Website security: weekly review (05.10.2026)
A short review of freshly disclosed vulnerabilities in popular systems (WordPress, Joomla) from the last few days. If you use any of the plugins or versions listed below, treat it as a signal to update.
VikAppointments Services Booking Calendar: remote code execution (RCE)
VikAppointments Services Booking Calendar · CVSS 9.1 · threat: Critical
Remote code execution (RCE) in the VikAppointments Services Booking Calendar component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-87115.
The Beaver Builder Page Builder - Drag and Drop Website Builder: remote code execution (RCE)
The Beaver Builder Page Builder - Drag and Drop Website Builder · CVSS 9.1 · threat: Critical
Remote code execution (RCE) in the The Beaver Builder Page Builder - Drag and Drop Website Builder component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-92084.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress: sensitive data disclosure
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress · CVSS 8.8 · threat: High
Sensitive data disclosure in the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-92536.
Groundhogg: CRM, Newsletters, and Marketing Automation: privilege escalation
Groundhogg: CRM, Newsletters, and Marketing Automation · CVSS 8.8 · threat: High
Privilege escalation in the Groundhogg: CRM, Newsletters, and Marketing Automation component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-97644.
Kubio AI Page Builder WordPress: security vulnerability
Kubio AI Page Builder WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Kubio AI Page Builder WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-88783.
Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management: SQL injection
Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management · CVSS 8.8 · threat: High
SQL injection in the Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-18443.
SaveTo Wishlist Lite WordPress: sensitive data disclosure
SaveTo Wishlist Lite WordPress · CVSS 8.6 · threat: High
Sensitive data disclosure in the SaveTo Wishlist Lite WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-89236.
TillKit WordPress: security vulnerability
TillKit WordPress · CVSS 8.2 · threat: High
Security vulnerability in the TillKit WordPress component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2026-91078.
Photo Reviews for WooCommerce: security vulnerability
Photo Reviews for WooCommerce · CVSS 8.1 · threat: High
Security vulnerability in the Photo Reviews for WooCommerce component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-101923.
Nelio Content - Editorial Calendar & Social Media Auto-Posting: security vulnerability
Nelio Content - Editorial Calendar & Social Media Auto-Posting · CVSS 8.1 · threat: High
Security vulnerability in the Nelio Content - Editorial Calendar & Social Media Auto-Posting component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-94505.
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: security vulnerability
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin · CVSS 7.5 · threat: High
Security vulnerability in the Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-93428.
WP Ultimate Review WordPress: cross-site scripting (XSS)
WP Ultimate Review WordPress · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the WP Ultimate Review WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-101159.
WP Ultimate Review WordPress: security vulnerability
WP Ultimate Review WordPress · CVSS 7.5 · threat: High
Security vulnerability in the WP Ultimate Review WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-101160.
WP Ultimate Review WordPress: security vulnerability
WP Ultimate Review WordPress · CVSS 7.5 · threat: High
Security vulnerability in the WP Ultimate Review WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-101161.
WP 2FA WordPress: security vulnerability
WP 2FA WordPress · CVSS 7.5 · threat: High
Security vulnerability in the WP 2FA WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-103514.
GeoDirectory: SQL injection
GeoDirectory · CVSS 7.5 · threat: High
SQL injection in the GeoDirectory component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-103913.
Simple Membership: sensitive data disclosure
Simple Membership · CVSS 7.5 · threat: High
Sensitive data disclosure in the Simple Membership component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-97337.
WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System: remote code execution (RCE)
WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System · CVSS 7.5 · threat: High
Remote code execution (RCE) in the WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-75028.
WP Visitor Statistics (Real Time Traffic): SQL injection
WP Visitor Statistics (Real Time Traffic) · CVSS 7.5 · threat: High
SQL injection in the WP Visitor Statistics (Real Time Traffic) component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-96267.
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: cross-site scripting (XSS)
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96270.
Real Cookie Banner: GDPR & ePrivacy Cookie Consent: cross-site scripting (XSS)
Real Cookie Banner: GDPR & ePrivacy Cookie Consent · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Real Cookie Banner: GDPR & ePrivacy Cookie Consent component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-92977.
Magic Tooltips For Contact Form 7: cross-site scripting (XSS)
Magic Tooltips For Contact Form 7 · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Magic Tooltips For Contact Form 7 component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-101928.
Welcart e-Commerce: cross-site scripting (XSS)
Welcart e-Commerce · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Welcart e-Commerce component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-87091.
GD Rating System: cross-site scripting (XSS)
GD Rating System · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the GD Rating System component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93430.
SEOPress - AI SEO Plugin & On-site SEO: cross-site scripting (XSS)
SEOPress - AI SEO Plugin & On-site SEO · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the SEOPress - AI SEO Plugin & On-site SEO component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96564.
Transliterator - Multilingual and Multi-script Text Conversion: cross-site scripting (XSS)
Transliterator - Multilingual and Multi-script Text Conversion · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Transliterator - Multilingual and Multi-script Text Conversion component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96575.
Strong Testimonials: cross-site scripting (XSS)
Strong Testimonials · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Strong Testimonials component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96650.
Visitor Traffic Real Time Statistics: cross-site scripting (XSS)
Visitor Traffic Real Time Statistics · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Visitor Traffic Real Time Statistics component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97341.
Mail logging - WP Mail Catcher: cross-site scripting (XSS)
Mail logging - WP Mail Catcher · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Mail logging - WP Mail Catcher component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93889.
WPC Product Options for WooCommerce: cross-site scripting (XSS)
WPC Product Options for WooCommerce · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the WPC Product Options for WooCommerce component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97660.
DevKit Pro: authentication bypass
DevKit Pro · CVSS 9.8 · threat: Critical
Authentication bypass in the DevKit Pro component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-14378.
Divi Membership: authentication bypass
Divi Membership · CVSS 9.8 · threat: Critical
Authentication bypass in the Divi Membership component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-19660.
JSON API Auth: authentication bypass
JSON API Auth · CVSS 9.8 · threat: Critical
Authentication bypass in the JSON API Auth component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-97637.
WPMobile.App - Android and iOS App Builder: security vulnerability
WPMobile.App - Android and iOS App Builder · CVSS 9.8 · threat: Critical
Security vulnerability in the WPMobile.App - Android and iOS App Builder component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-94541.
Divi Membership: privilege escalation
Divi Membership · CVSS 9.8 · threat: Critical
Privilege escalation in the Divi Membership component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-19652.
Super Forms - Drag & Drop Form Builder: arbitrary file upload
Super Forms - Drag & Drop Form Builder · CVSS 9.1 · threat: Critical
Arbitrary file upload in the Super Forms - Drag & Drop Form Builder component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-15896.
Super Forms - Drag & Drop Form Builder: account takeover
Super Forms - Drag & Drop Form Builder · CVSS 8.8 · threat: High
Account takeover in the Super Forms - Drag & Drop Form Builder component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-15897.
Ninja Forms - File Uploads: remote code execution (RCE)
Ninja Forms - File Uploads · CVSS 8.1 · threat: High
Remote code execution (RCE) in the Ninja Forms - File Uploads component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-92820.
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress: security vulnerability
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress · CVSS 7.5 · threat: High
Security vulnerability in the OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-91828.
SiteOrigin Widgets Bundle: remote code execution (RCE)
SiteOrigin Widgets Bundle · CVSS 7.5 · threat: High
Remote code execution (RCE) in the SiteOrigin Widgets Bundle component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-92174.
Visitors Traffic Real Time Statistics Pro: cross-site scripting (XSS)
Visitors Traffic Real Time Statistics Pro · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Visitors Traffic Real Time Statistics Pro component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93367.
CTX Feed Pro: security vulnerability
CTX Feed Pro · CVSS 7.2 · threat: High
Security vulnerability in the CTX Feed Pro component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-10026.
Ninja Forms - The Contact Form Builder That Grows With You: cross-site scripting (XSS)
Ninja Forms - The Contact Form Builder That Grows With You · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Ninja Forms - The Contact Form Builder That Grows With You component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-90438.
BA Book Everything: cross-site scripting (XSS)
BA Book Everything · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the BA Book Everything component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-102565.
Kubio AI Page Builder: cross-site scripting (XSS)
Kubio AI Page Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Kubio AI Page Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-100107.
Download Monitor: cross-site scripting (XSS)
Download Monitor · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Download Monitor component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-100182.
CMB2: cross-site scripting (XSS)
CMB2 · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the CMB2 component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-102772.
Relevanssi Premium: cross-site scripting (XSS)
Relevanssi Premium · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Relevanssi Premium component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-103426.
Smash Balloon Social Post Feed - Simple Social Feeds for WordPress: remote code execution (RCE)
Smash Balloon Social Post Feed - Simple Social Feeds for WordPress · CVSS 7.2 · threat: High
Remote code execution (RCE) in the Smash Balloon Social Post Feed - Simple Social Feeds for WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93756.
No External Links: cross-site scripting (XSS)
No External Links · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the No External Links component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-95670.
DoFollow Case by Case: cross-site scripting (XSS)
DoFollow Case by Case · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the DoFollow Case by Case component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-95817.
Newsletter - Send awesome emails from WordPress: cross-site scripting (XSS)
Newsletter - Send awesome emails from WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Newsletter - Send awesome emails from WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96566.
MW WP Form: cross-site scripting (XSS)
MW WP Form · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the MW WP Form component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96567.
GSpeech TTS - WordPress Text To Speech Plugin: cross-site scripting (XSS)
GSpeech TTS - WordPress Text To Speech Plugin · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the GSpeech TTS - WordPress Text To Speech Plugin component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96578.
Mang Board: cross-site scripting (XSS)
Mang Board · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Mang Board component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96871.
CMB2: cross-site scripting (XSS)
CMB2 · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the CMB2 component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97336.
JetFormBuilder: Dynamic Blocks Form Builder: cross-site scripting (XSS)
JetFormBuilder: Dynamic Blocks Form Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the JetFormBuilder: Dynamic Blocks Form Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97342.
Relevanssi - A Better Search: cross-site scripting (XSS)
Relevanssi - A Better Search · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Relevanssi - A Better Search component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97641.
Customer Reviews for WooCommerce: cross-site scripting (XSS)
Customer Reviews for WooCommerce · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Customer Reviews for WooCommerce component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97663.
W3 Total Cache: cross-site scripting (XSS)
W3 Total Cache · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the W3 Total Cache component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-87920.
JetAppointment: cross-site scripting (XSS)
JetAppointment · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the JetAppointment component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-93875.
BackupSheep WordPress Backup: security vulnerability
BackupSheep WordPress Backup · CVSS 10 · threat: Critical
Security vulnerability in the BackupSheep WordPress Backup component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-101148.
Super Forms - Drag & Drop Form Builder: privilege escalation
Super Forms - Drag & Drop Form Builder · CVSS 9.8 · threat: Critical
Privilege escalation in the Super Forms - Drag & Drop Form Builder component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-15989.
Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform: authentication bypass
Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform · CVSS 9.8 · threat: Critical
Authentication bypass in the Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-75957.
WordPress: arbitrary file upload
WordPress · CVSS 9.3 · threat: Critical
Arbitrary file upload in the WordPress component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-62071.
The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress: remote code execution (RCE)
The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress · CVSS 9.1 · threat: Critical
Remote code execution (RCE) in the The Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress component. Threat level: Critical (CVSS 9.1).
Details and what to do: CVE-2026-92966.
Featured Image from URL (FIFU) WordPress: CSRF (request forgery)
Featured Image from URL (FIFU) WordPress · CVSS 8.8 · threat: High
CSRF (request forgery) in the Featured Image from URL (FIFU) WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-101147.
ByteCoreStack - MCP Connector for AI Tools: privilege escalation
ByteCoreStack - MCP Connector for AI Tools · CVSS 8.8 · threat: High
Privilege escalation in the ByteCoreStack - MCP Connector for AI Tools component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-19807.
WPC Shop as a Customer for WooCommerce: account takeover
WPC Shop as a Customer for WooCommerce · CVSS 8.8 · threat: High
Account takeover in the WPC Shop as a Customer for WooCommerce component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-95687.
Cache Enabler WordPress: security vulnerability
Cache Enabler WordPress · CVSS 8.7 · threat: High
Security vulnerability in the Cache Enabler WordPress component. Threat level: High (CVSS 8.7).
Details and what to do: CVE-2026-19253.
Pro Like Button WordPress: SQL injection
Pro Like Button WordPress · CVSS 8.6 · threat: High
SQL injection in the Pro Like Button WordPress component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-89296.
Super Forms - Drag & Drop Form Builder: remote code execution (RCE)
Super Forms - Drag & Drop Form Builder · CVSS 8.1 · threat: High
Remote code execution (RCE) in the Super Forms - Drag & Drop Form Builder component. Threat level: High (CVSS 8.1).
Details and what to do: CVE-2026-15983.
Simply Schedule Appointments: sensitive data disclosure
Simply Schedule Appointments · CVSS 7.5 · threat: High
Sensitive data disclosure in the Simply Schedule Appointments component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-92245.
Paytm Payment Gateway WordPress: security vulnerability
Paytm Payment Gateway WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Paytm Payment Gateway WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-81739.
Paytm Payment Gateway WordPress: SQL injection
Paytm Payment Gateway WordPress · CVSS 7.5 · threat: High
SQL injection in the Paytm Payment Gateway WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-81809.
Payments for Hubtel WordPress: security vulnerability
Payments for Hubtel WordPress · CVSS 7.5 · threat: High
Security vulnerability in the Payments for Hubtel WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-96255.
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses: security vulnerability
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses · CVSS 7.5 · threat: High
Security vulnerability in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-93882.
AI Engine - The Chatbot, AI Framework & MCP for WordPress: cross-site scripting (XSS)
AI Engine - The Chatbot, AI Framework & MCP for WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the AI Engine - The Chatbot, AI Framework & MCP for WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96561.
Extendify: cross-site scripting (XSS)
Extendify · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Extendify component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-85679.
Autoptimize: cross-site scripting (XSS)
Autoptimize · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Autoptimize component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-14995.
Forminator Forms - Contact Form, Payment Form & Custom Form Builder: cross-site scripting (XSS)
Forminator Forms - Contact Form, Payment Form & Custom Form Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Forminator Forms - Contact Form, Payment Form & Custom Form Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-85235.
PDF Invoices & Packing Slips for WooCommerce: cross-site scripting (XSS)
PDF Invoices & Packing Slips for WooCommerce · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the PDF Invoices & Packing Slips for WooCommerce component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-92244.
Appointment Hour Booking - Booking Calendar: cross-site scripting (XSS)
Appointment Hour Booking - Booking Calendar · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Appointment Hour Booking - Booking Calendar component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96573.
Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder: cross-site scripting (XSS)
Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96813.
Business Essentials for Contact Form 7: cross-site scripting (XSS)
Business Essentials for Contact Form 7 · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Business Essentials for Contact Form 7 component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97661.
Forminator Forms - Contact Form, Payment Form & Custom Form Builder: cross-site scripting (XSS)
Forminator Forms - Contact Form, Payment Form & Custom Form Builder · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Forminator Forms - Contact Form, Payment Form & Custom Form Builder component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-92144.
Prime Mover: remote code execution (RCE)
Prime Mover · CVSS 7.2 · threat: High
Remote code execution (RCE) in the Prime Mover component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-101888.
Five Star Restaurant Reviews WordPress: security vulnerability
Five Star Restaurant Reviews WordPress · CVSS 7.1 · threat: High
Security vulnerability in the Five Star Restaurant Reviews WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-92412.
Joomla: SQL injection
Joomla · CVSS 10 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-76570.
Joomla: remote code execution (RCE)
Joomla · CVSS 10 · threat: Critical
Remote code execution (RCE) in the Joomla component. Threat level: Critical (CVSS 10).
Details and what to do: CVE-2026-102427.
Zella: remote code execution (RCE)
Zella · CVSS 9.8 · threat: Critical
Remote code execution (RCE) in the Zella component. Threat level: Critical (CVSS 9.8).
Details and what to do: CVE-2026-75873.
All in One Files Upload WordPress: security vulnerability
All in One Files Upload WordPress · CVSS 8.8 · threat: High
Security vulnerability in the All in One Files Upload WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-85573.
Verge3D Publishing and E-Commerce WordPress: security vulnerability
Verge3D Publishing and E-Commerce WordPress · CVSS 8.8 · threat: High
Security vulnerability in the Verge3D Publishing and E-Commerce WordPress component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-92994.
Robin Image Optimizer WordPress: cross-site scripting (XSS)
Robin Image Optimizer WordPress · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Robin Image Optimizer WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-89193.
Simply Schedule Appointments: remote code execution (RCE)
Simply Schedule Appointments · CVSS 7.5 · threat: High
Remote code execution (RCE) in the Simply Schedule Appointments component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-89294.
Motors - Car Dealership & Classified Listings Plugin: SQL injection
Motors - Car Dealership & Classified Listings Plugin · CVSS 7.5 · threat: High
SQL injection in the Motors - Car Dealership & Classified Listings Plugin component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-6806.
Product Designer App: directory traversal
Product Designer App · CVSS 7.5 · threat: High
Directory traversal in the Product Designer App component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-75098.
WordPress: security vulnerability
WordPress · CVSS 7.5 · threat: High
Security vulnerability in the WordPress component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-97197.
User Frontend WordPress: security vulnerability
User Frontend WordPress · CVSS 7.4 · threat: High
Security vulnerability in the User Frontend WordPress component. Threat level: High (CVSS 7.4).
Details and what to do: CVE-2026-75823.
Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin: cross-site scripting (XSS)
Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Frontend Post Submission Manager Lite - Frontend Posting WordPress Plugin component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96649.
Post Views Stats Counter: cross-site scripting (XSS)
Post Views Stats Counter · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the Post Views Stats Counter component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-97347.
Vayu X WordPress: security vulnerability
Vayu X WordPress · CVSS 7.1 · threat: High
Security vulnerability in the Vayu X WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-88797.
WP Mobile Menu WordPress: cross-site scripting (XSS)
WP Mobile Menu WordPress · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the WP Mobile Menu WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-91832.
WordPress: security vulnerability
WordPress · CVSS 7.1 · threat: High
Security vulnerability in the WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-93512.
WordPress: security vulnerability
WordPress · CVSS 7.1 · threat: High
Security vulnerability in the WordPress component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-94081.
Joomla: security vulnerability
Joomla · CVSS 9.5 · threat: Critical
Security vulnerability in the Joomla component. Threat level: Critical (CVSS 9.5).
Details and what to do: CVE-2026-102425.
Joomla: directory traversal
Joomla · CVSS 8.9 · threat: High
Directory traversal in the Joomla component. Threat level: High (CVSS 8.9).
Details and what to do: CVE-2026-102424.
Joomla: SSRF (server-side request forgery)
Joomla · CVSS 8.9 · threat: High
SSRF (server-side request forgery) in the Joomla component. Threat level: High (CVSS 8.9).
Details and what to do: CVE-2026-92222.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 8.6 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 8.6).
Details and what to do: CVE-2026-101127.
Joomla: authentication bypass
Joomla · CVSS 8.2 · threat: High
Authentication bypass in the Joomla component. Threat level: High (CVSS 8.2).
Details and what to do: CVE-2026-92227.
HT Contact Form - Drag & Drop Form Builder for WordPress: cross-site scripting (XSS)
HT Contact Form - Drag & Drop Form Builder for WordPress · CVSS 7.2 · threat: High
Cross-site scripting (XSS) in the HT Contact Form - Drag & Drop Form Builder for WordPress component. Threat level: High (CVSS 7.2).
Details and what to do: CVE-2026-96326.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-92231.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.1 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.1).
Details and what to do: CVE-2026-92232.
Joomla: security vulnerability
Joomla · CVSS 7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 7).
Details and what to do: CVE-2026-90913.
Joomla: security vulnerability
Joomla · CVSS 7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 7).
Details and what to do: CVE-2026-90915.
Joomla: security vulnerability
Joomla · CVSS 7 · threat: High
Security vulnerability in the Joomla component. Threat level: High (CVSS 7).
Details and what to do: CVE-2026-92226.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-100752.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-101108.
Joomla: SQL injection
Joomla · CVSS 9.3 · threat: Critical
SQL injection in the Joomla component. Threat level: Critical (CVSS 9.3).
Details and what to do: CVE-2026-101110.
ConvertPlus: insecure deserialization
ConvertPlus · CVSS 8.8 · threat: High
Insecure deserialization in the ConvertPlus component. Threat level: High (CVSS 8.8).
Details and what to do: CVE-2026-87741.
Joomla: SSRF (server-side request forgery)
Joomla · CVSS 8.5 · threat: High
SSRF (server-side request forgery) in the Joomla component. Threat level: High (CVSS 8.5).
Details and what to do: CVE-2026-100750.
Joomla: cross-site scripting (XSS)
Joomla · CVSS 7.5 · threat: High
Cross-site scripting (XSS) in the Joomla component. Threat level: High (CVSS 7.5).
Details and what to do: CVE-2026-100751.
You will find the full, continuously updated list on the Current threats page.
Not sure whether your website is safe? Request a free audit and we will check it against these and other threats.