Website security: weekly review (28.09.2026)
A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.
Joomla: security vulnerability
Joomla · CVSS 7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 7).
Details and what to do: CVE-2026-97164.
Joomla: security vulnerability
Joomla · CVSS 10 · threat: Critical
Security vulnerability in the Joomla component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-97163.
Request a Quote for WooCommerce: arbitrary file upload
Request a Quote for WooCommerce · CVSS 9.8 · threat: Critical
Arbitrary file upload in the Request a Quote for WooCommerce component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-18143.
miniOrange OTP Login, Verification and SMS Notifications: authentication bypass
miniOrange OTP Login, Verification and SMS Notifications · CVSS 9.8 · threat: Critical
Authentication bypass in the miniOrange OTP Login, Verification and SMS Notifications component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-85984.
Ultra Addons for Contact Form 7: remote code execution (RCE)
Ultra Addons for Contact Form 7 · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Ultra Addons for Contact Form 7 component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-82901.
Joomla: remote code execution (RCE)
Joomla · CVSS 9.5 · threat: Critical
Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.5).
Details and what to do: CVE-2026-94132.
Joomla: remote code execution (RCE)
Joomla · CVSS 9.4 · threat: Critical
Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 9.4).
Details and what to do: CVE-2026-97160.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-94130.
Joomla: directory traversal
Joomla · CVSS 9.2 · threat: Critical
Directory traversal in the Joomla component. Threat level: Critical (CVSS 9.2).
Details and what to do: CVE-2026-97161.
MCP Server for WordPress WordPress: security vulnerability
MCP Server for WordPress WordPress · CVSS 8.8 · threat: High
Security vulnerability in the MCP Server for WordPress WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-96524.
Groups - Memberships and Access Control: privilege escalation
Groups - Memberships and Access Control · CVSS 8.8 · threat: High
Privilege escalation in the Groups - Memberships and Access Control component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-77203.
Joomla: arbitrary file deletion
Joomla · CVSS 8.3 · threat: High
Arbitrary file deletion in the Joomla component. Threat level: High (CVSS 8.3).
Details and what to do: CVE-2026-94131.
Joomla: SQL injection
Joomla · CVSS 8.3 · threat: High
SQL injection in the Joomla component. Threat level: High (CVSS 8.3).
Details and what to do: CVE-2026-97162.
wp-review-slider-pro WordPress: cross-site scripting (XSS)
wp-review-slider-pro WordPress · CVSS 8 · threat: High
Cross-site scripting (XSS) in the wp-review-slider-pro WordPress component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-84095.
wp-review-slider-pro WordPress: cross-site scripting (XSS)
wp-review-slider-pro WordPress · CVSS 8 · threat: High
Cross-site scripting (XSS) in the wp-review-slider-pro WordPress component. Threat level: High (CVSS 8).
Details and what to do: CVE-2026-84096.
File Manager WordPress: security vulnerability
File Manager WordPress · CVSS 7.5 · threat: High
Security vulnerability in the File Manager WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-85081.
Testimonials Widget WordPress: security vulnerability
Testimonials Widget WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Testimonials Widget WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-96532.
WP Directory Kit WordPress: cross-site scripting (XSS)
WP Directory Kit WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WP Directory Kit WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-16591.
Automation Web Platform - Notifications and OTP for WooCommerce, Advanced Country Code: privilege escalation
Automation Web Platform - Notifications and OTP for WooCommerce, Advanced Country Code · CVSS 9.8 · threat: Critical
Privilege escalation in the Automation Web Platform - Notifications and OTP for WooCommerce, Advanced Country Code component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-14281.
Customer Reviews for WooCommerce: security vulnerability
Customer Reviews for WooCommerce · CVSS 9.1 · threat: Critical
Security vulnerability in the Customer Reviews for WooCommerce component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-89055.
Bookly: security vulnerability
Bookly · CVSS 9.1 · threat: Critical
Security vulnerability in the Bookly component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-93399.
s2Member - Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions: remote code execution (RCE)
s2Member - Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions · CVSS 8.8 · threat: High
Remote code execution (RCE) in the s2Member - Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-19804.
Knit Pay - Cashfree, Instamojo, Razorpay, PayPal and more: privilege escalation
Knit Pay - Cashfree, Instamojo, Razorpay, PayPal and more · CVSS 8.8 · threat: High
Privilege escalation in the Knit Pay - Cashfree, Instamojo, Razorpay, PayPal and more component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-89426.
Modula Image Gallery - Photo Grid & Video Gallery: arbitrary file deletion
Modula Image Gallery - Photo Grid & Video Gallery · CVSS 8.1 · threat: High
Arbitrary file deletion in the Modula Image Gallery - Photo Grid & Video Gallery component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-92713.
WP Maps - Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters: remote code execution (RCE)
WP Maps - Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters · CVSS 7.5 · threat: High
Remote code execution (RCE) in the WP Maps - Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-13456.
Modula Image Gallery - Photo Grid & Video Gallery: security vulnerability
Modula Image Gallery - Photo Grid & Video Gallery · CVSS 7.5 · threat: High
Security vulnerability in the Modula Image Gallery - Photo Grid & Video Gallery component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-89406.
Optima Express IDX: privilege escalation
Optima Express IDX · CVSS 7.3 · threat: High
Privilege escalation in the Optima Express IDX component. Threat level: High (CVSS 7.3).
Details and what to do: CVE-2026-93901.
AMP for WP - Accelerated Mobile Pages: cross-site scripting (XSS)
AMP for WP - Accelerated Mobile Pages · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the AMP for WP - Accelerated Mobile Pages component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-83591.
Fancy Product Designer: cross-site scripting (XSS)
Fancy Product Designer · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Fancy Product Designer component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-84279.
Fancy Product Designer: cross-site scripting (XSS)
Fancy Product Designer · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Fancy Product Designer component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-84281.
HT Contact Form - Drag & Drop Form Builder for WordPress: cross-site scripting (XSS)
HT Contact Form - Drag & Drop Form Builder for WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the HT Contact Form - Drag & Drop Form Builder for WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93303.
BA Book Everything: cross-site scripting (XSS)
BA Book Everything · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the BA Book Everything component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96039.
Fancy Product Designer: cross-site scripting (XSS)
Fancy Product Designer · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Fancy Product Designer component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-84280.
Premium Packages - Sell Digital Products Securely: cross-site scripting (XSS)
Premium Packages - Sell Digital Products Securely · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Premium Packages - Sell Digital Products Securely component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93654.
Repeater Fields for Elementor Forms: cross-site scripting (XSS)
Repeater Fields for Elementor Forms · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Repeater Fields for Elementor Forms component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-94573.
Themify Builder: cross-site scripting (XSS)
Themify Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Themify Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-95864.
User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor: cross-site scripting (XSS)
User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-95866.
Restaurant Menu and Food Ordering: cross-site scripting (XSS)
Restaurant Menu and Food Ordering · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Restaurant Menu and Food Ordering component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96568.
Zero Spam for WordPress: cross-site scripting (XSS)
Zero Spam for WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Zero Spam for WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96752.
Paytium: Mollie payment forms & donations: privilege escalation
Paytium: Mollie payment forms & donations · CVSS 9.8 · threat: Critical
Privilege escalation in the Paytium: Mollie payment forms & donations component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-18467.
Visual Composer Website Builder: remote code execution (RCE)
Visual Composer Website Builder · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Visual Composer Website Builder component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-12227.
YOP Poll: account takeover
YOP Poll · CVSS 8.8 · threat: High
Account takeover in the YOP Poll component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85682.
wpForo Forum WordPress: remote code execution (RCE)
wpForo Forum WordPress · CVSS 7.5 · threat: High
Remote code execution (RCE) in the wpForo Forum WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-80513.
eesy_ID2WP - Publish InDesign HTML5: directory traversal
eesy_ID2WP - Publish InDesign HTML5 · CVSS 7.5 · threat: High
Directory traversal in the eesy_ID2WP - Publish InDesign HTML5 component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-77193.
MasterStudy LMS WordPress: security vulnerability
MasterStudy LMS WordPress · CVSS 7.2 · threat: High
Security vulnerability in the MasterStudy LMS WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-88843.
YAHMAN Add-ons WordPress: security vulnerability
YAHMAN Add-ons WordPress · CVSS 9 · threat: Critical
Security vulnerability in the YAHMAN Add-ons WordPress component. Threat level: Critical (CVSS 9).
Details and what to do: CVE-2026-75799.
WP OAuth Server ( Login with WordPress ) WordPress: security vulnerability
WP OAuth Server ( Login with WordPress ) WordPress · CVSS 9 · threat: Critical
Security vulnerability in the WP OAuth Server ( Login with WordPress ) WordPress component. Threat level: Critical (CVSS 9).
Details and what to do: CVE-2026-82843.
Import and export users and customers: privilege escalation
Import and export users and customers · CVSS 8.8 · threat: High
Privilege escalation in the Import and export users and customers component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-86583.
Joomla: SQL injection
Joomla · CVSS 8.6 · threat: High
SQL injection in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-90901.
Joomla: security vulnerability
Joomla · CVSS 8.6 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-90904.
divi-dash WordPress: security vulnerability
divi-dash WordPress · CVSS 8.2 · threat: High
Security vulnerability in the divi-dash WordPress component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2026-14321.
WP Recipe Maker WordPress: security vulnerability
WP Recipe Maker WordPress · CVSS 8.2 · threat: High
Security vulnerability in the WP Recipe Maker WordPress component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2026-86608.
Joomla: security vulnerability
Joomla · CVSS 8.2 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2026-90899.
Joomla: SQL injection
Joomla · CVSS 8.2 · threat: High
SQL injection in the Joomla component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2026-90902.
WC Fields Factory WordPress: security vulnerability
WC Fields Factory WordPress · CVSS 8.1 · threat: High
Security vulnerability in the WC Fields Factory WordPress component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-93508.
EthPress - Web3 Login: authentication bypass
EthPress - Web3 Login · CVSS 8.1 · threat: High
Authentication bypass in the EthPress - Web3 Login component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-19125.
Rename wp-login.php to anything you want: SQL injection
Rename wp-login.php to anything you want · CVSS 7.5 · threat: High
SQL injection in the Rename wp-login.php to anything you want component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-93368.
WordPress: security vulnerability
WordPress · CVSS 7.5 · threat: High
Security vulnerability in the WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-95513.
Joomla: CSRF (request forgery)
Joomla · CVSS 7.2 · threat: High
CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-90903.
Joomla: CSRF (request forgery)
Joomla · CVSS 7.2 · threat: High
CSRF (request forgery) in the Joomla component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-90905.
Meta Box AIO: privilege escalation
Meta Box AIO · CVSS 9.8 · threat: Critical
Privilege escalation in the Meta Box AIO component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-13355.
Give Tributes: insecure deserialization
Give Tributes · CVSS 9.8 · threat: Critical
Insecure deserialization in the Give Tributes component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-19658.
Ninja Forms WordPress: security vulnerability
Ninja Forms WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Ninja Forms WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-92438.
BM Content Builder: remote code execution (RCE)
BM Content Builder · CVSS 8.8 · threat: High
Remote code execution (RCE) in the BM Content Builder component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2025-1281.
The WP Ultimate Review: remote code execution (RCE)
The WP Ultimate Review · CVSS 8.1 · threat: High
Remote code execution (RCE) in the The WP Ultimate Review component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-92235.
HUSKY - Products Filter for WooCommerce Professional: remote code execution (RCE)
HUSKY - Products Filter for WooCommerce Professional · CVSS 8.1 · threat: High
Remote code execution (RCE) in the HUSKY - Products Filter for WooCommerce Professional component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-92969.
HashBar - WordPress Notification Bar: SQL injection
HashBar - WordPress Notification Bar · CVSS 7.6 · threat: High
SQL injection in the HashBar - WordPress Notification Bar component. Threat level: High (CVSS 7.6).
Details and what to do: CVE-2026-94117.
Ninja Forms WordPress: remote code execution (RCE)
Ninja Forms WordPress · CVSS 7.5 · threat: High
Remote code execution (RCE) in the Ninja Forms WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-91827.
WP Travel Engine - Tour Booking Plugin - Tour Operator Software: remote code execution (RCE)
WP Travel Engine - Tour Booking Plugin - Tour Operator Software · CVSS 7.5 · threat: High
Remote code execution (RCE) in the WP Travel Engine - Tour Booking Plugin - Tour Operator Software component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-9231.
CMP - Coming Soon & Maintenance Plugin by NiteoThemes: privilege escalation
CMP - Coming Soon & Maintenance Plugin by NiteoThemes · CVSS 7.2 · threat: High
Privilege escalation in the CMP - Coming Soon & Maintenance Plugin by NiteoThemes component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-12470.
TranslatePress - Translate Multilingual sites with AI Translation: cross-site scripting (XSS)
TranslatePress - Translate Multilingual sites with AI Translation · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the TranslatePress - Translate Multilingual sites with AI Translation component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-89412.
WordPress: security vulnerability
WordPress · CVSS 7.2 · threat: High
Security vulnerability in the WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-94504.
WP Yelp Review Slider: cross-site scripting (XSS)
WP Yelp Review Slider · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WP Yelp Review Slider component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93778.
WPC Product Bundles for WooCommerce: cross-site scripting (XSS)
WPC Product Bundles for WooCommerce · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WPC Product Bundles for WooCommerce component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93836.
WP Table Builder - Drag & Drop Table Builder: security vulnerability
WP Table Builder - Drag & Drop Table Builder · CVSS 7.1 · threat: High
Security vulnerability in the WP Table Builder - Drag & Drop Table Builder component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-6922.
Web to Print Online Designer WordPress: security vulnerability
Web to Print Online Designer WordPress · CVSS 9.8 · threat: Critical
Security vulnerability in the Web to Print Online Designer WordPress component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-82187.
You will find the full, continuously updated list on the Current threats page.
Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.