Threat monitoring
Current WordPress and Joomla threats
We track the most dangerous, actively exploited vulnerabilities so we can react before they reach your site. Here is the list worth keeping an eye on. Want to check whether any of them affects your site? Use the My site vulnerabilities tool.
Last updated: September 7, 2026
1 055WordPress and Joomla vulnerabilities in our database, see flaw types, the most frequently vulnerable plugins and trends
Full statistics →
WordPress Critical · 9.8
CVE-2026-16310 September 6, 2026
MemberDash: security vulnerability
MemberDash
Security vulnerability in the MemberDash component. Threat level: Critical (CVSS 9.8).
WordPress High · 7.5
CVE-2026-18056 September 6, 2026
HivePress Authentication: authentication bypass
HivePress Authentication
Authentication bypass in the HivePress Authentication component. Threat level: High (CVSS 7.5).
WordPress Critical · 9.8
CVE-2026-75816 September 6, 2026
Frontend Admin by DynamiApps: authentication bypass
Frontend Admin by DynamiApps
Authentication bypass in the Frontend Admin by DynamiApps component. Threat level: Critical (CVSS 9.8).
WordPress High · 8.8
CVE-2026-18480 September 6, 2026
SureCart WordPress: security vulnerability
SureCart WordPress
Security vulnerability in the SureCart WordPress component. Threat level: High (CVSS 8.8).
WordPress High · 7.5
CVE-2026-84219 September 6, 2026
Kirki WordPress: security vulnerability
Kirki WordPress
Security vulnerability in the Kirki WordPress component. Threat level: High (CVSS 7.5).
WordPress Critical · 9.8
CVE-2026-13447 September 5, 2026
Mstore Api: authentication bypass
Mstore Api
Authentication bypass in the Mstore Api component. Threat level: Critical (CVSS 9.8).
WordPress High · 7.2
CVE-2026-77233 September 5, 2026
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more: cross-site scripting (XSS)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
Cross-site scripting (XSS) in the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more component. Threat level: High (CVSS 7.2).
WordPress High · 7.2
CVE-2026-77263 September 5, 2026
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more: cross-site scripting (XSS)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
Cross-site scripting (XSS) in the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more component. Threat level: High (CVSS 7.2).
WordPress Critical · 9.8
CVE-2026-83627 September 5, 2026
Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN: remote code execution (RCE)
Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN
Remote code execution (RCE) in the Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN component. Threat level: Critical (CVSS 9.8).
WordPress High · 7.2
CVE-2026-15984 September 5, 2026
QuickCal: cross-site scripting (XSS)
QuickCal
Cross-site scripting (XSS) in the QuickCal component. Threat level: High (CVSS 7.2).
WordPress High · 7.2
CVE-2026-16649 September 5, 2026
Gravity Forms: cross-site scripting (XSS)
Gravity Forms
Cross-site scripting (XSS) in the Gravity Forms component. Threat level: High (CVSS 7.2).
WordPress High · 7.2
CVE-2026-18406 September 5, 2026
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz: cross-site scripting (XSS)
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
Cross-site scripting (XSS) in the SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz component. Threat level: High (CVSS 7.2).
WordPress High · 7.2
CVE-2026-19769 September 5, 2026
Ninja Forms – The Contact Form Builder That Grows With You: arbitrary file upload
Ninja Forms – The Contact Form Builder That Grows With You
Arbitrary file upload in the Ninja Forms – The Contact Form Builder That Grows With You component. Threat level: High (CVSS 7.2).
WordPress High · 8.8
CVE-2026-19887 September 5, 2026
Welcart e-Commerce: remote code execution (RCE)
Welcart e-Commerce
Remote code execution (RCE) in the Welcart e-Commerce component. Threat level: High (CVSS 8.8).
WordPress High · 7.2
CVE-2026-77830 September 5, 2026
Spam protection, Honeypot, Anti-Spam by CleanTalk: cross-site scripting (XSS)
Spam protection, Honeypot, Anti-Spam by CleanTalk
Cross-site scripting (XSS) in the Spam protection, Honeypot, Anti-Spam by CleanTalk component. Threat level: High (CVSS 7.2).
WordPress High · 7.2
CVE-2026-78438 September 5, 2026
W3 Total Cache: cross-site scripting (XSS)
W3 Total Cache
Cross-site scripting (XSS) in the W3 Total Cache component. Threat level: High (CVSS 7.2).
WordPress High · 8.8
CVE-2026-81543 September 5, 2026
Abandoned Cart Pro for WooCommerce: privilege escalation
Abandoned Cart Pro for WooCommerce
Privilege escalation in the Abandoned Cart Pro for WooCommerce component. Threat level: High (CVSS 8.8).
WordPress High · 7.2
CVE-2026-83625 September 5, 2026
Contact Form by Supsystic: cross-site scripting (XSS)
Contact Form by Supsystic
Cross-site scripting (XSS) in the Contact Form by Supsystic component. Threat level: High (CVSS 7.2).
Data comes from the public NVD (NIST) vulnerability catalog and is refreshed automatically. This list does not replace a full audit of your site.
Do not guess, check
Does any of these flaws affect your site?
We will run a free audit: we check versions, plugins, and configuration, and tell you plainly whether you are safe.
Request a free audit →
Security newsletter
Once a week we send a review of the most important WordPress and Joomla vulnerabilities. No spam, one-click unsubscribe.