVSS 8 · threat: High

Security vulnerability in the YayPricing WordPress component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-87888.

Zonify WordPress: security vulnerability

Zonify WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Zonify WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-87842.

rtMedia for WordPress, BuddyPress and bbPress: SQL injection

rtMedia for WordPress, BuddyPress and bbPress · CVSS 7.5 · threat: High

SQL injection in the rtMedia for WordPress, BuddyPress and bbPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-16482.

GEO my WP: remote code execution (RCE)

GEO my WP · CVSS 7.5 · threat: High

Remote code execution (RCE) in the GEO my WP component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85200.

Booking for Appointments and Events Calendar WordPress: security vulnerability

Booking for Appointments and Events Calendar WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Booking for Appointments and Events Calendar WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-77705.

Temporary Login Without Password WordPress: security vulnerability

Temporary Login Without Password WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Temporary Login Without Password WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-77752.

Gpx2Graphics WordPress: remote code execution (RCE)

Gpx2Graphics WordPress · CVSS 7.2 · threat: High

Remote code execution (RCE) in the Gpx2Graphics WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-81090.

Export & Import WPBakery Page Builder WordPress: cross-site scripting (XSS)

Export & Import WPBakery Page Builder WordPress · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Export & Import WPBakery Page Builder WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-81429.

teddy-bear-customize-addon WordPress: security vulnerability

teddy-bear-customize-addon WordPress · CVSS 10 · threat: Critical

Security vulnerability in the teddy-bear-customize-addon WordPress component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-14560.

MIPL Grouped Checkout Fields for WooCommerce - Customize & Organize Checkout Fields.: remote code execution (RCE)

MIPL Grouped Checkout Fields for WooCommerce - Customize & Organize Checkout Fields. · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the MIPL Grouped Checkout Fields for WooCommerce - Customize & Organize Checkout Fields. component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-8778.

teddy-bear-customize-addon WordPress: security vulnerability

teddy-bear-customize-addon WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the teddy-bear-customize-addon WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-14559.

advanced-customized-prompts WordPress: security vulnerability

advanced-customized-prompts WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the advanced-customized-prompts WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-14563.

Gutenverse News WordPress: security vulnerability

Gutenverse News WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Gutenverse News WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85677.

UsersWP: arbitrary file deletion

UsersWP · CVSS 8.1 · threat: High

Arbitrary file deletion in the UsersWP component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-19991.

AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: directory traversal

AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress · CVSS 7.5 · threat: High

Directory traversal in the AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-77807.

Sticky Chat Widget: SQL injection

Sticky Chat Widget · CVSS 7.5 · threat: High

SQL injection in the Sticky Chat Widget component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-15462.

Unlimited Elements For Elementor: SQL injection

Unlimited Elements For Elementor · CVSS 7.5 · threat: High

SQL injection in the Unlimited Elements For Elementor component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-18561.

WP Photo Album Plus: cross-site scripting (XSS)

WP Photo Album Plus · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WP Photo Album Plus component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-18579.

Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…: cross-site scripting (XSS)

Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Vigilant - 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-81754.

Simple Ajax Chat - Add a Fast, Secure Chat Box: cross-site scripting (XSS)

Simple Ajax Chat - Add a Fast, Secure Chat Box · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Simple Ajax Chat - Add a Fast, Secure Chat Box component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-81825.

MultiVendorX WordPress: security vulnerability

MultiVendorX WordPress · CVSS 7.2 · threat: High

Security vulnerability in the MultiVendorX WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-74925.

Kirki - Freeform Page Builder, Website Builder & Customizer: cross-site scripting (XSS)

Kirki - Freeform Page Builder, Website Builder & Customizer · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Kirki - Freeform Page Builder, Website Builder & Customizer component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-17037.

miniOrange 2FA WordPress: security vulnerability

miniOrange 2FA WordPress · CVSS 10 · threat: Critical

Security vulnerability in the miniOrange 2FA WordPress component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-77770.

Drag and Drop File Upload for Elementor Forms: remote code execution (RCE)

Drag and Drop File Upload for Elementor Forms · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Drag and Drop File Upload for Elementor Forms component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-18351.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-78082.

zipMoney(Zip Co) Payments: security vulnerability

zipMoney(Zip Co) Payments · CVSS 9.1 · threat: Critical

Security vulnerability in the zipMoney(Zip Co) Payments component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-78361.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 8.6 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-78302.

Site Reviews WordPress: security vulnerability

Site Reviews WordPress · CVSS 8.1 · threat: High

Security vulnerability in the Site Reviews WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-82925.

Bulk Password Reset: account takeover

Bulk Password Reset · CVSS 8 · threat: High

Account takeover in the Bulk Password Reset component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-14873.

Direct Download for WooCommerce: directory traversal

Direct Download for WooCommerce · CVSS 7.5 · threat: High

Directory traversal in the Direct Download for WooCommerce component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-15019.

Ultimate Gift Cards for WooCommerce WordPress: security vulnerability

Ultimate Gift Cards for WooCommerce WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Ultimate Gift Cards for WooCommerce WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-19436.

Ultimate Gift Cards for WooCommerce WordPress: security vulnerability

Ultimate Gift Cards for WooCommerce WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Ultimate Gift Cards for WooCommerce WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-19439.

miniOrange 2FA WordPress: security vulnerability

miniOrange 2FA WordPress · CVSS 7.5 · threat: High

Security vulnerability in the miniOrange 2FA WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-77771.

Sidebar Manager Light: cross-site scripting (XSS)

Sidebar Manager Light · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Sidebar Manager Light component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-76562.

Registration Form for WooCommerce WordPress: security vulnerability

Registration Form for WooCommerce WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Registration Form for WooCommerce WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-81431.

Joomla: CSRF (request forgery)

Joomla · CVSS 7.1 · threat: High

CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-78083.

FireBox - WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment: remote code execution (RCE)

FireBox - WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment · CVSS 8.8 · threat: High

Remote code execution (RCE) in the FireBox - WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-76801.

YITH WooCommerce Waitlist Premium: privilege escalation

YITH WooCommerce Waitlist Premium · CVSS 8.8 · threat: High

Privilege escalation in the YITH WooCommerce Waitlist Premium component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-14359.

ELEX WooCommerce Request a Quote WordPress: SQL injection

ELEX WooCommerce Request a Quote WordPress · CVSS 8.6 · threat: High

SQL injection in the ELEX WooCommerce Request a Quote WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-14962.

Quentn WP WordPress: SQL injection

Quentn WP WordPress · CVSS 8.6 · threat: High

SQL injection in the Quentn WP WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-84068.

Next-Cart Store to WooCommerce Migration: arbitrary file deletion

Next-Cart Store to WooCommerce Migration · CVSS 8.1 · threat: High

Arbitrary file deletion in the Next-Cart Store to WooCommerce Migration component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-76009.

Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered): remote code execution (RCE)

Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 7.5 · threat: High

Remote code execution (RCE) in the Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-15406.

Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered): remote code execution (RCE)

Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 7.5 · threat: High

Remote code execution (RCE) in the Eventin - Event Calendar, Event Registration, Tickets & Booking (AI Powered) component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-15667.

Loops & Logic WordPress: security vulnerability

Loops & Logic WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Loops & Logic WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-16960.

Contact Form to DB by BestWebSoft - Messages Database: cross-site scripting (XSS)

Contact Form to DB by BestWebSoft - Messages Database · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Contact Form to DB by BestWebSoft - Messages Database component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-13359.

WP EasyCart: privilege escalation

WP EasyCart · CVSS 7.2 · threat: High

Privilege escalation in the WP EasyCart component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-17553.

Repeater Fields for Gravity Forms: cross-site scripting (XSS)

Repeater Fields for Gravity Forms · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Repeater Fields for Gravity Forms component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-84293.

WPBot - AI ChatBot for Live Support, Lead Generation, AI Services: cross-site scripting (XSS)

WPBot - AI ChatBot for Live Support, Lead Generation, AI Services · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-83593.

PublishPress Capabilities - User Role Editor, Access Permissions, User Capabilities, Admin Menus: privilege escalation

PublishPress Capabilities - User Role Editor, Access Permissions, User Capabilities, Admin Menus · CVSS 7.2 · threat: High

Privilege escalation in the PublishPress Capabilities - User Role Editor, Access Permissions, User Capabilities, Admin Menus component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-75927.

Cookie Banner for GDPR / CCPA - WPLP Cookie Consent: cross-site scripting (XSS)

Cookie Banner for GDPR / CCPA - WPLP Cookie Consent · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Cookie Banner for GDPR / CCPA - WPLP Cookie Consent component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-14989.

Rara One Click Demo Import: remote code execution (RCE)

Rara One Click Demo Import · CVSS 7.2 · threat: High

Remote code execution (RCE) in the Rara One Click Demo Import component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-26212.

Live Composer - Free WordPress Website Builder: insecure deserialization

Live Composer - Free WordPress Website Builder · CVSS 8.8 · threat: High

Insecure deserialization in the Live Composer - Free WordPress Website Builder component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-16502.

Event Tickets and Registration: security vulnerability

Event Tickets and Registration · CVSS 7.5 · threat: High

Security vulnerability in the Event Tickets and Registration component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-3174.

EDD Product Catalog Feed by PixelYourSite: security vulnerability

EDD Product Catalog Feed by PixelYourSite · CVSS 7.1 · threat: High

Security vulnerability in the EDD Product Catalog Feed by PixelYourSite component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-9331.

WP Fusion (Pro): privilege escalation

WP Fusion (Pro) · CVSS 7.5 · threat: High

Privilege escalation in the WP Fusion (Pro) component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-14444.

User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor: cross-site scripting (XSS)

User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-6431.


You will find the full, continuously updated list on the Current threats page.

Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.