Security

Website security: weekly review (05.10.2026)

Website security: weekly review (05.10.2026)

A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.

VikAppointments Services Booking Calendar: remote code execution (RCE)

VikAppointments Services Booking Calendar · CVSS 9.1 · threat: Critical

Remote code execution (RCE) in the VikAppointments Services Booking Calendar component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-87115.

The Beaver Builder Page Builder - Drag and Drop Website Builder: remote code execution (RCE)

The Beaver Builder Page Builder - Drag and Drop Website Builder · CVSS 9.1 · threat: Critical

Remote code execution (RCE) in the The Beaver Builder Page Builder - Drag and Drop Website Builder component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-92084.

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress: sensitive data disclosure

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress · CVSS 8.8 · threat: High

Sensitive data disclosure in the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-92536.

Groundhogg: CRM, Newsletters, and Marketing Automation: privilege escalation

Groundhogg: CRM, Newsletters, and Marketing Automation · CVSS 8.8 · threat: High

Privilege escalation in the Groundhogg: CRM, Newsletters, and Marketing Automation component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-97644.

Kubio AI Page Builder WordPress: security vulnerability

Kubio AI Page Builder WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Kubio AI Page Builder WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-88783.

Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management: SQL injection

Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management · CVSS 8.8 · threat: High

SQL injection in the Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-18443.

SaveTo Wishlist Lite WordPress: sensitive data disclosure

SaveTo Wishlist Lite WordPress · CVSS 8.6 · threat: High

Sensitive data disclosure in the SaveTo Wishlist Lite WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-89236.

TillKit WordPress: security vulnerability

TillKit WordPress · CVSS 8.2 · threat: High

Security vulnerability in the TillKit WordPress component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2026-91078.

Photo Reviews for WooCommerce: security vulnerability

Photo Reviews for WooCommerce · CVSS 8.1 · threat: High

Security vulnerability in the Photo Reviews for WooCommerce component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-101923.

Nelio Content - Editorial Calendar & Social Media Auto-Posting: security vulnerability

Nelio Content - Editorial Calendar & Social Media Auto-Posting · CVSS 8.1 · threat: High

Security vulnerability in the Nelio Content - Editorial Calendar & Social Media Auto-Posting component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-94505.

Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: security vulnerability

Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin · CVSS 7.5 · threat: High

Security vulnerability in the Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-93428.

WP Ultimate Review WordPress: cross-site scripting (XSS)

WP Ultimate Review WordPress · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the WP Ultimate Review WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-101159.

WP Ultimate Review WordPress: security vulnerability

WP Ultimate Review WordPress · CVSS 7.5 · threat: High

Security vulnerability in the WP Ultimate Review WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-101160.

WP Ultimate Review WordPress: security vulnerability

WP Ultimate Review WordPress · CVSS 7.5 · threat: High

Security vulnerability in the WP Ultimate Review WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-101161.

WP 2FA WordPress: security vulnerability

WP 2FA WordPress · CVSS 7.5 · threat: High

Security vulnerability in the WP 2FA WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-103514.

GeoDirectory: SQL injection

GeoDirectory · CVSS 7.5 · threat: High

SQL injection in the GeoDirectory component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-103913.

Simple Membership: sensitive data disclosure

Simple Membership · CVSS 7.5 · threat: High

Sensitive data disclosure in the Simple Membership component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-97337.

WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System: remote code execution (RCE)

WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System · CVSS 7.5 · threat: High

Remote code execution (RCE) in the WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-75028.

WP Visitor Statistics (Real Time Traffic): SQL injection

WP Visitor Statistics (Real Time Traffic) · CVSS 7.5 · threat: High

SQL injection in the WP Visitor Statistics (Real Time Traffic) component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-96267.

Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: cross-site scripting (XSS)

Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96270.

Real Cookie Banner: GDPR & ePrivacy Cookie Consent: cross-site scripting (XSS)

Real Cookie Banner: GDPR & ePrivacy Cookie Consent · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Real Cookie Banner: GDPR & ePrivacy Cookie Consent component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-92977.

Magic Tooltips For Contact Form 7: cross-site scripting (XSS)

Magic Tooltips For Contact Form 7 · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Magic Tooltips For Contact Form 7 component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-101928.

Welcart e-Commerce: cross-site scripting (XSS)

Welcart e-Commerce · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Welcart e-Commerce component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-87091.

GD Rating System: cross-site scripting (XSS)

GD Rating System · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the GD Rating System component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93430.

SEOPress - AI SEO Plugin & On-site SEO: cross-site scripting (XSS)

SEOPress - AI SEO Plugin & On-site SEO · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the SEOPress - AI SEO Plugin & On-site SEO component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96564.

Transliterator - Multilingual and Multi-script Text Conversion: cross-site scripting (XSS)

Transliterator - Multilingual and Multi-script Text Conversion · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Transliterator - Multilingual and Multi-script Text Conversion component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96575.

Strong Testimonials: cross-site scripting (XSS)

Strong Testimonials · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Strong Testimonials component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96650.

Visitor Traffic Real Time Statistics: cross-site scripting (XSS)

Visitor Traffic Real Time Statistics · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Visitor Traffic Real Time Statistics component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97341.

Mail logging - WP Mail Catcher: cross-site scripting (XSS)

Mail logging - WP Mail Catcher · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Mail logging - WP Mail Catcher component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93889.

WPC Product Options for WooCommerce: cross-site scripting (XSS)

WPC Product Options for WooCommerce · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the WPC Product Options for WooCommerce component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97660.

DevKit Pro: authentication bypass

DevKit Pro · CVSS 9.8 · threat: Critical

Authentication bypass in the DevKit Pro component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-14378.

Divi Membership: authentication bypass

Divi Membership · CVSS 9.8 · threat: Critical

Authentication bypass in the Divi Membership component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-19660.

JSON API Auth: authentication bypass

JSON API Auth · CVSS 9.8 · threat: Critical

Authentication bypass in the JSON API Auth component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-97637.

WPMobile.App - Android and iOS App Builder: security vulnerability

WPMobile.App - Android and iOS App Builder · CVSS 9.8 · threat: Critical

Security vulnerability in the WPMobile.App - Android and iOS App Builder component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-94541.

Divi Membership: privilege escalation

Divi Membership · CVSS 9.8 · threat: Critical

Privilege escalation in the Divi Membership component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-19652.

Super Forms - Drag & Drop Form Builder: arbitrary file upload

Super Forms - Drag & Drop Form Builder · CVSS 9.1 · threat: Critical

Arbitrary file upload in the Super Forms - Drag & Drop Form Builder component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-15896.

Super Forms - Drag & Drop Form Builder: account takeover

Super Forms - Drag & Drop Form Builder · CVSS 8.8 · threat: High

Account takeover in the Super Forms - Drag & Drop Form Builder component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-15897.

Ninja Forms - File Uploads: remote code execution (RCE)

Ninja Forms - File Uploads · CVSS 8.1 · threat: High

Remote code execution (RCE) in the Ninja Forms - File Uploads component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-92820.

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress: security vulnerability

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress · CVSS 7.5 · threat: High

Security vulnerability in the OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-91828.

SiteOrigin Widgets Bundle: remote code execution (RCE)

SiteOrigin Widgets Bundle · CVSS 7.5 · threat: High

Remote code execution (RCE) in the SiteOrigin Widgets Bundle component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-92174.

Visitors Traffic Real Time Statistics Pro: cross-site scripting (XSS)

Visitors Traffic Real Time Statistics Pro · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Visitors Traffic Real Time Statistics Pro component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93367.

CTX Feed Pro: security vulnerability

CTX Feed Pro · CVSS 7.2 · threat: High

Security vulnerability in the CTX Feed Pro component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-10026.

Ninja Forms - The Contact Form Builder That Grows With You: cross-site scripting (XSS)

Ninja Forms - The Contact Form Builder That Grows With You · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Ninja Forms - The Contact Form Builder That Grows With You component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-90438.

BA Book Everything: cross-site scripting (XSS)

BA Book Everything · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the BA Book Everything component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-102565.

Kubio AI Page Builder: cross-site scripting (XSS)

Kubio AI Page Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Kubio AI Page Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-100107.

Download Monitor: cross-site scripting (XSS)

Download Monitor · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Download Monitor component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-100182.

CMB2: cross-site scripting (XSS)

CMB2 · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the CMB2 component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-102772.

Relevanssi Premium: cross-site scripting (XSS)

Relevanssi Premium · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Relevanssi Premium component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-103426.

Smash Balloon Social Post Feed - Simple Social Feeds for WordPress: remote code execution (RCE)

Smash Balloon Social Post Feed - Simple Social Feeds for WordPress · CVSS 7.2 · threat: High

Remote code execution (RCE) in the Smash Balloon Social Post Feed - Simple Social Feeds for WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93756.

No External Links: cross-site scripting (XSS)

No External Links · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the No External Links component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-95670.

DoFollow Case by Case: cross-site scripting (XSS)

DoFollow Case by Case · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the DoFollow Case by Case component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-95817.

Newsletter - Send awesome emails from WordPress: cross-site scripting (XSS)

Newsletter - Send awesome emails from WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Newsletter - Send awesome emails from WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96566.

MW WP Form: cross-site scripting (XSS)

MW WP Form · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the MW WP Form component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96567.

GSpeech TTS - WordPress Text To Speech Plugin: cross-site scripting (XSS)

GSpeech TTS - WordPress Text To Speech Plugin · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the GSpeech TTS - WordPress Text To Speech Plugin component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96578.

Mang Board: cross-site scripting (XSS)

Mang Board · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Mang Board component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96871.

CMB2: cross-site scripting (XSS)

CMB2 · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the CMB2 component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97336.

JetFormBuilder: Dynamic Blocks Form Builder: cross-site scripting (XSS)

JetFormBuilder: Dynamic Blocks Form Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the JetFormBuilder: Dynamic Blocks Form Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97342.

Relevanssi - A Better Search: cross-site scripting (XSS)

Relevanssi - A Better Search · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Relevanssi - A Better Search component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97641.

Customer Reviews for WooCommerce: cross-site scripting (XSS)

Customer Reviews for WooCommerce · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Customer Reviews for WooCommerce component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97663.

W3 Total Cache: cross-site scripting (XSS)

W3 Total Cache · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the W3 Total Cache component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-87920.

JetAppointment: cross-site scripting (XSS)

JetAppointment · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the JetAppointment component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-93875.

BackupSheep WordPress Backup: security vulnerability

BackupSheep WordPress Backup · CVSS 10 · threat: Critical

Security vulnerability in the BackupSheep WordPress Backup component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-101148.

Super Forms - Drag & Drop Form Builder: privilege escalation

Super Forms - Drag & Drop Form Builder · CVSS 9.8 · threat: Critical

Privilege escalation in the Super Forms - Drag & Drop Form Builder component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-15989.

Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform: authentication bypass

Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform · CVSS 9.8 · threat: Critical

Authentication bypass in the Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-75957.

WordPress: arbitrary file upload

WordPress · CVSS 9.3 · threat: Critical

Arbitrary file upload in the WordPress component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-62071.

The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress: remote code execution (RCE)

The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress · CVSS 9.1 · threat: Critical

Remote code execution (RCE) in the The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress component. Threat level: Critical (CVSS 9.1).

Details and what to do: CVE-2026-92966.

Featured Image from URL (FIFU) WordPress: CSRF (request forgery)

Featured Image from URL (FIFU) WordPress · CVSS 8.8 · threat: High

CSRF (request forgery) in the Featured Image from URL (FIFU) WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-101147.

ByteCoreStack - MCP Connector for AI Tools: privilege escalation

ByteCoreStack - MCP Connector for AI Tools · CVSS 8.8 · threat: High

Privilege escalation in the ByteCoreStack - MCP Connector for AI Tools component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-19807.

WPC Shop as a Customer for WooCommerce: account takeover

WPC Shop as a Customer for WooCommerce · CVSS 8.8 · threat: High

Account takeover in the WPC Shop as a Customer for WooCommerce component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-95687.

Cache Enabler WordPress: security vulnerability

Cache Enabler WordPress · CVSS 8.7 · threat: High

Security vulnerability in the Cache Enabler WordPress component. Threat level: High (CVSS 8.7).

Details and what to do: CVE-2026-19253.

Pro Like Button WordPress: SQL injection

Pro Like Button WordPress · CVSS 8.6 · threat: High

SQL injection in the Pro Like Button WordPress component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-89296.

Super Forms - Drag & Drop Form Builder: remote code execution (RCE)

Super Forms - Drag & Drop Form Builder · CVSS 8.1 · threat: High

Remote code execution (RCE) in the Super Forms - Drag & Drop Form Builder component. Threat level: High (CVSS 8.1).

Details and what to do: CVE-2026-15983.

Simply Schedule Appointments: sensitive data disclosure

Simply Schedule Appointments · CVSS 7.5 · threat: High

Sensitive data disclosure in the Simply Schedule Appointments component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-92245.

Paytm Payment Gateway WordPress: security vulnerability

Paytm Payment Gateway WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Paytm Payment Gateway WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-81739.

Paytm Payment Gateway WordPress: SQL injection

Paytm Payment Gateway WordPress · CVSS 7.5 · threat: High

SQL injection in the Paytm Payment Gateway WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-81809.

Payments for Hubtel WordPress: security vulnerability

Payments for Hubtel WordPress · CVSS 7.5 · threat: High

Security vulnerability in the Payments for Hubtel WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-96255.

LearnPress - WordPress LMS Plugin for Create and Sell Online Courses: security vulnerability

LearnPress - WordPress LMS Plugin for Create and Sell Online Courses · CVSS 7.5 · threat: High

Security vulnerability in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-93882.

AI Engine - The Chatbot, AI Framework & MCP for WordPress: cross-site scripting (XSS)

AI Engine - The Chatbot, AI Framework & MCP for WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the AI Engine - The Chatbot, AI Framework & MCP for WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96561.

Extendify: cross-site scripting (XSS)

Extendify · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Extendify component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-85679.

Autoptimize: cross-site scripting (XSS)

Autoptimize · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Autoptimize component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-14995.

Forminator Forms - Contact Form, Payment Form & Custom Form Builder: cross-site scripting (XSS)

Forminator Forms - Contact Form, Payment Form & Custom Form Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Forminator Forms - Contact Form, Payment Form & Custom Form Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-85235.

PDF Invoices & Packing Slips for WooCommerce: cross-site scripting (XSS)

PDF Invoices & Packing Slips for WooCommerce · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the PDF Invoices & Packing Slips for WooCommerce component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-92244.

Appointment Hour Booking - Booking Calendar: cross-site scripting (XSS)

Appointment Hour Booking - Booking Calendar · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Appointment Hour Booking - Booking Calendar component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96573.

Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder: cross-site scripting (XSS)

Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96813.

Business Essentials for Contact Form 7: cross-site scripting (XSS)

Business Essentials for Contact Form 7 · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Business Essentials for Contact Form 7 component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97661.

Forminator Forms - Contact Form, Payment Form & Custom Form Builder: cross-site scripting (XSS)

Forminator Forms - Contact Form, Payment Form & Custom Form Builder · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Forminator Forms - Contact Form, Payment Form & Custom Form Builder component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-92144.

Prime Mover: remote code execution (RCE)

Prime Mover · CVSS 7.2 · threat: High

Remote code execution (RCE) in the Prime Mover component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-101888.

Five Star Restaurant Reviews WordPress: security vulnerability

Five Star Restaurant Reviews WordPress · CVSS 7.1 · threat: High

Security vulnerability in the Five Star Restaurant Reviews WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-92412.

Joomla: SQL injection

Joomla · CVSS 10 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-76570.

Joomla: remote code execution (RCE)

Joomla · CVSS 10 · threat: Critical

Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 10).

Details and what to do: CVE-2026-102427.

Zella: remote code execution (RCE)

Zella · CVSS 9.8 · threat: Critical

Remote code execution (RCE) in the Zella component. Threat level: Critical (CVSS 9.8).

Details and what to do: CVE-2026-75873.

All in One Files Upload WordPress: security vulnerability

All in One Files Upload WordPress · CVSS 8.8 · threat: High

Security vulnerability in the All in One Files Upload WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-85573.

Verge3D Publishing and E-Commerce WordPress: security vulnerability

Verge3D Publishing and E-Commerce WordPress · CVSS 8.8 · threat: High

Security vulnerability in the Verge3D Publishing and E-Commerce WordPress component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-92994.

Robin Image Optimizer WordPress: cross-site scripting (XSS)

Robin Image Optimizer WordPress · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Robin Image Optimizer WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-89193.

Simply Schedule Appointments: remote code execution (RCE)

Simply Schedule Appointments · CVSS 7.5 · threat: High

Remote code execution (RCE) in the Simply Schedule Appointments component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-89294.

Motors - Car Dealership & Classified Listings Plugin: SQL injection

Motors - Car Dealership & Classified Listings Plugin · CVSS 7.5 · threat: High

SQL injection in the Motors - Car Dealership & Classified Listings Plugin component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-6806.

Product Designer App: directory traversal

Product Designer App · CVSS 7.5 · threat: High

Directory traversal in the Product Designer App component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-75098.

WordPress: security vulnerability

WordPress · CVSS 7.5 · threat: High

Security vulnerability in the WordPress component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-97197.

User Frontend WordPress: security vulnerability

User Frontend WordPress · CVSS 7.4 · threat: High

Security vulnerability in the User Frontend WordPress component. Threat level: High (CVSS 7.4).

Details and what to do: CVE-2026-75823.

Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin: cross-site scripting (XSS)

Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96649.

Post Views Stats Counter: cross-site scripting (XSS)

Post Views Stats Counter · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the Post Views Stats Counter component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-97347.

Vayu X WordPress: security vulnerability

Vayu X WordPress · CVSS 7.1 · threat: High

Security vulnerability in the Vayu X WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-88797.

WP Mobile Menu WordPress: cross-site scripting (XSS)

WP Mobile Menu WordPress · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the WP Mobile Menu WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-91832.

WordPress: security vulnerability

WordPress · CVSS 7.1 · threat: High

Security vulnerability in the WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-93512.

WordPress: security vulnerability

WordPress · CVSS 7.1 · threat: High

Security vulnerability in the WordPress component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-94081.

Joomla: security vulnerability

Joomla · CVSS 9.5 · threat: Critical

Security vulnerability in the Joomla component. Threat level: Critical (CVSS 9.5).

Details and what to do: CVE-2026-102425.

Joomla: directory traversal

Joomla · CVSS 8.9 · threat: High

Directory traversal in the Joomla component. Threat level: High (CVSS 8.9).

Details and what to do: CVE-2026-102424.

Joomla: SSRF (server-side request forgery)

Joomla · CVSS 8.9 · threat: High

SSRF (server-side request forgery) in the Joomla component. Threat level: High (CVSS 8.9).

Details and what to do: CVE-2026-92222.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 8.6 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 8.6).

Details and what to do: CVE-2026-101127.

Joomla: authentication bypass

Joomla · CVSS 8.2 · threat: High

Authentication bypass in the Joomla component. Threat level: High (CVSS 8.2).

Details and what to do: CVE-2026-92227.

HT Contact Form - Drag & Drop Form Builder for WordPress: cross-site scripting (XSS)

HT Contact Form - Drag & Drop Form Builder for WordPress · CVSS 7.2 · threat: High

Cross-site scripting (XSS) in the HT Contact Form - Drag & Drop Form Builder for WordPress component. Threat level: High (CVSS 7.2).

Details and what to do: CVE-2026-96326.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-92231.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.1 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.1).

Details and what to do: CVE-2026-92232.

Joomla: security vulnerability

Joomla · CVSS 7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 7).

Details and what to do: CVE-2026-90913.

Joomla: security vulnerability

Joomla · CVSS 7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 7).

Details and what to do: CVE-2026-90915.

Joomla: security vulnerability

Joomla · CVSS 7 · threat: High

Security vulnerability in the Joomla component. Threat level: High (CVSS 7).

Details and what to do: CVE-2026-92226.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-100752.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-101108.

Joomla: SQL injection

Joomla · CVSS 9.3 · threat: Critical

SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).

Details and what to do: CVE-2026-101110.

ConvertPlus: insecure deserialization

ConvertPlus · CVSS 8.8 · threat: High

Insecure deserialization in the ConvertPlus component. Threat level: High (CVSS 8.8).

Details and what to do: CVE-2026-87741.

Joomla: SSRF (server-side request forgery)

Joomla · CVSS 8.5 · threat: High

SSRF (server-side request forgery) in the Joomla component. Threat level: High (CVSS 8.5).

Details and what to do: CVE-2026-100750.

Joomla: cross-site scripting (XSS)

Joomla · CVSS 7.5 · threat: High

Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).

Details and what to do: CVE-2026-100751.


You will find the full, continuously updated list on the Current threats page.

Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.