Security

Website security: weekly review (21.09.2026)

Website security: weekly review (21.09.2026)

A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.

Joomla: remote code execution (RCE)

Joomla · CVSS 9.4 · threat: Critical

Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).

Details and what to do: CVE-2026-88856.

Joomla: remote code execution (RCE)

Joomla · CVSS 9.4 · threat: Critical

Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).

Details and what to do: CVE-2026-88857.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-88854.

Joomla: SQL injection

Joomla · CVSS 8.6 · threat: High

SQL injection in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-88855.

Forminator Forms WordPress: security vulnerability

Forminator Forms WordPress · CVSS 8.5 · threat: High

Security vulnerability in the Forminator Forms WordPress component. Threat level: High (CVSS 8.5).

Details and what to do: CVE-2026-87067.

SAML Single Sign On WordPress: security vulnerability

SAML Single Sign On WordPress · CVSS 8.1 · threat: High

Security vulnerability in the SAML Single Sign On WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-82842.

Unlimited Elements For Elementor WordPress: security vulnerability

Unlimited Elements For Elementor WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Unlimited Elements For Elementor WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85017.

Tripzzy WordPress: security vulnerability

Tripzzy WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Tripzzy WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-87839.

Photo Gallery, Sliders, Proofing and WordPress: security vulnerability

Photo Gallery, Sliders, Proofing and WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Photo Gallery, Sliders, Proofing and WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-81650.

Import and export users and customers WordPress: security vulnerability

Import and export users and customers WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Import and export users and customers WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-92540.

Import and export users and customers WordPress: security vulnerability

Import and export users and customers WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Import and export users and customers WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-92541.

Gravity Forms: remote code execution (RCE)

Gravity Forms · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Gravity Forms component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-84434.

Botiga Pro WordPress: privilege escalation

Botiga Pro WordPress · CVSS 9.8 · threat: Critical

Privilege escalation in the Botiga Pro WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-86591.

WP Recipe Maker: remote code execution (RCE)

WP Recipe Maker · CVSS 9.1 · threat: Critical

Remote code execution (RCE) in the WP Recipe Maker component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-89274.

The Forminator Forms - Contact Form, Payment Form & Custom Form Builder: remote code execution (RCE)

The Forminator Forms - Contact Form, Payment Form & Custom Form Builder · CVSS 9.1 · threat: Critical

Remote code execution (RCE) in the The Forminator Forms - Contact Form, Payment Form & Custom Form Builder component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-92229.

Save as PDF Plugin by PDFCrowd: security vulnerability

Save as PDF Plugin by PDFCrowd · CVSS 8.8 · threat: High

Security vulnerability in the Save as PDF Plugin by PDFCrowd component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-92807.

Ultimate Member WordPress: security vulnerability

Ultimate Member WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Ultimate Member WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85680.

Master Blocks WordPress: cross-site scripting (XSS)

Master Blocks WordPress · CVSS 8.8 · threat: High

Cross-site scripting (XSS) in the Master Blocks WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-88824.

The Welcomizer: remote code execution (RCE)

The Welcomizer · CVSS 8.8 · threat: High

Remote code execution (RCE) in the The Welcomizer component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-4327.

VikRentItems Flexible Rental Management System WordPress: SQL injection

VikRentItems Flexible Rental Management System WordPress · CVSS 8.6 · threat: High

SQL injection in the VikRentItems Flexible Rental Management System WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-88926.

UsersWP WordPress: security vulnerability

UsersWP WordPress · CVSS 8.1 · threat: High

Security vulnerability in the UsersWP WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-86814.

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress: remote code execution (RCE)

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress · CVSS 8.1 · threat: High

Remote code execution (RCE) in the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-85658.

Unbounce Landing Pages WordPress: security vulnerability

Unbounce Landing Pages WordPress · CVSS 8 · threat: High

Security vulnerability in the Unbounce Landing Pages WordPress component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-85574.

WP Photo Album Plus: remote code execution (RCE)

WP Photo Album Plus · CVSS 7.5 · threat: High

Remote code execution (RCE) in the WP Photo Album Plus component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-87909.

MgoSync WordPress: security vulnerability

MgoSync WordPress · CVSS 7.5 · threat: High

Security vulnerability in the MgoSync WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-92404.

YS LeadGen: sensitive data disclosure

YS LeadGen · CVSS 7.5 · threat: High

Sensitive data disclosure in the YS LeadGen component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-1255.

Asset CleanUp: Page Speed Booster: cross-site scripting (XSS)

Asset CleanUp: Page Speed Booster · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Asset CleanUp: Page Speed Booster component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-13354.

WP Import Export Lite WordPress: security vulnerability

WP Import Export Lite WordPress · CVSS 7.2 · threat: High

Security vulnerability in the WP Import Export Lite WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-76554.

Quill Forms | Conversational Multi Step Forms, Surveys & quizzes: cross-site scripting (XSS)

Quill Forms | Conversational Multi Step Forms, Surveys & quizzes · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Quill Forms | Conversational Multi Step Forms, Surveys & quizzes component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-15664.

Estatik Real Estate: cross-site scripting (XSS)

Estatik Real Estate · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Estatik Real Estate component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-76790.

AF Companion WordPress: remote code execution (RCE)

AF Companion WordPress · CVSS 9.1 · threat: Critical

Remote code execution (RCE) in the AF Companion WordPress component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-84738.

ShortPixel Image Optimizer - Optimize Images, Convert WebP & AVIF: insecure deserialization

ShortPixel Image Optimizer - Optimize Images, Convert WebP & AVIF · CVSS 8.8 · threat: High

Insecure deserialization in the ShortPixel Image Optimizer - Optimize Images, Convert WebP & AVIF component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-17086.

Easy Form Builder by WhiteStudio WordPress: cross-site scripting (XSS)

Easy Form Builder by WhiteStudio WordPress · CVSS 8.8 · threat: High

Cross-site scripting (XSS) in the Easy Form Builder by WhiteStudio WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85122.

VikBooking Hotel Booking Engine & PMS WordPress: security vulnerability

VikBooking Hotel Booking Engine & PMS WordPress · CVSS 8.8 · threat: High

Security vulnerability in the VikBooking Hotel Booking Engine & PMS WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85127.

iGMS Direct Booking WordPress: security vulnerability

iGMS Direct Booking WordPress · CVSS 8.8 · threat: High

Security vulnerability in the iGMS Direct Booking WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-88825.

Mapster WP Maps: privilege escalation

Mapster WP Maps · CVSS 8.8 · threat: High

Privilege escalation in the Mapster WP Maps component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-12954.

WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajaxnopriv, a missing capability check in can_import(), and the imported file's: remote code execution (RCE)

WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajaxnopriv, a missing capability check in can_import(), and the imported file's · CVSS 8.8 · threat: High

Remote code execution (RCE) in the WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajaxnopriv, a missing capability check in can_import(), and the imported file's component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-93031.

wp shortcut link and advertisement baner WordPress: SQL injection

wp shortcut link and advertisement baner WordPress · CVSS 8.6 · threat: High

SQL injection in the wp shortcut link and advertisement baner WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-87767.

Price Drop Alert for Woo Commerce WordPress: SQL injection

Price Drop Alert for Woo Commerce WordPress · CVSS 8.6 · threat: High

SQL injection in the Price Drop Alert for Woo Commerce WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-87770.

Product Question and Answer WordPress: SQL injection

Product Question and Answer WordPress · CVSS 8.6 · threat: High

SQL injection in the Product Question and Answer WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-87771.

Tz Weekly Radio Schedule WordPress: SQL injection

Tz Weekly Radio Schedule WordPress · CVSS 8.6 · threat: High

SQL injection in the Tz Weekly Radio Schedule WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-87774.

Tz Weekly Radio Schedule WordPress: SQL injection

Tz Weekly Radio Schedule WordPress · CVSS 8.6 · threat: High

SQL injection in the Tz Weekly Radio Schedule WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-87775.

Filter Gallery: security vulnerability

Filter Gallery · CVSS 8.1 · threat: High

Security vulnerability in the Filter Gallery component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-89413.

Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits: security vulnerability

Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits · CVSS 8.1 · threat: High

Security vulnerability in the Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-85410.

Printcart Web to Print Product Designer for WooCommerce: directory traversal

Printcart Web to Print Product Designer for WooCommerce · CVSS 7.5 · threat: High

Directory traversal in the Printcart Web to Print Product Designer for WooCommerce component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-14323.

WP Multi Store Locator Pro: SQL injection

WP Multi Store Locator Pro · CVSS 7.5 · threat: High

SQL injection in the WP Multi Store Locator Pro component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-15275.

WCFM Marketplace - Multivendor Marketplace for WooCommerce: SQL injection

WCFM Marketplace - Multivendor Marketplace for WooCommerce · CVSS 7.5 · threat: High

SQL injection in the WCFM Marketplace - Multivendor Marketplace for WooCommerce component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-18442.

Location Manager: SQL injection

Location Manager · CVSS 7.5 · threat: High

SQL injection in the Location Manager component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85705.

All-in-One WP Migration and Backup WordPress: security vulnerability

All-in-One WP Migration and Backup WordPress · CVSS 7.2 · threat: High

Security vulnerability in the All-in-One WP Migration and Backup WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-81810.

Booking Calendar: privilege escalation

Booking Calendar · CVSS 7.2 · threat: High

Privilege escalation in the Booking Calendar component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-92619.

Complianz GDPR/CCPA Cookie Consent Banner: cross-site scripting (XSS)

Complianz GDPR/CCPA Cookie Consent Banner · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Complianz GDPR/CCPA Cookie Consent Banner component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-83561.

Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress: cross-site scripting (XSS)

Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-18405.

Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder: cross-site scripting (XSS)

Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-87915.

Filter Gallery WordPress: security vulnerability

Filter Gallery WordPress · CVSS 7.1 · threat: High

Security vulnerability in the Filter Gallery WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-90978.

WordPress: cross-site scripting (XSS)

WordPress · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-93485.

Multi Uploader for Gravity Forms: remote code execution (RCE)

Multi Uploader for Gravity Forms · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Multi Uploader for Gravity Forms component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-87796.

Private Feed Key WordPress: security vulnerability

Private Feed Key WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the Private Feed Key WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-86707.

Pressengine WordPress: security vulnerability

Pressengine WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the Pressengine WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-86709.

Login with QR WordPress: security vulnerability

Login with QR WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the Login with QR WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-86710.

wpShopGermany IT-RECHT KANZLEI WordPress: remote code execution (RCE)

wpShopGermany IT-RECHT KANZLEI WordPress · CVSS 9 · threat: Critical

Remote code execution (RCE) in the wpShopGermany IT-RECHT KANZLEI WordPress component. Threat level: Critical (CVSS 9).

Details and what to do: CVE-2026-88795.

WPLP Cookie Consent WordPress: security vulnerability

WPLP Cookie Consent WordPress · CVSS 8.8 · threat: High

Security vulnerability in the WPLP Cookie Consent WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85130.

Dewa Kirim WordPress: security vulnerability

Dewa Kirim WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Dewa Kirim WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-87786.

Dictionary WordPress: security vulnerability

Dictionary WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Dictionary WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-88792.

PuppyFW WordPress: security vulnerability

PuppyFW WordPress · CVSS 8.8 · threat: High

Security vulnerability in the PuppyFW WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-88904.

To Do List Member WordPress: arbitrary file upload

To Do List Member WordPress · CVSS 8.8 · threat: High

Arbitrary file upload in the To Do List Member WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-86801.

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress: remote code execution (RCE)

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress · CVSS 8.8 · threat: High

Remote code execution (RCE) in the Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-54239.

Yo WordPress: SQL injection

Yo WordPress · CVSS 8.6 · threat: High

SQL injection in the Yo WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-87963.

Paid Downloads: remote code execution (RCE)

Paid Downloads · CVSS 8.1 · threat: High

Remote code execution (RCE) in the Paid Downloads component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-87935.

Choose User Role at Registration WordPress: security vulnerability

Choose User Role at Registration WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Choose User Role at Registration WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85128.

Dictionary WordPress: cross-site scripting (XSS)

Dictionary WordPress · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Dictionary WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2025-15697.

Realtyna Organic IDX: cross-site scripting (XSS)

Realtyna Organic IDX · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Realtyna Organic IDX component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-91014.

JetFormBuilder: Dynamic Blocks Form Builder: privilege escalation

JetFormBuilder: Dynamic Blocks Form Builder · CVSS 9.8 · threat: Critical

Privilege escalation in the JetFormBuilder: Dynamic Blocks Form Builder component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-12793.

TrueBooker - Appointment Booking and Scheduler System: security vulnerability

TrueBooker - Appointment Booking and Scheduler System · CVSS 9.8 · threat: Critical

Security vulnerability in the TrueBooker - Appointment Booking and Scheduler System component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-14349.

Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe: remote code execution (RCE)

Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe · CVSS 8.8 · threat: High

Remote code execution (RCE) in the Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-78088.

WP Import Export Lite WordPress: remote code execution (RCE)

WP Import Export Lite WordPress · CVSS 8.8 · threat: High

Remote code execution (RCE) in the WP Import Export Lite WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-76552.

Optimole WordPress: cross-site scripting (XSS)

Optimole WordPress · CVSS 8.8 · threat: High

Cross-site scripting (XSS) in the Optimole WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-84829.

Ni WooCommerce Sales Report WordPress: SQL injection

Ni WooCommerce Sales Report WordPress · CVSS 8.6 · threat: High

SQL injection in the Ni WooCommerce Sales Report WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-78472.

GiveWP WordPress: security vulnerability

GiveWP WordPress · CVSS 8.1 · threat: High

Security vulnerability in the GiveWP WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-85530.

Online Scheduling and Appointment Booking System - Bookly: security vulnerability

Online Scheduling and Appointment Booking System - Bookly · CVSS 7.5 · threat: High

Security vulnerability in the Online Scheduling and Appointment Booking System - Bookly component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-89063.

WP-Lister Lite for eBay: cross-site scripting (XSS)

WP-Lister Lite for eBay · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WP-Lister Lite for eBay component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-18595.

WP Import Export Lite WordPress: remote code execution (RCE)

WP Import Export Lite WordPress · CVSS 7.2 · threat: High

Remote code execution (RCE) in the WP Import Export Lite WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-76550.

WP Import Export Lite WordPress: remote code execution (RCE)

WP Import Export Lite WordPress · CVSS 7.2 · threat: High

Remote code execution (RCE) in the WP Import Export Lite WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-76551.

Tutor LMS WordPress: security vulnerability

Tutor LMS WordPress · CVSS 7.2 · threat: High

Security vulnerability in the Tutor LMS WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-85569.

MultiVendorX WordPress: security vulnerability

MultiVendorX WordPress · CVSS 7.1 · threat: High

Security vulnerability in the MultiVendorX WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-74926.

LearnPress WordPress: security vulnerability

LearnPress WordPress · CVSS 7.1 · threat: High

Security vulnerability in the LearnPress WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-86444.

Consulting: privilege escalation

Consulting · CVSS 8.8 · threat: High

Privilege escalation in the Consulting component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-14805.

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia: directory traversal

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia · CVSS 8.7 · threat: High

Directory traversal in the A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-87791.

"Design Scuole Italia" WordPress: security vulnerability

"Design Scuole Italia" WordPress · CVSS 8.7 · threat: High

Security vulnerability in the "Design Scuole Italia" WordPress component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-87792.

Joomla: SQL injection

Joomla · CVSS 8.7 · threat: High

SQL injection in the Joomla component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-81567.

Joomla: CSRF (request forgery)

Joomla · CVSS 8.7 · threat: High

CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-81568.

Joomla: security vulnerability

Joomla · CVSS 8.7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-82189.

Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce: remote code execution (RCE)

Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce · CVSS 7.5 · threat: High

Remote code execution (RCE) in the Eventin - Event Calendar, Tickets, Registration, Booking & WooCommerce component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-75983.

MotoPress Hotel Booking: cross-site scripting (XSS)

MotoPress Hotel Booking · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the MotoPress Hotel Booking component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-90650.

Joomla: CSRF (request forgery)

Joomla · CVSS 7.1 · threat: High

CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-78081.

Joomla: remote code execution (RCE)

Joomla · CVSS 9.4 · threat: Critical

Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).

Details and what to do: CVE-2026-85192.

ThemeAtelier Domain For Sale: security vulnerability

ThemeAtelier Domain For Sale · CVSS 8.6 · threat: High

Security vulnerability in the ThemeAtelier Domain For Sale component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-89023.

Joomla: SQL injection

Joomla · CVSS 8.6 · threat: High

SQL injection in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-78375.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85189.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85190.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85191.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85195.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-88852.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-88853.

Joomla: security vulnerability

Joomla · CVSS 7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 7).

Details and what to do: CVE-2026-81564.


You will find the full, continuously updated list on the Current threats page.

Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.