Security

Website security: weekly review (28.09.2026)

Website security: weekly review (28.09.2026)

A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.

Joomla: security vulnerability

Joomla · CVSS 7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 7).

Details and what to do: CVE-2026-97164.

Joomla: security vulnerability

Joomla · CVSS 10 · threat: Critical

Security vulnerability in the Joomla component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-97163.

Request a Quote for WooCommerce: arbitrary file upload

Request a Quote for WooCommerce · CVSS 9.8 · threat: Critical

Arbitrary file upload in the Request a Quote for WooCommerce component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-18143.

miniOrange OTP Login, Verification and SMS Notifications: authentication bypass

miniOrange OTP Login, Verification and SMS Notifications · CVSS 9.8 · threat: Critical

Authentication bypass in the miniOrange OTP Login, Verification and SMS Notifications component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-85984.

Ultra Addons for Contact Form 7: remote code execution (RCE)

Ultra Addons for Contact Form 7 · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Ultra Addons for Contact Form 7 component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-82901.

Joomla: remote code execution (RCE)

Joomla · CVSS 9.5 · threat: Critical

Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.5).

Details and what to do: CVE-2026-94132.

Joomla: remote code execution (RCE)

Joomla · CVSS 9.4 · threat: Critical

Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).

Details and what to do: CVE-2026-97160.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-94130.

Joomla: directory traversal

Joomla · CVSS 9.2 · threat: Critical

Directory traversal in the Joomla component. Threat level: Critical (CVSS 9.2).

Details and what to do: CVE-2026-97161.

MCP Server for WordPress WordPress: security vulnerability

MCP Server for WordPress WordPress · CVSS 8.8 · threat: High

Security vulnerability in the MCP Server for WordPress WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-96524.

Groups - Memberships and Access Control: privilege escalation

Groups - Memberships and Access Control · CVSS 8.8 · threat: High

Privilege escalation in the Groups - Memberships and Access Control component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-77203.

Joomla: arbitrary file deletion

Joomla · CVSS 8.3 · threat: High

Arbitrary file deletion in the Joomla component. Threat level: High (CVSS 8.3).

Details and what to do: CVE-2026-94131.

Joomla: SQL injection

Joomla · CVSS 8.3 · threat: High

SQL injection in the Joomla component. Threat level: High (CVSS 8.3).

Details and what to do: CVE-2026-97162.

wp-review-slider-pro WordPress: cross-site scripting (XSS)

wp-review-slider-pro WordPress · CVSS 8 · threat: High

Cross-site scripting (XSS) in the wp-review-slider-pro WordPress component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-84095.

wp-review-slider-pro WordPress: cross-site scripting (XSS)

wp-review-slider-pro WordPress · CVSS 8 · threat: High

Cross-site scripting (XSS) in the wp-review-slider-pro WordPress component. Threat level: High (CVSS 8).

Details and what to do: CVE-2026-84096.

File Manager WordPress: security vulnerability

File Manager WordPress · CVSS 7.5 · threat: High

Security vulnerability in the File Manager WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-85081.

Testimonials Widget WordPress: security vulnerability

Testimonials Widget WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Testimonials Widget WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-96532.

WP Directory Kit WordPress: cross-site scripting (XSS)

WP Directory Kit WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WP Directory Kit WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-16591.

Automation Web Platform - Notifications and OTP for WooCommerce, Advanced Country Code: privilege escalation

Automation Web Platform - Notifications and OTP for WooCommerce, Advanced Country Code · CVSS 9.8 · threat: Critical

Privilege escalation in the Automation Web Platform - Notifications and OTP for WooCommerce, Advanced Country Code component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-14281.

Customer Reviews for WooCommerce: security vulnerability

Customer Reviews for WooCommerce · CVSS 9.1 · threat: Critical

Security vulnerability in the Customer Reviews for WooCommerce component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-89055.

Bookly: security vulnerability

Bookly · CVSS 9.1 · threat: Critical

Security vulnerability in the Bookly component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-93399.

s2Member - Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions: remote code execution (RCE)

s2Member - Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions · CVSS 8.8 · threat: High

Remote code execution (RCE) in the s2Member - Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-19804.

Knit Pay - Cashfree, Instamojo, Razorpay, PayPal and more: privilege escalation

Knit Pay - Cashfree, Instamojo, Razorpay, PayPal and more · CVSS 8.8 · threat: High

Privilege escalation in the Knit Pay - Cashfree, Instamojo, Razorpay, PayPal and more component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-89426.

Modula Image Gallery - Photo Grid & Video Gallery: arbitrary file deletion

Modula Image Gallery - Photo Grid & Video Gallery · CVSS 8.1 · threat: High

Arbitrary file deletion in the Modula Image Gallery - Photo Grid & Video Gallery component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-92713.

WP Maps - Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters: remote code execution (RCE)

WP Maps - Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters · CVSS 7.5 · threat: High

Remote code execution (RCE) in the WP Maps - Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-13456.

Modula Image Gallery - Photo Grid & Video Gallery: security vulnerability

Modula Image Gallery - Photo Grid & Video Gallery · CVSS 7.5 · threat: High

Security vulnerability in the Modula Image Gallery - Photo Grid & Video Gallery component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-89406.

Optima Express IDX: privilege escalation

Optima Express IDX · CVSS 7.3 · threat: High

Privilege escalation in the Optima Express IDX component. Threat level: High (CVSS 7.3).

Details and what to do: CVE-2026-93901.

AMP for WP - Accelerated Mobile Pages: cross-site scripting (XSS)

AMP for WP - Accelerated Mobile Pages · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the AMP for WP - Accelerated Mobile Pages component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-83591.

Fancy Product Designer: cross-site scripting (XSS)

Fancy Product Designer · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Fancy Product Designer component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-84279.

Fancy Product Designer: cross-site scripting (XSS)

Fancy Product Designer · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Fancy Product Designer component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-84281.

HT Contact Form - Drag & Drop Form Builder for WordPress: cross-site scripting (XSS)

HT Contact Form - Drag & Drop Form Builder for WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the HT Contact Form - Drag & Drop Form Builder for WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93303.

BA Book Everything: cross-site scripting (XSS)

BA Book Everything · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the BA Book Everything component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96039.

Fancy Product Designer: cross-site scripting (XSS)

Fancy Product Designer · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Fancy Product Designer component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-84280.

Premium Packages - Sell Digital Products Securely: cross-site scripting (XSS)

Premium Packages - Sell Digital Products Securely · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Premium Packages - Sell Digital Products Securely component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93654.

Repeater Fields for Elementor Forms: cross-site scripting (XSS)

Repeater Fields for Elementor Forms · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Repeater Fields for Elementor Forms component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-94573.

Themify Builder: cross-site scripting (XSS)

Themify Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Themify Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-95864.

User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor: cross-site scripting (XSS)

User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-95866.

Restaurant Menu and Food Ordering: cross-site scripting (XSS)

Restaurant Menu and Food Ordering · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Restaurant Menu and Food Ordering component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96568.

Zero Spam for WordPress: cross-site scripting (XSS)

Zero Spam for WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Zero Spam for WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96752.

Paytium: Mollie payment forms & donations: privilege escalation

Paytium: Mollie payment forms & donations · CVSS 9.8 · threat: Critical

Privilege escalation in the Paytium: Mollie payment forms & donations component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-18467.

Visual Composer Website Builder: remote code execution (RCE)

Visual Composer Website Builder · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Visual Composer Website Builder component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-12227.

YOP Poll: account takeover

YOP Poll · CVSS 8.8 · threat: High

Account takeover in the YOP Poll component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85682.

wpForo Forum WordPress: remote code execution (RCE)

wpForo Forum WordPress · CVSS 7.5 · threat: High

Remote code execution (RCE) in the wpForo Forum WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-80513.

eesy_ID2WP - Publish InDesign HTML5: directory traversal

eesy_ID2WP - Publish InDesign HTML5 · CVSS 7.5 · threat: High

Directory traversal in the eesy_ID2WP - Publish InDesign HTML5 component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-77193.

MasterStudy LMS WordPress: security vulnerability

MasterStudy LMS WordPress · CVSS 7.2 · threat: High

Security vulnerability in the MasterStudy LMS WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-88843.

YAHMAN Add-ons WordPress: security vulnerability

YAHMAN Add-ons WordPress · CVSS 9 · threat: Critical

Security vulnerability in the YAHMAN Add-ons WordPress component. Threat level: Critical (CVSS 9).

Details and what to do: CVE-2026-75799.

WP OAuth Server ( Login with WordPress ) WordPress: security vulnerability

WP OAuth Server ( Login with WordPress ) WordPress · CVSS 9 · threat: Critical

Security vulnerability in the WP OAuth Server ( Login with WordPress ) WordPress component. Threat level: Critical (CVSS 9).

Details and what to do: CVE-2026-82843.

Import and export users and customers: privilege escalation

Import and export users and customers · CVSS 8.8 · threat: High

Privilege escalation in the Import and export users and customers component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-86583.

Joomla: SQL injection

Joomla · CVSS 8.6 · threat: High

SQL injection in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-90901.

Joomla: security vulnerability

Joomla · CVSS 8.6 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-90904.

divi-dash WordPress: security vulnerability

divi-dash WordPress · CVSS 8.2 · threat: High

Security vulnerability in the divi-dash WordPress component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2026-14321.

WP Recipe Maker WordPress: security vulnerability

WP Recipe Maker WordPress · CVSS 8.2 · threat: High

Security vulnerability in the WP Recipe Maker WordPress component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2026-86608.

Joomla: security vulnerability

Joomla · CVSS 8.2 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2026-90899.

Joomla: SQL injection

Joomla · CVSS 8.2 · threat: High

SQL injection in the Joomla component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2026-90902.

WC Fields Factory WordPress: security vulnerability

WC Fields Factory WordPress · CVSS 8.1 · threat: High

Security vulnerability in the WC Fields Factory WordPress component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-93508.

EthPress - Web3 Login: authentication bypass

EthPress - Web3 Login · CVSS 8.1 · threat: High

Authentication bypass in the EthPress - Web3 Login component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-19125.

Rename wp-login.php to anything you want: SQL injection

Rename wp-login.php to anything you want · CVSS 7.5 · threat: High

SQL injection in the Rename wp-login.php to anything you want component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-93368.

WordPress: security vulnerability

WordPress · CVSS 7.5 · threat: High

Security vulnerability in the WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-95513.

Joomla: CSRF (request forgery)

Joomla · CVSS 7.2 · threat: High

CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-90903.

Joomla: CSRF (request forgery)

Joomla · CVSS 7.2 · threat: High

CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-90905.

Meta Box AIO: privilege escalation

Meta Box AIO · CVSS 9.8 · threat: Critical

Privilege escalation in the Meta Box AIO component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-13355.

Give Tributes: insecure deserialization

Give Tributes · CVSS 9.8 · threat: Critical

Insecure deserialization in the Give Tributes component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-19658.

Ninja Forms WordPress: security vulnerability

Ninja Forms WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Ninja Forms WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-92438.

BM Content Builder: remote code execution (RCE)

BM Content Builder · CVSS 8.8 · threat: High

Remote code execution (RCE) in the BM Content Builder component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2025-1281.

The WP Ultimate Review: remote code execution (RCE)

The WP Ultimate Review · CVSS 8.1 · threat: High

Remote code execution (RCE) in the The WP Ultimate Review component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-92235.

HUSKY - Products Filter for WooCommerce Professional: remote code execution (RCE)

HUSKY - Products Filter for WooCommerce Professional · CVSS 8.1 · threat: High

Remote code execution (RCE) in the HUSKY - Products Filter for WooCommerce Professional component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-92969.

HashBar - WordPress Notification Bar: SQL injection

HashBar - WordPress Notification Bar · CVSS 7.6 · threat: High

SQL injection in the HashBar - WordPress Notification Bar component. Threat level: High (CVSS 7.6).

Details and what to do: CVE-2026-94117.

Ninja Forms WordPress: remote code execution (RCE)

Ninja Forms WordPress · CVSS 7.5 · threat: High

Remote code execution (RCE) in the Ninja Forms WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-91827.

WP Travel Engine - Tour Booking Plugin - Tour Operator Software: remote code execution (RCE)

WP Travel Engine - Tour Booking Plugin - Tour Operator Software · CVSS 7.5 · threat: High

Remote code execution (RCE) in the WP Travel Engine - Tour Booking Plugin - Tour Operator Software component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-9231.

CMP - Coming Soon & Maintenance Plugin by NiteoThemes: privilege escalation

CMP - Coming Soon & Maintenance Plugin by NiteoThemes · CVSS 7.2 · threat: High

Privilege escalation in the CMP - Coming Soon & Maintenance Plugin by NiteoThemes component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-12470.

TranslatePress - Translate Multilingual sites with AI Translation: cross-site scripting (XSS)

TranslatePress - Translate Multilingual sites with AI Translation · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the TranslatePress - Translate Multilingual sites with AI Translation component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-89412.

WordPress: security vulnerability

WordPress · CVSS 7.2 · threat: High

Security vulnerability in the WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-94504.

WP Yelp Review Slider: cross-site scripting (XSS)

WP Yelp Review Slider · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WP Yelp Review Slider component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93778.

WPC Product Bundles for WooCommerce: cross-site scripting (XSS)

WPC Product Bundles for WooCommerce · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WPC Product Bundles for WooCommerce component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93836.

WP Table Builder - Drag & Drop Table Builder: security vulnerability

WP Table Builder - Drag & Drop Table Builder · CVSS 7.1 · threat: High

Security vulnerability in the WP Table Builder - Drag & Drop Table Builder component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-6922.

Web to Print Online Designer WordPress: security vulnerability

Web to Print Online Designer WordPress · CVSS 9.8 · threat: Critical

Security vulnerability in the Web to Print Online Designer WordPress component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-82187.


You will find the full, continuously updated list on the Current threats page.

Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.