Website security: weekly review (21.09.2026)
A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.
Joomla: remote code execution (RCE)
Joomla · CVSS 9.4 · threat: Critical
Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).
Details and what to do: CVE-2026-88856.
Joomla: remote code execution (RCE)
Joomla · CVSS 9.4 · threat: Critical
Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).
Details and what to do: CVE-2026-88857.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-88854.
Joomla: SQL injection
Joomla · CVSS 8.6 · threat: High
SQL injection in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-88855.
Forminator Forms WordPress: security vulnerability
Forminator Forms WordPress · CVSS 8.5 · threat: High
Security vulnerability in the Forminator Forms WordPress component. Threat level: High (CVSS 8.5).
Details and what to do: CVE-2026-87067.
SAML Single Sign On WordPress: security vulnerability
SAML Single Sign On WordPress · CVSS 8.1 · threat: High
Security vulnerability in the SAML Single Sign On WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-82842.
Unlimited Elements For Elementor WordPress: security vulnerability
Unlimited Elements For Elementor WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Unlimited Elements For Elementor WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85017.
Tripzzy WordPress: security vulnerability
Tripzzy WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Tripzzy WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-87839.
Photo Gallery, Sliders, Proofing and WordPress: security vulnerability
Photo Gallery, Sliders, Proofing and WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Photo Gallery, Sliders, Proofing and WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-81650.
Import and export users and customers WordPress: security vulnerability
Import and export users and customers WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Import and export users and customers WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-92540.
Import and export users and customers WordPress: security vulnerability
Import and export users and customers WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Import and export users and customers WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-92541.
Gravity Forms: remote code execution (RCE)
Gravity Forms · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Gravity Forms component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-84434.
Botiga Pro WordPress: privilege escalation
Botiga Pro WordPress · CVSS 9.8 · threat: Critical
Privilege escalation in the Botiga Pro WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-86591.
WP Recipe Maker: remote code execution (RCE)
WP Recipe Maker · CVSS 9.1 · threat: Critical
Remote code execution (RCE) in the WP Recipe Maker component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-89274.
The Forminator Forms - Contact Form, Payment Form & Custom Form Builder: remote code execution (RCE)
The Forminator Forms - Contact Form, Payment Form & Custom Form Builder · CVSS 9.1 · threat: Critical
Remote code execution (RCE) in the The Forminator Forms - Contact Form, Payment Form & Custom Form Builder component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-92229.
Save as PDF Plugin by PDFCrowd: security vulnerability
Save as PDF Plugin by PDFCrowd · CVSS 8.8 · threat: High
Security vulnerability in the Save as PDF Plugin by PDFCrowd component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-92807.
Ultimate Member WordPress: security vulnerability
Ultimate Member WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Ultimate Member WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85680.
Master Blocks WordPress: cross-site scripting (XSS)
Master Blocks WordPress · CVSS 8.8 · threat: High
Cross-site scripting (XSS) in the Master Blocks WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-88824.
The Welcomizer: remote code execution (RCE)
The Welcomizer · CVSS 8.8 · threat: High
Remote code execution (RCE) in the The Welcomizer component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-4327.
VikRentItems Flexible Rental Management System WordPress: SQL injection
VikRentItems Flexible Rental Management System WordPress · CVSS 8.6 · threat: High
SQL injection in the VikRentItems Flexible Rental Management System WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-88926.
UsersWP WordPress: security vulnerability
UsersWP WordPress · CVSS 8.1 · threat: High
Security vulnerability in the UsersWP WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-86814.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress: remote code execution (RCE)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress · CVSS 8.1 · threat: High
Remote code execution (RCE) in the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-85658.
Unbounce Landing Pages WordPress: security vulnerability
Unbounce Landing Pages WordPress · CVSS 8 · threat: High
Security vulnerability in the Unbounce Landing Pages WordPress component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-85574.
WP Photo Album Plus: remote code execution (RCE)
WP Photo Album Plus · CVSS 7.5 · threat: High
Remote code execution (RCE) in the WP Photo Album Plus component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-87909.
MgoSync WordPress: security vulnerability
MgoSync WordPress · CVSS 7.5 · threat: High
Security vulnerability in the MgoSync WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-92404.
YS LeadGen: sensitive data disclosure
YS LeadGen · CVSS 7.5 · threat: High
Sensitive data disclosure in the YS LeadGen component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-1255.
Asset CleanUp: Page Speed Booster: cross-site scripting (XSS)
Asset CleanUp: Page Speed Booster · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Asset CleanUp: Page Speed Booster component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-13354.
WP Import Export Lite WordPress: security vulnerability
WP Import Export Lite WordPress · CVSS 7.2 · threat: High
Security vulnerability in the WP Import Export Lite WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-76554.
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes: cross-site scripting (XSS)
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Quill Forms | Conversational Multi Step Forms, Surveys & quizzes component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-15664.
Estatik Real Estate: cross-site scripting (XSS)
Estatik Real Estate · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Estatik Real Estate component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-76790.
AF Companion WordPress: remote code execution (RCE)
AF Companion WordPress · CVSS 9.1 · threat: Critical
Remote code execution (RCE) in the AF Companion WordPress component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-84738.
ShortPixel Image Optimizer - Optimize Images, Convert WebP & AVIF: insecure deserialization
ShortPixel Image Optimizer - Optimize Images, Convert WebP & AVIF · CVSS 8.8 · threat: High
Insecure deserialization in the ShortPixel Image Optimizer - Optimize Images, Convert WebP & AVIF component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-17086.
Easy Form Builder by WhiteStudio WordPress: cross-site scripting (XSS)
Easy Form Builder by WhiteStudio WordPress · CVSS 8.8 · threat: High
Cross-site scripting (XSS) in the Easy Form Builder by WhiteStudio WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85122.
VikBooking Hotel Booking Engine & PMS WordPress: security vulnerability
VikBooking Hotel Booking Engine & PMS WordPress · CVSS 8.8 · threat: High
Security vulnerability in the VikBooking Hotel Booking Engine & PMS WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85127.
iGMS Direct Booking WordPress: security vulnerability
iGMS Direct Booking WordPress · CVSS 8.8 · threat: High
Security vulnerability in the iGMS Direct Booking WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-88825.
Mapster WP Maps: privilege escalation
Mapster WP Maps · CVSS 8.8 · threat: High
Privilege escalation in the Mapster WP Maps component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-12954.
WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajaxnopriv, a missing capability check in can_import(), and the imported file's: remote code execution (RCE)
WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajaxnopriv, a missing capability check in can_import(), and the imported file's · CVSS 8.8 · threat: High
Remote code execution (RCE) in the WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajaxnopriv, a missing capability check in can_import(), and the imported file's component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-93031.
wp shortcut link and advertisement baner WordPress: SQL injection
wp shortcut link and advertisement baner WordPress · CVSS 8.6 · threat: High
SQL injection in the wp shortcut link and advertisement baner WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-87767.
Price Drop Alert for Woo Commerce WordPress: SQL injection
Price Drop Alert for Woo Commerce WordPress · CVSS 8.6 · threat: High
SQL injection in the Price Drop Alert for Woo Commerce WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-87770.
Product Question and Answer WordPress: SQL injection
Product Question and Answer WordPress · CVSS 8.6 · threat: High
SQL injection in the Product Question and Answer WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-87771.
Tz Weekly Radio Schedule WordPress: SQL injection
Tz Weekly Radio Schedule WordPress · CVSS 8.6 · threat: High
SQL injection in the Tz Weekly Radio Schedule WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-87774.
Tz Weekly Radio Schedule WordPress: SQL injection
Tz Weekly Radio Schedule WordPress · CVSS 8.6 · threat: High
SQL injection in the Tz Weekly Radio Schedule WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-87775.
Filter Gallery: security vulnerability
Filter Gallery · CVSS 8.1 · threat: High
Security vulnerability in the Filter Gallery component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-89413.
Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits: security vulnerability
Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits · CVSS 8.1 · threat: High
Security vulnerability in the Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-85410.
Printcart Web to Print Product Designer for WooCommerce: directory traversal
Printcart Web to Print Product Designer for WooCommerce · CVSS 7.5 · threat: High
Directory traversal in the Printcart Web to Print Product Designer for WooCommerce component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-14323.
WP Multi Store Locator Pro: SQL injection
WP Multi Store Locator Pro · CVSS 7.5 · threat: High
SQL injection in the WP Multi Store Locator Pro component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-15275.
WCFM Marketplace - Multivendor Marketplace for WooCommerce: SQL injection
WCFM Marketplace - Multivendor Marketplace for WooCommerce · CVSS 7.5 · threat: High
SQL injection in the WCFM Marketplace - Multivendor Marketplace for WooCommerce component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-18442.
Location Manager: SQL injection
Location Manager · CVSS 7.5 · threat: High
SQL injection in the Location Manager component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85705.
All-in-One WP Migration and Backup WordPress: security vulnerability
All-in-One WP Migration and Backup WordPress · CVSS 7.2 · threat: High
Security vulnerability in the All-in-One WP Migration and Backup WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-81810.
Booking Calendar: privilege escalation
Booking Calendar · CVSS 7.2 · threat: High
Privilege escalation in the Booking Calendar component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-92619.
Complianz GDPR/CCPA Cookie Consent Banner: cross-site scripting (XSS)
Complianz GDPR/CCPA Cookie Consent Banner · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Complianz GDPR/CCPA Cookie Consent Banner component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-83561.
Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress: cross-site scripting (XSS)
Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-18405.
Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder: cross-site scripting (XSS)
Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-87915.
Filter Gallery WordPress: security vulnerability
Filter Gallery WordPress · CVSS 7.1 · threat: High
Security vulnerability in the Filter Gallery WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-90978.
WordPress: cross-site scripting (XSS)
WordPress · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-93485.
Multi Uploader for Gravity Forms: remote code execution (RCE)
Multi Uploader for Gravity Forms · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Multi Uploader for Gravity Forms component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-87796.
Private Feed Key WordPress: security vulnerability
Private Feed Key WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the Private Feed Key WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-86707.
Pressengine WordPress: security vulnerability
Pressengine WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the Pressengine WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-86709.
Login with QR WordPress: security vulnerability
Login with QR WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the Login with QR WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-86710.
wpShopGermany IT-RECHT KANZLEI WordPress: remote code execution (RCE)
wpShopGermany IT-RECHT KANZLEI WordPress · CVSS 9 · threat: Critical
Remote code execution (RCE) in the wpShopGermany IT-RECHT KANZLEI WordPress component. Threat level: Critical (CVSS 9).
Details and what to do: CVE-2026-88795.
WPLP Cookie Consent WordPress: security vulnerability
WPLP Cookie Consent WordPress · CVSS 8.8 · threat: High
Security vulnerability in the WPLP Cookie Consent WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85130.
Dewa Kirim WordPress: security vulnerability
Dewa Kirim WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Dewa Kirim WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-87786.
Dictionary WordPress: security vulnerability
Dictionary WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Dictionary WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-88792.
PuppyFW WordPress: security vulnerability
PuppyFW WordPress · CVSS 8.8 · threat: High
Security vulnerability in the PuppyFW WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-88904.
To Do List Member WordPress: arbitrary file upload
To Do List Member WordPress · CVSS 8.8 · threat: High
Arbitrary file upload in the To Do List Member WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-86801.
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress: remote code execution (RCE)
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress · CVSS 8.8 · threat: High
Remote code execution (RCE) in the Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-54239.
Yo WordPress: SQL injection
Yo WordPress · CVSS 8.6 · threat: High
SQL injection in the Yo WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-87963.
Paid Downloads: remote code execution (RCE)
Paid Downloads · CVSS 8.1 · threat: High
Remote code execution (RCE) in the Paid Downloads component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-87935.
Choose User Role at Registration WordPress: security vulnerability
Choose User Role at Registration WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Choose User Role at Registration WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85128.
Dictionary WordPress: cross-site scripting (XSS)
Dictionary WordPress · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Dictionary WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2025-15697.
Realtyna Organic IDX: cross-site scripting (XSS)
Realtyna Organic IDX · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Realtyna Organic IDX component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-91014.
JetFormBuilder: Dynamic Blocks Form Builder: privilege escalation
JetFormBuilder: Dynamic Blocks Form Builder · CVSS 9.8 · threat: Critical
Privilege escalation in the JetFormBuilder: Dynamic Blocks Form Builder component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-12793.
TrueBooker - Appointment Booking and Scheduler System: security vulnerability
TrueBooker - Appointment Booking and Scheduler System · CVSS 9.8 · threat: Critical
Security vulnerability in the TrueBooker - Appointment Booking and Scheduler System component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-14349.
Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe: remote code execution (RCE)
Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe · CVSS 8.8 · threat: High
Remote code execution (RCE) in the Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-78088.
WP Import Export Lite WordPress: remote code execution (RCE)
WP Import Export Lite WordPress · CVSS 8.8 · threat: High
Remote code execution (RCE) in the WP Import Export Lite WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-76552.
Optimole WordPress: cross-site scripting (XSS)
Optimole WordPress · CVSS 8.8 · threat: High
Cross-site scripting (XSS) in the Optimole WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-84829.
Ni WooCommerce Sales Report WordPress: SQL injection
Ni WooCommerce Sales Report WordPress · CVSS 8.6 · threat: High
SQL injection in the Ni WooCommerce Sales Report WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-78472.
GiveWP WordPress: security vulnerability
GiveWP WordPress · CVSS 8.1 · threat: High
Security vulnerability in the GiveWP WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-85530.
Online Scheduling and Appointment Booking System - Bookly: security vulnerability
Online Scheduling and Appointment Booking System - Bookly · CVSS 7.5 · threat: High
Security vulnerability in the Online Scheduling and Appointment Booking System - Bookly component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-89063.
WP-Lister Lite for eBay: cross-site scripting (XSS)
WP-Lister Lite for eBay · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WP-Lister Lite for eBay component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-18595.
WP Import Export Lite WordPress: remote code execution (RCE)
WP Import Export Lite WordPress · CVSS 7.2 · threat: High
Remote code execution (RCE) in the WP Import Export Lite WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-76550.
WP Import Export Lite WordPress: remote code execution (RCE)
WP Import Export Lite WordPress · CVSS 7.2 · threat: High
Remote code execution (RCE) in the WP Import Export Lite WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-76551.
Tutor LMS WordPress: security vulnerability
Tutor LMS WordPress · CVSS 7.2 · threat: High
Security vulnerability in the Tutor LMS WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-85569.
MultiVendorX WordPress: security vulnerability
MultiVendorX WordPress · CVSS 7.1 · threat: High
Security vulnerability in the MultiVendorX WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-74926.
LearnPress WordPress: security vulnerability
LearnPress WordPress · CVSS 7.1 · threat: High
Security vulnerability in the LearnPress WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-86444.
Consulting: privilege escalation
Consulting · CVSS 8.8 · threat: High
Privilege escalation in the Consulting component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-14805.
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia: directory traversal
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia · CVSS 8.7 · threat: High
Directory traversal in the A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-87791.
"Design Scuole Italia" WordPress: security vulnerability
"Design Scuole Italia" WordPress · CVSS 8.7 · threat: High
Security vulnerability in the "Design Scuole Italia" WordPress component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-87792.
Joomla: SQL injection
Joomla · CVSS 8.7 · threat: High
SQL injection in the Joomla component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-81567.
Joomla: CSRF (request forgery)
Joomla · CVSS 8.7 · threat: High
CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-81568.
Joomla: security vulnerability
Joomla · CVSS 8.7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-82189.
Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce: remote code execution (RCE)
Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce · CVSS 7.5 · threat: High
Remote code execution (RCE) in the Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-75983.
MotoPress Hotel Booking: cross-site scripting (XSS)
MotoPress Hotel Booking · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the MotoPress Hotel Booking component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-90650.
Joomla: CSRF (request forgery)
Joomla · CVSS 7.1 · threat: High
CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-78081.
Joomla: remote code execution (RCE)
Joomla · CVSS 9.4 · threat: Critical
Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).
Details and what to do: CVE-2026-85192.
ThemeAtelier Domain For Sale: security vulnerability
ThemeAtelier Domain For Sale · CVSS 8.6 · threat: High
Security vulnerability in the ThemeAtelier Domain For Sale component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-89023.
Joomla: SQL injection
Joomla · CVSS 8.6 · threat: High
SQL injection in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-78375.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85189.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85190.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85191.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85195.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-88852.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-88853.
Joomla: security vulnerability
Joomla · CVSS 7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 7).
Details and what to do: CVE-2026-81564.
You will find the full, continuously updated list on the Current threats page.
Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.