- What: Weekly report on WordPress vulnerabilities
- Impact: WordPress users may be affected
Last week, there were 246 vulnerabilities disclosed in 174 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 121 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , webhook integration , and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium , Care , and Response customers last week: InfusedWoo Pro <= 5.1.18 – Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure WPeMatico RSS Feed Fetcher <= 2.8.24 – Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action WPMU DEV Dashboard <= 5.0.1 – Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion WPLP Cookie Consent <= 4.4.1 – Unauthenticated Arbitrary File Upload via ‘upload-logo’ REST Endpoint WAF-RULE-953 – Data redacted while we work with the vendor on a patch. WAF-RULE-955 – Data redacted while we work with the vendor on a patch. Wordfence Premium , Care , and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 234 Unpatched 12 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Low Severity 2 Medium Severity 153 High Severity 73 Critical Severity 18 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 57 Missing Authorization 46 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 22 Authorization Bypass Through User-Controlled Key 16 Exposure of Sensitive Information to an Unauthorized Actor 14 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 14 Improper Privilege Management 13 Improper Control of Generation of Code ('Code Injection') 10 Deserialization of Untrusted Data 8 Unrestricted Upload of File with Dangerous Type 8 Cross-Site Request Forgery (CSRF) 7 Client-Side Enforcement of Server-Side Security 5 Server-Side Request Forgery (SSRF) 5 Improper Authentication 4 Authentication Bypass by Alternate Name 2 Authentication Bypass Using an Alternate Path or Channel 2 Missing Authentication for Critical Function 2 Embedded Malicious Code 1 Generation of Predictable Numbers or Identifiers 1 Guessable CAPTCHA 1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 1 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1 Improper Verification of Cryptographic Signature 1 Insufficient Verification of Data Authenticity 1 Uncontrolled Resource Consumption 1 URL Redirection to Untrusted Site ('Open Redirect') 1 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) 1 Weak Password Recovery Mechanism for Forgotten Password 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Ananda Dhakal 17 Wordfence PRISM 14 Jakub Herman 12 daroo 12 Shikhali Jamalzade 9 Erwan LR 9 JunHee CHO 7 Sai Praneeth Koti 7 Revanth Hari Narayana Matte 6 sungbyeongchan 6 Rafie Muhammad 4 dutafi 4 Supakiad S. 4 Vaibhav Narkhede 4 Artus KG 4 Meher Sudhakar Abbireddi 3 Osvaldo Noe Gonzalez Del Rio (Os) 3 Usama Arshad 3 Muni Nitish Kumar Yaddala 3 Dmitrii Ignatyev 3 João Ramos Maciel 2 TruongLV1 From FPT Night Wolf 2 Jack Taylor 2 Huynh Kien Minh 2 VDsec 2 h0xilo 2 Khaled Alenazi 2 Alex Thomas 2 Wordfence Argus 2 Farid Narimanov 2 kimsunghoon 2 Yuto Hyakumoto 2 João Pedro Soares de Alcântara 2 Adrien Brunner 2 Shivamani Vastrala 2 Jashid Sany 2 Shhriyash 2 Nir Yehoshua 2 Jiemook 2 Charles Vosburgh 2 Abdullah Kareem 2 V1T 1 andrew gomez 1 Cem Bas 1 Pedro Pinho 1 hoangphuong 1 Benjamin Aguayo 1 Muhammad Yudha - DJ 1 Aydan Arabadzha 1 Athiwat Tiprasaharn (Jitlada) 1 Itthidej Aramsri (Boeing777) 1 sequence_X0 1 molten bit 1 Trương Hữu Phúc 1 lord willmore 1 Vivien LEBAS 1 Phat RiO 1 Thanh Lam Tang 1 Haitam Lazaar 1 Ionut Pipirig 1 Hijun Kim 1 Tin Pham (TF1T) 1 Trong Pham (dtro) 1 Hao Ngo 1 sanghyeok Kim 1 Md Mehedi Hasan 1 Spy0x7 1 d.v4n_s3c 1 Jaan Buerms 1 Truoc Phan 1 Udin Chan 1 Lee chul woong 1 Nguyen Ba Khanh 1 Mohammed Abd Alrahman 1 CoryRoo 1 Louise 1 Manuel Martínez Casasola 1 Slopothecary 1 marim00 1 0xd4rk5id3 1 emiliano carrizo 1 Pablo González 1 Fran Ramírez 1 Vapour 1 Bao 1 Pablo González Pérez 1 Francisco José Ramírez Vicente 1 Iñigo Sánchez Enciso 1 Nguyen Phuoc Thinh 1 Ahmed Hassan 1 type5afe 1 Brian Willows 1 doyz 1 Jonah Burgess (CryptoCat) 1 lanlv 1 Duy Tran 1 G0053 1 Tanishq Shah 1 Thatchapol Booranatanit (AliceZz) 1 Bhaveshkumar Parmar 1 Gaurav popalghat 1 Lucas Montes (NiRoX) 1 Ren Voza 1 tiborisaak 1 Asim Alshaya 1 Akshat Parikh 1 Chamseddine Bouzaiene 1 Talal Nasraddeen 1 ABIODUN VICTOR TAIWO 1 Leonid Semenenko (lsemenenko) 1 stealthcopter 1 Abiodun Victor 1 huytqtq 1 Ezekiel Victor 1 Huseyn 1 Yaswanth Reddy Sunkara 1 Tyler Chin 1 ashv4ni 1 Dthangws 1 mad4cyber 1 Seongwon Lee 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug 12 Step Meeting List 12-step-meeting-list ACPT (Premium) advanced-custom-post-type Advanced Custom Fields: Extended acf-extended Affiliate Program Suite — SliceWP Affiliates slicewp AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine All-in-One WP Migration and Backup all-in-one-wp-migration All-in-One WP Migration Unlimited Extension all-in-one-wp-migration-unlimited-extension Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates animation-addons-for-elementor Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress bookingpress-appointment-booking Avada (Fusion) Builder fusion-builder Beautiful taxonomy filters beautiful-taxonomy-filters BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP betterlinks BlogVault Backup & Staging blogvault-real-time-backup Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment booking-and-rental-manager-for-woocommerce Booking for Appointments and Events Calendar – Amelia ameliabooking Booking Package booking-package Breeze Cache breeze Catfolders Document Gallery Pro catfolders-document-gallery-pro Classified Listing - Mobile Number Verification rtcl-verification CM Map Locations – Visualize and share your locations in a few clicks cm-map-locations CMP – Coming Soon & Maintenance Plugin by NiteoThemes cmp-coming-soon-maintenance Content Mask content-mask Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates cozy-addons CP Media Player – Audio Player and Video Player audio-and-video-player Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce Customer Reviews for WooCommerce customer-reviews-woocommerce Defender Security – Malware Scanner, Login Security & Firewall defender-security Directorist: AI-Powered Business Directory, Listings & Classified Ads directorist Ditty – Responsive News Tickers, Sliders, and Lists ditty-news-ticker Document Embedder – let visitors read files without downloading document-emberdder Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy dokan-lite Drag and Drop Multiple File Upload for Contact Form 7 drag-and-drop-multiple-file-upload-contact-form-7 Duplicate Post copy-delete-posts eCommerce Product Catalog ecommerce-product-catalog ElementsKit Pro elementskit Email Essentials email-essentials Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress email-subscribers Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More envira-gallery-lite ePayco plugin for WooCommerce epayco-gateway ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce erp Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar mage-eventpress Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce wp-event-solution Events Manager – Calendar, Bookings, Tickets, and more! events-manager Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI everest-forms FiboSearch – Ajax Search for WooCommerce ajax-search-for-woocommerce Finale Lite – Sales Countdown Timer & Discount for WooCommerce finale-woocommerce-sales-countdown-timer-discount Fluent Boards Pro fluent-boards-pro Fluent Booking Pro fluent-booking-pro Fluent Forms Pro Add On Pack fluentformpro Fluent Player Pro fluent-player-pro Fluent Support Pro fluent-support-pro FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler fluent-cart FluentCRM PRO fluentcampaign-pro FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution fluentcrm-pro Formidable Charts formidable-charts Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More formidable Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator Frontend Admin by DynamiApps acf-frontend-form-element FundEngine – Donation and Crowdfunding Platform wp-fundraising-donation Geo Controller cf-geoplugin GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory GeotargetingWP geotargetingwp GiveWP – Donation Plugin and Fundraising Platform give Greenshift – animation and page builder blocks greenshift-animation-and-page-builder-blocks Gutenverse – WordPress Blocks, Page Builder & Site Editor gutenverse Hash Form – Drag & Drop Form Builder hash-form HEL Online Classroom: AI-powered Online Classrooms hel-online-classroom InfusedWoo Pro infusedwooPRO JetBackup – Backup, Restore & Migrate backup JetEngine jet-engine Kadence Shop Kit kadence-shop-kit Kali Forms — Contact Form & Drag-and-Drop Builder kali-forms Kirki – Freeform Page Builder, Website Builder & Customizer kirki KiviCare – Clinic & Patient Management System (EHR) kivicare-clinic-management-system LeadConnector leadconnector LearnPress – Sepay Payment learnpress-sepay-payment LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress Like Button Rating LikeBtn likebtn-like-button Link Whisper Free link-whisper LiteSpeed Cache litespeed-cache LitExtension – Automated Store Migration & Import litextension-data-migration-to-woocommerce Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid magazine-blocks MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall malcare-security ManageWP Worker worker Mang Board WP mangboard MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system Media Library Assistant media-library-assistant Media Sweep – WordPress Media Cleaner media-sweep MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor metform miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon miniorange-login-openid Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce mobile-app-for-woocommerce MStore API – Create Native Android & iOS Apps On The Cloud mstore-api Music Player for WooCommerce music-player-for-woocommerce MW WP Form mw-wp-form My Agile Privacy® – CMP, Cookie Consent & Privacy Tools myagileprivacy MyHome Core myhome-core NewPath WildApricotPress Add-on – Member Directory newpath-wildapricotpress-add-on-member-directory Newsletters newsletters-lite Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist woocommerce-product-stock-alert One User Avatar | User Profile Picture one-user-avatar Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization optimole-wp Order Tip for WooCommerce order-tip-woo OwnerRez ownerrez Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress wp-user-avatar Passster – Password Protect Pages and Content content-protector Pods – Custom Content Types and Fields pods Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred mycred Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App post-smtp PPWP – Password Protect Pages password-protect-page Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages wplegalpages Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker wedevs-project-manager Push Notification for Post and BuddyPress push-notification-for-post-and-buddypress Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker quiz-master-next Rank Math SEO – AI SEO Tools to Dominate SEO Rankings seo-by-rank-math Realtyna Organic IDX plugin + WPL Real Estate real-estate-listing-realtyna-wpl RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login custom-registration-form-builder-with-submission-manager RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress computer-repair-shop RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) restrictmate Return Refund and Exchange For WooCommerce woo-refund-and-exchange-lite Reviews and Rating – Google Reviews g-business-reviews-rating Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons SAML Single Sign On – SSO Login miniorange-saml-20-single-sign-on Security Optimizer – The All-In-One Protection Plugin sg-security Shared Files Pro shared-files-pro Shared Files – File Upload & Download Manager shared-files ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets shopengine SigmaForms Pro – AI Generated Forms sigmaforms-pro Simple Newsletter Plugin – Noptin newsletter-optin-box Simple Payment simple-payment Slider Hero with Video Background, Animation slider-hero Smart Marketing SMS and Newsletters Forms smart-marketing-for-wp Smart Slider 3 smart-slider-3 SmartAIPress smartaipress SmilePass Selfie Login selfie-login SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert Smush – Image Optimization, Compression, Lazy Load, WebP & CDN wp-smushit SOGO Add Script to Individual Pages Header Footer oh-add-script-header-footer StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce storegrowth-sales-booster Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions wp-full-stripe-free Suggestion Engine for WooCommerce woo-suggestion-engine Super Store Finder superstorefinder-wp SureFeedback Client Site projecthuddle-child-site tagDiv Composer td-composer Tailored Tools tailored-tools Tamara Checkout tamara-checkout The WP Remote WordPress Plugin wpremote Throws SPAM Away throws-spam-away Tickera – Sell Tickets & Manage Events tickera-event-ticketing-system TranslatePress – Translate Multilingual sites with AI Translation translatepress-multilingual Tutor LMS – eLearning and online course solution tutor Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member UpdraftPlus: WP Backup & Migration Plugin updraftplus User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission wp-user-frontend User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor profile-builder User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder user-registration Visitor Traffic Real Time Statistics pro visitors-traffic-real-time-statistics-pro WCFM Marketplace – Multivendor Marketplace for WooCommerce wc-multivendor-marketplace WooCommerce Lottery woocommerce-lottery Workeera – AI Job Board with Applicant Tracking System (ATS) workeera-remote-tech-job-board WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses wp-courses WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards wp-data-access WP Fastest Cache – WordPress Cache Plugin wp-fastest-cache WP Job Portal – AI-Powered Recruitment System for Company or Job Board website wp-job-portal WP OAuth Server ( Login with WordPress ) miniorange-oauth-20-server WP Rocket wp-rocket WP Ultimate CSV Importer – WordPress CSV, XML & Excel Import wp-ultimate-csv-importer WP w3all phpBB wp-w3all-phpbb-integration WPBulky – WordPress Bulk Edit Post Types wpbulky-wp-bulk-edit-post-types WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System wp-cafe wpForo Forum wpforo WPMU DEV Dashboard wpmudev-updates WPvivid — Backup, Migration & Staging wpvivid-backuprestore 爱采集数据采集和发布插件 icollect WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug Avada | Website Builder For WordPress & WooCommerce Avada Betheme betheme CozyStay - Hotel Booking WordPress Theme cozystay Newspapers X newspapers-x Uncode uncode Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. ACPT (Premium) <= 2.0.63 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-32566 Patch Status Unpatched Published Aug 25, 2026 Affected Software ACPT (Premium) [advanced-custom-post-type] Researcher VDsec More Details > Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-18431 Patch Status Patched Published Aug 25, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Avada | Website Builder For WordPress & WooCommerce [Avada] Researchers Alex Thomas Wordfence Argus More Details > Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15369 Patch Status Patched Published Aug 29, 2026 Affected Software Custom User Registration Fields for WooCommerce [user-registration-plugin-for-woocommerce] Researcher 0xd4rk5id3 More Details > Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated Remote Code Execution 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-18781 Patch Status Patched Published Aug 24, 2026 Affected Software Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] Researcher Jakub Herman More Details > ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-18080 Patch Status Patched Published Aug 25, 2026 Affected Software ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce [erp] Researcher Talal Nasraddeen More Details > GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-82222 Patch Status Patched Published Aug 28, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher Udin Chan More Details > Hash Form – Drag & Drop Form Builder <= 1.4.2 - Unauthenticated Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-81780 Patch Status Patched Published Aug 28, 2026 Affected Software Hash Form – Drag & Drop Form Builder [hash-form] Researcher CoryRoo More Details > Kirki – Freeform Page Builder, Website Builder & Customizer < 6.2.1 - Unauthenticated Remote Code Execution 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-16747 Patch Status Patched Published Aug 24, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Jakub Herman More Details > ManageWP Worker < 4.9.37 - Authentication Bypass 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-18052 Patch Status Patched Published Aug 25, 2026 Affected Software ManageWP Worker [worker] Researcher Jakub Herman More Details > MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15980 Patch Status Patched Published Aug 29, 2026 Affected Software MyHome Core [myhome-core] Researcher Rafie Muhammad More Details > Newspapers X 1.0.46 - 1.0.48 - Backdoor 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-81779 Patch Status Patched Published Aug 28, 2026 Affected Software Newspapers X [newspapers-x] Researcher ashv4ni More Details > Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-14494 Patch Status Patched Published Aug 28, 2026 Affected Software SigmaForms Pro – AI Generated Forms [sigmaforms-pro] Researcher d.v4n_s3c More Details > SmilePass Selfie Login <= 1.0.2 - Authentication Bypass to Administrator 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-77002 Patch Status Unpatched Published Aug 26, 2026 Affected Software SmilePass Selfie Login [selfie-login] Researcher Khaled Alenazi More Details > SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery < 3.9.8 - Authentication Bypass via Account Takeover 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15206 Patch Status Patched Published Aug 24, 2026 Affected Software SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery [sms-alert] Researcher Sai Praneeth Koti More Details > The WP Remote WordPress Plugin, Malcare Security, and BlogVault Backup & Staging < 6.65 - Unauthenticated Site Takeover via Brute Force 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-19718 Patch Status Patched Published Aug 24, 2026 Affected Software BlogVault Backup & Staging [blogvault-real-time-backup] MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall [malcare-security] The WP Remote WordPress Plugin [wpremote] Researcher Jakub Herman More Details > TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-19632 Patch Status Patched Published Aug 25, 2026 Affected Software TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] Researcher Yuto Hyakumoto More Details > WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-76581 Patch Status Patched Published Aug 27, 2026 Affected Software WPMU DEV Dashboard [wpmudev-updates] Researchers Alex Thomas Wordfence Argus More Details > Shared Files Pro < 1.7.68 & Shared Files Free < 1.7.67 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-12513 Patch Status Patched Published Aug 28, 2026 Affected Software Shared Files – File Upload & Download Manager [shared-files] Shared Files Pro [shared-files-pro] Researcher Huynh Kien Minh More Details > All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-19949 Patch Status Patched Published Aug 24, 2026 Affected Software All-in-One WP Migration and Backup [all-in-one-wp-migration] Researcher Jack Taylor More Details > CM Map Locations <= 2.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via cmloc_route_image_upload AJAX Action 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-16601 Patch Status Patched Published Aug 24, 2026 Affected Software CM Map Locations – Visualize and share your locations in a few clicks [cm-map-locations] Researcher Spy0x7 More Details > InfusedWoo Pro <= 5.1.18 - Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-19892 Patch Status Patched Published Aug 24, 2026 Affected Software InfusedWoo Pro [infusedwooPRO] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-75977 Patch Status Patched Published Aug 25, 2026 Affected Software Mang Board WP [mangboard] Researcher daroo More Details > Pods – Custom Content Types and Fields < 3.3.9.1 - Authenticated (Author+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-74851 Patch Status Patched Published Aug 28, 2026 Affected Software Pods – Custom Content Types and Fields [pods] Researcher Tyler Chin More Details > Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.276 - Authenticated (Author+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-81757 Patch Status Patched Published Aug 27, 2026 Affected Software Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] Researcher Ananda Dhakal More Details > Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-77018 Patch Status Patched Published Aug 27, 2026 Affected Software Workeera – AI Job Board with Applicant Tracking System (ATS) [workeera-remote-tech-job-board] Researcher Erwan LR More Details > Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-15985 Patch Status Patched Published Aug 25, 2026 Affected Software Classified Listing - Mobile Number Verification [rtcl-verification] Researcher Rafie Muhammad More Details > FluentCart A New Era of eCommerce <= 1.6.2 - Authenticated (Custom+) Arbitrary File Deletion via 'file_path' Parameter 8.1 CVSS Rating 8.1 (High) Patch Status Patched Published Aug 24, 2026 Affected Software FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler [fluent-cart] Researcher Wordfence PRISM More Details > Geo Controller <= 8.9.8 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-78286 Patch Status Patched Published Aug 25, 2026 Affected Software Geo Controller [cf-geoplugin] Researcher Supakiad S. More Details > Hash Form – Drag & Drop Form Builder <= 1.4.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-78292 Patch Status Patched Published Aug 25, 2026 Affected Software Hash Form – Drag & Drop Form Builder [hash-form] Researcher Supakiad S. More Details > Tickera – Sell Tickets & Manage Events <= 3.6.0.2 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-82226 Patch Status Patched Published Aug 28, 2026 Affected Software Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system] Researcher Ionut Pipirig More Details > Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-77016 Patch Status Patched Published Aug 25, 2026 Affected Software Workeera – AI Job Board with Applicant Tracking System (ATS) [workeera-remote-tech-job-board] Researchers Artus KG Shhriyash More Details > Beautiful taxonomy filters <= 2.4.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-78288 Patch Status Patched Published Aug 25, 2026 Affected Software Beautiful taxonomy filters [beautiful-taxonomy-filters] Researcher JunHee CHO More Details > Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.5 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-78257 Patch Status Patched Published Aug 25, 2026 Affected Software Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] Researcher daroo More Details > Document Embedder – let visitors read files without downloading < 2.3.1 - Unauthenticated Arbitrary Document Download 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-16567 Patch Status Patched Published Aug 28, 2026 Affected Software Document Embedder – let visitors read files without downloading [document-emberdder] Researcher Vaibhav Narkhede More Details > ePayco plugin for WooCommerce <= 8.4.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-78260 Patch Status Patched Published Aug 25, 2026 Affected Software ePayco plugin for WooCommerce [epayco-gateway] Researcher Lee chul woong More Details > Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-15990 Patch Status Patched Published Aug 26, 2026 Affected Software Formidable Charts [formidable-charts] Researcher Rafie Muhammad More Details > One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-18983 Patch Status Patched Published Aug 27, 2026 Affected Software One User Avatar | User Profile Picture [one-user-avatar] Researcher Dthangws More Details > SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-75807 Patch Status Patched Published Aug 29, 2026 Affected Software SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] Researchers Tanishq Shah Thatchapol Booranatanit (AliceZz) More Details > Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-81756 Patch Status Patched Published Aug 28, 2026 Affected Software Smart Marketing SMS and Newsletters Forms [smart-marketing-for-wp] Researcher Supakiad S. More Details > Smush – Image Optimization, Compression, Lazy Load, WebP & CDN <= 4.2.0 - Unauthenticated Denial of Service 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-81285 Patch Status Patched Published Aug 27, 2026 Affected Software Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] Researcher Asim Alshaya More Details > Throws SPAM Away <= 3.8.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-81763 Patch Status Patched Published Aug 28, 2026 Affected Software Throws SPAM Away [throws-spam-away] Researcher Jiemook More Details > Tutor LMS – eLearning and online course solution < 4.0.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-19094 Patch Status Patched Published Aug 24, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher Jakub Herman More Details > Visitor Traffic Real Time Statistics pro <= 11.17 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-32479 Patch Status Patched Published Aug 25, 2026 Affected Software Visitor Traffic Real Time Statistics pro [visitors-traffic-real-time-statistics-pro] Researcher Trương Hữu Phúc More Details > WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-18884 Patch Status Patched Published Aug 25, 2026 Affected Software WooCommerce Lottery [woocommerce-lottery] Researcher h0xilo More Details > WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards <= 5.5.81 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-81293 Patch Status Patched Published Aug 28, 2026 Affected Software WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards [wp-data-access] Researcher sequence_X0 More Details > wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-5097 Patch Status Patched Published Aug 27, 2026 Affected Software wpForo Forum [wpforo] Researcher Leonid Semenenko (lsemenenko) More Details > 爱采集数据采集和发布插件 <= 1.0.0 - Unauthenticated Arbitrary File Read 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-77012 Patch Status Unpatched Published Aug 27, 2026 Affected Software 爱采集数据采集和发布插件 [icollect] Researchers Pablo González Pérez Francisco José Ramírez Vicente Iñigo Sánchez Enciso More Details > Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-76586 Patch Status Patched Published Aug 29, 2026 Affected Software Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress [bookingpress-appointment-booking] Researcher Nguyen Phuoc Thinh More Details > Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.1 - Unauthenticated Privilege Escalation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-19220 Patch Status Patched Published Aug 28, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher Jakub Herman More Details > HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Settings Update 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-77008 Patch Status Unpatched Published Aug 27, 2026 Affected Software HEL Online Classroom: AI-powered Online Classrooms [hel-online-classroom] Researcher kimsunghoon More Details > Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-19848 Patch Status Patched Published Aug 28, 2026 Affected Software Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar] Researcher Jakub Herman More Details > RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.9.8 - Authentication Bypass 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-82225 Patch Status Patched Published Aug 28, 2026 Affected Software RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login [custom-registration-form-builder-with-submission-manager] Researcher emiliano carrizo More Details > RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) < 1.3.0 - Unauthenticated Privilege Escalation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-13598 Patch Status Patched Published Aug 27, 2026 Affected Software RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) [restrictmate] Researcher João Ramos Maciel More Details > Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-19423 Patch Status Patched Published Aug 28, 2026 Affected Software Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] Researcher Jakub Herman More Details > 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78333 Patch Status Patched Published Aug 28, 2026 Affected Software 12 Step Meeting List [12-step-meeting-list] Researcher Huseyn More Details > Affiliate Program Suite — SliceWP Affiliates <= 1.2.10 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-82224 Patch Status Patched Published Aug 28, 2026 Affected Software Affiliate Program Suite — SliceWP Affiliates [slicewp] Researcher daroo More Details > Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates < 2.7.2 - Unauthenticated Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-17565 Patch Status Patched Published Aug 28, 2026 Affected Software Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates [animation-addons-for-elementor] Researcher Seongwon Lee More Details > Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-6286 Patch Status Patched Published Aug 27, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Lucas Montes (NiRoX) More Details > CozyStay - Hotel Booking WordPress Theme <= 1.10.0 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78289 Patch Status Patched Published Aug 25, 2026 Affected Software CozyStay - Hotel Booking WordPress Theme [cozystay] Researcher G0053 More Details > CP Media Player – Audio Player and Video Player <= 1.3.0 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78281 Patch Status Patched Published Aug 25, 2026 Affected Software CP Media Player – Audio Player and Video Player [audio-and-video-player] Researcher dutafi More Details > Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-6176 Patch Status Patched Published Aug 27, 2026 Affected Software Customer Reviews for WooCommerce [customer-reviews-woocommerce] Researcher daroo More Details > Defender Security – Malware Scanner, Login Security & Firewall < 6.2.0 - Authenticated (Administrator+) Remote Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-19225 Patch Status Patched Published Aug 27, 2026 Affected Software Defender Security – Malware Scanner, Login Security & Firewall [defender-security] Researcher Jakub Herman More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Authenticated (Shop Manager+) Remote Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-16576 Patch Status Patched Published Aug 28, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher Khaled Alenazi More Details > Email Essentials <= 6.0.6 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81764 Patch Status Patched Published Aug 28, 2026 Affected Software Email Essentials [email-essentials] Researcher JunHee CHO More Details > Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress <= 5.9.33 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81290 Patch Status Patched Published Aug 27, 2026 Affected Software Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress [email-subscribers] Researcher Jiemook More Details > Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) Arbitrary File Upload 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78274 Patch Status Patched Published Aug 26, 2026 Affected Software Fluent Boards Pro [fluent-boards-pro] Researcher Ananda Dhakal More Details > FluentCRM Pro <= 3.1.12 - Authenticated (Editor+) Privilege Escalation 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78271 Patch Status Patched Published Aug 25, 2026 Affected Software FluentCRM PRO [fluentcampaign-pro] Researcher Ananda Dhakal More Details > Formidable Forms <= 6.33.1 - Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-18331 Patch Status Patched Published Aug 25, 2026 Affected Software Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] Researcher daroo More Details > Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.0.5 - Authenticated (Administrator+) Remote Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-19221 Patch Status Patched Published Aug 27, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher Jakub Herman More Details > Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-18328 Patch Status Patched Published Aug 24, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher Adrien Brunner More Details > Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-18324 Patch Status Patched Published Aug 27, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher daroo More Details > Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-18323 Patch Status Patched Published Aug 24, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher daroo More Details > JetEngine <= 3.8.14.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81760 Patch Status Patched Published Aug 27, 2026 Affected Software JetEngine [jet-engine] Researcher dutafi More Details > LeadConnector <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81298 Patch Status Patched Published Aug 28, 2026 Affected Software LeadConnector [leadconnector] Researcher daroo More Details > LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-18978 Patch Status Patched Published Aug 27, 2026 Affected Software LiteSpeed Cache [litespeed-cache] Researcher Jack Taylor More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.43 - Unauthenticated Open Redirect 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81342 Patch Status Patched Published Aug 27, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher Abiodun Victor More Details > Music Player for WooCommerce <= 1.8.9 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78283 Patch Status Patched Published Aug 25, 2026 Affected Software Music Player for WooCommerce [music-player-for-woocommerce] Researcher daroo More Details > Optimole <= 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-77365 Patch Status Patched Published Aug 27, 2026 Affected Software Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization [optimole-wp] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Realtyna Organic IDX plugin + WPL Real Estate <= 5.4.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78261 Patch Status Patched Published Aug 25, 2026 Affected Software Realtyna Organic IDX plugin + WPL Real Estate [real-estate-listing-realtyna-wpl] Researcher Aydan Arabadzha More Details > ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-75971 Patch Status Patched Published Aug 24, 2026 Affected Software ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets [shopengine] Researcher Wordfence PRISM More Details > Slider Hero with Video Background, Animation < 9.1.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-76789 Patch Status Patched Published Aug 28, 2026 Affected Software Slider Hero with Video Background, Animation [slider-hero] Researcher Artus KG More Details > Smush – Image Optimization, Compression, Lazy Load, WebP & CDN < 4.3.2 - Authenticated (Administrator+) Remote Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-19223 Patch Status Patched Published Aug 27, 2026 Affected Software Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] Researcher Jakub Herman More Details > Social Login, Social Sharing by miniOrange <= 7.8.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-82229 Patch Status Patched Published Aug 28, 2026 Affected Software miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon [miniorange-login-openid] Researcher Ananda Dhakal More Details > Super Store Finder <= 7.10 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81768 Patch Status Patched Published Aug 28, 2026 Affected Software Super Store Finder [superstorefinder-wp] Researcher dutafi More Details > Tailored Tools <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81765 Patch Status Patched Published Aug 28, 2026 Affected Software Tailored Tools [tailored-tools] Researcher V1T More Details > TranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-76053 Patch Status Patched Published Aug 27, 2026 Affected Software TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] Researcher daroo More Details > Uncode <= 2.12.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81291 Patch Status Patched Published Aug 27, 2026 Affected Software Uncode [uncode] Researcher Nguyen Ba Khanh More Details > WP Fastest Cache <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting via HTTP Host Header 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-19760 Patch Status Patched Published Aug 25, 2026 Affected Software WP Fastest Cache – WordPress Cache Plugin [wp-fastest-cache] Researcher Adrien Brunner More Details > WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-5934 Patch Status Patched Published Aug 27, 2026 Affected Software WP Rocket [wp-rocket] Researchers Tin Pham (TF1T) Trong Pham (dtro) Hao Ngo More Details > WP w3all phpBB <= 3.0.6 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-78293 Patch Status Patched Published Aug 25, 2026 Affected Software WP w3all phpBB [wp-w3all-phpbb-integration] Researcher lanlv More Details > WPvivid — Backup, Migration & Staging < 0.9.133 - Authenticated (Administrator+) Remote Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-19722 Patch Status Patched Published Aug 30, 2026 Affected Software WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] Researcher Nir Yehoshua More Details > Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-14280 Patch Status Patched Published Aug 24, 2026 Affected Software Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] Researcher Wordfence PRISM More Details > Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-78276 Patch Status Patched Published Aug 26, 2026 Affected Software Fluent Boards Pro [fluent-boards-pro] Researcher Ananda Dhakal More Details > User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission < 4.3.10 - Authenticated (Editor+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-14558 Patch Status Patched Published Aug 28, 2026 Affected Software User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] Researcher Hijun Kim More Details > User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Administrator+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-76547 Patch Status Patched Published Aug 29, 2026 Affected Software User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] Researcher Vivien LEBAS More Details > ACPT (Premium) <= 2.0.63 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-32564 Patch Status Unpatched Published Aug 25, 2026 Affected Software ACPT (Premium) [advanced-custom-post-type] Researcher VDsec More Details > AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.3.3 - 3.7.1 - Authenticated (Subscriber+) Arbitrary File Read 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-75797 Patch Status Patched Published Aug 27, 2026 Affected Software AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] Researcher Jashid Sany More Details > Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-15023 Patch Status Patched Published Aug 24, 2026 Affected Software Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] Researcher Dmitrii Ignatyev More Details > Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) Arbitrary File Deletion 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-78275 Patch Status Patched Published Aug 26, 2026 Affected Software Fluent Boards Pro [fluent-boards-pro] Researcher Ananda Dhakal More Details > FluentCRM Pro <= 3.1.12 - Authenticated (Author+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-78270 Patch Status Patched Published Aug 24, 2026 Affected Software FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluentcrm-pro] Researcher Ananda Dhakal More Details > Kadence Shop Kit <= 3.0.6 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-32550 Patch Status Patched Published Aug 25, 2026 Affected Software Kadence Shop Kit [kadence-shop-kit] Researcher dutafi More Details > Like Button Rating LikeBtn <= 2.6.61 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-78285 Patch Status Patched Published Aug 25, 2026 Affected Software Like Button Rating LikeBtn [likebtn-like-button] Researcher daroo More Details > Media Library Assistant < 3.40 - Authenticated (Author+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-16959 Patch Status Patched Published Aug 24, 2026 Affected Software Media Library Assistant [media-library-assistant] Researcher João Ramos Maciel More Details > Order Tip for WooCommerce < 1.6.0 - Authenticated (Shop Manager+) Arbitrary File Deletion 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-77693 Patch Status Patched Published Aug 24, 2026 Affected Software Order Tip for WooCommerce [order-tip-woo] Researcher Shikhali Jamalzade More Details > Suggestion Engine for WooCommerce <= 2.0.11 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-81277 Patch Status Patched Published Aug 26, 2026 Affected Software Suggestion Engine for WooCommerce [woo-suggestion-engine] Researcher JunHee CHO More Details > Tutor LMS – eLearning and online course solution < 4.0.6 - Authenticated (Custom Role+) Arbitrary File Read 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-19093 Patch Status Patched Published Aug 28, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher Sai Praneeth Koti More Details > Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-16759 Patch Status Patched Published Aug 27, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher Slopothecary More Details > Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Read 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-77017 Patch Status Patched Published Aug 27, 2026 Affected Software Workeera – AI Job Board with Applicant Tracking System (ATS) [workeera-remote-tech-job-board] Researchers Artus KG Shhriyash More Details > WPBulky – WordPress Bulk Edit Post Types <= 1.2.2 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-82227 Patch Status Patched Published Aug 28, 2026 Affected Software WPBulky – WordPress Bulk Edit Post Types [wpbulky-wp-bulk-edit-post-types] Researcher JunHee CHO More Details > All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6128 Patch Status Patched Published Aug 27, 2026 Affected Software All-in-One WP Migration Unlimited Extension [all-in-one-wp-migration-unlimited-extension] Researcher Rafie Muhammad More Details > Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-16654 Patch Status Patched Published Aug 27, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher João Pedro Soares de Alcântara More Details > Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6178 Patch Status Patched Published Aug 25, 2026 Affected Software Betheme [betheme] Researcher João Pedro Soares de Alcântara More Details > Cozy Blocks <= 2.2.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via cozyHoverEffect Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-75019 Patch Status Patched Published Aug 24, 2026 Affected Software Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates [cozy-addons] Researcher Wordfence PRISM More Details > eCommerce Product Catalog <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-76128 Patch Status Patched Published Aug 24, 2026 Affected Software eCommerce Product Catalog [ecommerce-product-catalog] Researcher Wordfence PRISM More Details > Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3423 Patch Status Patched Published Aug 27, 2026 Affected Software Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More [envira-gallery-lite] Researcher lord willmore More Details > Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.21 - Authenticated (Contributor+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13176 Patch Status Patched Published Aug 24, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Yaswanth Reddy Sunkara More Details > Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-78273 Patch Status Patched Published Aug 26, 2026 Affected Software Fluent Boards Pro [fluent-boards-pro] Researcher Ananda Dhakal More Details > FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-76063 Patch Status Patched Published Aug 24, 2026 Affected Software FundEngine – Donation and Crowdfunding Platform [wp-fundraising-donation] Researcher Wordfence PRISM More Details > GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5510 Patch Status Patched Published Aug 27, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher daroo More Details > Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5092 Patch Status Patched Published Aug 25, 2026 Affected Software Greenshift – animation and page builder blocks [greenshift-animation-and-page-builder-blocks] Researchers Athiwat Tiprasaharn (Jitlada) Itthidej Aramsri (Boeing777) More Details > Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-19943 Patch Status Patched Published Aug 24, 2026 Affected Software Gutenverse – WordPress Blocks, Page Builder & Site Editor [gutenverse] Researcher Wordfence PRISM More Details > Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3002 Patch Status Patched Published Aug 25, 2026 Affected Software Gutenverse – WordPress Blocks, Page Builder & Site Editor [gutenverse] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3129 Patch Status Patched Published Aug 27, 2026 Affected Software LiteSpeed Cache [litespeed-cache] Researcher stealthcopter More Details > Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-78290 Patch Status Patched Published Aug 24, 2026 Affected Software Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid [magazine-blocks] Researcher sungbyeongchan More Details > MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-18100 Patch Status Patched Published Aug 24, 2026 Affected Software MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] Researcher Jonah Burgess (CryptoCat) More Details > Password Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-9878 Patch Status Patched Published Aug 24, 2026 Affected Software PPWP – Password Protect Pages [password-protect-page] Researcher Dmitrii Ignatyev More Details > Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2388 Patch Status Unpatched Published Aug 25, 2026 Affected Software Reviews and Rating – Google Reviews [g-business-reviews-rating] Researcher Muhammad Yudha - DJ More Details > Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-19226 Patch Status Patched Published Aug 26, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Erwan LR More Details > Shared Files – File Upload & Download Manager <= 1.7.69 - Authenticated (Contributor+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-78269 Patch Status Patched Published Aug 24, 2026 Affected Software Shared Files – File Upload & Download Manager [shared-files] Researcher Cem Bas More Details > Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15798 Patch Status Patched Published Aug 27, 2026 Affected Software Smart Slider 3 [smart-slider-3] Researcher Dmitrii Ignatyev More Details > SmartAIPress <= 1.2.0 - Authenticated (Subscriber+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-16600 Patch Status Unpatched Published Aug 29, 2026 Affected Software SmartAIPress [smartaipress] Researcher Benjamin Aguayo More Details > SOGO Add Script to Individual Pages Header Footer <= 3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-14835 Patch Status Unpatched Published Aug 30, 2026 Affected Software SOGO Add Script to Individual Pages Header Footer [oh-add-script-header-footer] Researcher Chamseddine Bouzaiene More Details > tagDiv Composer <= 5.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12561 Patch Status Unpatched Published Aug 24, 2026 Affected Software tagDiv Composer [td-composer] Researcher Truoc Phan More Details > TranslatePress <= 3.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-18512 Patch Status Patched Published Aug 24, 2026 Affected Software TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] Researcher Yuto Hyakumoto More Details > Ultimate Member <= 2.12.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-18547 Patch Status Patched Published Aug 24, 2026 Affected Software Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] Researcher tiborisaak More Details > User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-76546 Patch Status Patched Published Aug 29, 2026 Affected Software User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] Researcher Muni Nitish Kumar Yaddala More Details > Booking for Appointments and Events Calendar – Amelia 9.0 - 9.7 - Authenticated (Provider+) Arbitrary Provider Password Update 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-14212 Patch Status Patched Published Aug 28, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Haitam Lazaar More Details > Fluent Forms Pro Add On Pack <= 6.2.12 - Authenticated (Subscriber+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-81297 Patch Status Patched Published Aug 28, 2026 Affected Software Fluent Forms Pro Add On Pack [fluentformpro] Researcher Ananda Dhakal More Details > Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.0.7 - Authenticated (Custom Role+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-19222 Patch Status Patched Published Aug 28, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher Thanh Lam Tang More Details > MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-18234 Patch Status Patched Published Aug 27, 2026 Affected Software MStore API – Create Native Android & iOS Apps On The Cloud [mstore-api] Researcher Erwan LR More Details > Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App 4.0.0-beta.1 - Missing Authorization to Authenticated (Subscriber+) Settings Change 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-81278 Patch Status Patched Published Aug 26, 2026 Affected Software Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] Researcher mad4cyber More Details > User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.6 - Authenticated (Custom Role+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-79996 Patch Status Patched Published Aug 28, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researcher Artus KG More Details > ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-4246 Patch Status Patched Published Aug 27, 2026 Affected Software ElementsKit Pro [elementskit] Researcher Ren Voza More Details > Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-17089 Patch Status Patched Published Aug 24, 2026 Affected Software Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] Researcher Wordfence PRISM More Details > GeotargetingWP < 3.5.6.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-14307 Patch Status Patched Published Aug 28, 2026 Affected Software GeotargetingWP [geotargetingwp] Researcher andrew gomez More Details > AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.4.0 - 3.7.1 - Missing Authorization to Unauthenticated Arbitrary AI Query Execution 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-75798 Patch Status Patched Published Aug 28, 2026 Affected Software AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] Researcher Abdullah Kareem More Details > Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78258 Patch Status Patched Published Aug 24, 2026 Affected Software Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] Researcher Bao More Details > Booking for Appointments and Events Calendar – Amelia < 2.4.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-14216 Patch Status Patched Published Aug 26, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Manuel Martínez Casasola More Details > Booking Package < 1.7.25 - Unauthenticated Price Manipulation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-16986 Patch Status Patched Published Aug 24, 2026 Affected Software Booking Package [booking-package] Researcher Muni Nitish Kumar Yaddala More Details > Breeze Cache < 2.5.13 - Unauthenticated File Creation via Path Traversal 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-79706 Patch Status Patched Published Aug 28, 2026 Affected Software Breeze Cache [breeze] Researcher Jakub Herman More Details > Catfolders Document Gallery Pro < 2.0.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-19430 Patch Status Patched Published Aug 29, 2026 Affected Software Catfolders Document Gallery Pro [catfolders-document-gallery-pro] Researcher Shikhali Jamalzade More Details > CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Missing Authorization to Unauthenticated Settings Change 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13414 Patch Status Patched Published Aug 27, 2026 Affected Software CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] Researcher Revanth Hari Narayana Matte More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-16575 Patch Status Patched Published Aug 24, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher Usama Arshad More Details > Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.8.0 - Unauthenticated Captcha Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81777 Patch Status Patched Published Aug 27, 2026 Affected Software Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] Researcher Gaurav popalghat More Details > Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.19 - Unauthenticated Order Completion 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77694 Patch Status Patched Published Aug 24, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Nir Yehoshua More Details > Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.22 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13172 Patch Status Patched Published Aug 26, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Meher Sudhakar Abbireddi More Details > Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-10627 Patch Status Patched Published Aug 24, 2026 Affected Software Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] Researcher molten bit More Details > Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5096 Patch Status Patched Published Aug 27, 2026 Affected Software Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI [everest-forms] Researcher h0xilo More Details > FiboSearch – Ajax Search for WooCommerce < 1.34.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-16612 Patch Status Patched Published Aug 25, 2026 Affected Software FiboSearch – Ajax Search for WooCommerce [ajax-search-for-woocommerce] Researcher Duy Tran More Details > Fluent Forms Pro Add On Pack <= 6.2.12 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81296 Patch Status Patched Published Aug 28, 2026 Affected Software Fluent Forms Pro Add On Pack [fluentformpro] Researcher Ananda Dhakal More Details > Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.57.1 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82220 Patch Status Patched Published Aug 28, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher Ahmed Hassan More Details > HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77007 Patch Status Unpatched Published Aug 29, 2026 Affected Software HEL Online Classroom: AI-powered Online Classrooms [hel-online-classroom] Researcher kimsunghoon More Details > Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.23 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81276 Patch Status Patched Published Aug 26, 2026 Affected Software Kali Forms — Contact Form & Drag-and-Drop Builder [kali-forms] Researcher sungbyeongchan More Details > Kirki – Freeform Page Builder, Website Builder & Customizer < 6.0.14 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77754 Patch Status Patched Published Aug 26, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Vaibhav Narkhede More Details > KiviCare – Clinic & Patient Management System (EHR) <= 4.5.4 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13611 Patch Status Patched Published Aug 28, 2026 Affected Software KiviCare – Clinic & Patient Management System (EHR) [kivicare-clinic-management-system] Researcher Sai Praneeth Koti More Details > LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78125 Patch Status Patched Published Aug 25, 2026 Affected Software LearnPress – Sepay Payment [learnpress-sepay-payment] Researcher Shikhali Jamalzade More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.40 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81026 Patch Status Patched Published Aug 27, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher Abdullah Kareem More Details > Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce <= 0.4.62 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27330 Patch Status Patched Published Aug 25, 2026 Affected Software Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce [mobile-app-for-woocommerce] Researcher Phat RiO More Details > My Agile Privacy® <= 3.3.6 - Missing Authorization to Unauthenticated Plugin Settings Modification via map_missing_cookie_shield / map_check_consent_mode_status AJAX Actions 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-17587 Patch Status Patched Published Aug 24, 2026 Affected Software My Agile Privacy® – CMP, Cookie Consent & Privacy Tools [myagileprivacy] Researcher Wordfence PRISM More Details > NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13736 Patch Status Unpatched Published Aug 24, 2026 Affected Software NewPath WildApricotPress Add-on – Member Directory [newpath-wildapricotpress-add-on-member-directory] Researcher Huynh Kien Minh More Details > Newsletters < 4.17 - Insufficient Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-17520 Patch Status Patched Published Aug 27, 2026 Affected Software Newsletters [newsletters-lite] Researcher Erwan LR More Details > Passster – Password Protect Pages and Content < 4.3.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-17559 Patch Status Patched Published Aug 24, 2026 Affected Software Passster – Password Protect Pages and Content [content-protector] Researcher Erwan LR More Details > Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred < 3.2.5 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-15150 Patch Status Patched Published Aug 24, 2026 Affected Software Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred [mycred] Researcher Muni Nitish Kumar Yaddala More Details > Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages < 3.7.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-16984 Patch Status Patched Published Aug 28, 2026 Affected Software Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages [wplegalpages] Researcher Vaibhav Narkhede More Details > Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-74928 Patch Status Patched Published Aug 24, 2026 Affected Software Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker [wedevs-project-manager] Researcher Usama Arshad More Details > RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1223 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78291 Patch Status Patched Published Aug 24, 2026 Affected Software RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress [computer-repair-shop] Researcher Supakiad S. More Details > Return Refund and Exchange For WooCommerce < 4.6.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77695 Patch Status Patched Published Aug 28, 2026 Affected Software Return Refund and Exchange For WooCommerce [woo-refund-and-exchange-lite] Researcher Shikhali Jamalzade More Details > Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13406 Patch Status Patched Published Aug 26, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Meher Sudhakar Abbireddi More Details > Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Unauthenticated Like Count Manipulation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13404 Patch Status Patched Published Aug 24, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Shivamani Vastrala More Details > Security Optimizer – The All-In-One Protection Plugin <= 1.6.6 - 2-Factor Authentication Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82228 Patch Status Patched Published Aug 28, 2026 Affected Software Security Optimizer – The All-In-One Protection Plugin [sg-security] Researcher Ananda Dhakal More Details > Shared Files Pro < 1.7.70 & Shared Files Free < 1.7.67 - Unauthenticated Limited File Upload 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12514 Patch Status Patched Published Aug 26, 2026 Affected Software Shared Files – File Upload & Download Manager [shared-files] Shared Files Pro [shared-files-pro] Researcher hoangphuong More Details > Simple Newsletter Plugin – Noptin < 4.3.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78146 Patch Status Patched Published Aug 26, 2026 Affected Software Simple Newsletter Plugin – Noptin [newsletter-optin-box] Researcher Shivamani Vastrala More Details > Simple Payment <= 2.5.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81767 Patch Status Patched Published Aug 28, 2026 Affected Software Simple Payment [simple-payment] Researcher JunHee CHO More Details > StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78137 Patch Status Patched Published Aug 28, 2026 Affected Software StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce [storegrowth-sales-booster] Researcher Shikhali Jamalzade More Details > Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions < 8.5.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77758 Patch Status Patched Published Aug 24, 2026 Affected Software Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions [wp-full-stripe-free] Researcher Vaibhav Narkhede More Details > Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions < 8.5.1 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77789 Patch Status Patched Published Aug 24, 2026 Affected Software Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions [wp-full-stripe-free] Researcher Charles Vosburgh More Details > Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions < 8.5.5 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-80311 Patch Status Patched Published Aug 27, 2026 Affected Software Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions [wp-full-stripe-free] Researcher Farid Narimanov More Details > Tamara Checkout <= 1.9.9.20 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-16962 Patch Status Patched Published Aug 24, 2026 Affected Software Tamara Checkout [tamara-checkout] Researcher Ezekiel Victor More Details > User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission < 4.3.10 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-14567 Patch Status Patched Published Aug 28, 2026 Affected Software User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] Researcher Revanth Hari Narayana Matte More Details > WCFM Marketplace – Multivendor Marketplace for WooCommerce < 3.8.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Refund Request 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77701 Patch Status Patched Published Aug 26, 2026 Affected Software WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] Researcher Shikhali Jamalzade More Details > WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3235 Patch Status Patched Published Aug 25, 2026 Affected Software WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards [wp-data-access] Researcher type5afe More Details > WP OAuth Server ( Login with WordPress ) < 6.3.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-19715 Patch Status Patched Published Aug 28, 2026 Affected Software WP OAuth Server ( Login with WordPress ) [miniorange-oauth-20-server] Researcher Farid Narimanov More Details > WP Rocket 3.23.1 - 3.23.3.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) Patch Status Patched Published Aug 28, 2026 Affected Software WP Rocket [wp-rocket] Researcher(s): Unknown More Details > WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System < 3.0.18 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-14550 Patch Status Patched Published Aug 26, 2026 Affected Software WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] Researcher ABIODUN VICTOR TAIWO More Details > JetBackup – Backup, Restore & Migrate 3.1.18.8 - 3.1.23.3 - Authenticated (Admin+) Backup Download 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-19454 Patch Status Patched Published Aug 25, 2026 Affected Software JetBackup – Backup, Restore & Migrate [backup] Researcher Akshat Parikh More Details > Link Whisper Free < 0.9.7 - Authenticated (Editor+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-14601 Patch Status Patched Published Aug 24, 2026 Affected Software Link Whisper Free [link-whisper] Researcher huytqtq More Details > Media Sweep <= 1.1.3 - Authenticated (Administrator+) SQL Injection via 'fields' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-77824 Patch Status Patched Published Aug 24, 2026 Affected Software Media Sweep – WordPress Media Cleaner [media-sweep] Researcher Wordfence PRISM More Details > RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login < 6.0.9.4 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-77790 Patch Status Patched Published Aug 26, 2026 Affected Software RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login [custom-registration-form-builder-with-submission-manager] Researcher Meher Sudhakar Abbireddi More Details > WP Ultimate CSV Importer – WordPress CSV, XML & Excel Import < 9.0 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-80488 Patch Status Patched Published Aug 29, 2026 Affected Software WP Ultimate CSV Importer – WordPress CSV, XML & Excel Import [wp-ultimate-csv-importer] Researcher Jaan Buerms More Details > AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.0 - Authenticated (Administrator+) Privilege Escalation 4.7 CVSS Rating 4.7 (Medium) CVE-ID CVE-2026-75796 Patch Status Patched Published Aug 24, 2026 Affected Software AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] Researcher Charles Vosburgh More Details > CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Authenticated (Editor+) Privilege Escalation 4.7 CVSS Rating 4.7 (Medium) CVE-ID CVE-2026-13415 Patch Status Patched Published Aug 28, 2026 Affected Software CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] Researcher Revanth Hari Narayana Matte More Details > CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Authenticated (Editor+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-13416 Patch Status Patched Published Aug 25, 2026 Affected Software CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] Researcher Revanth Hari Narayana Matte More Details > Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Authenticated (Administrator+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-14325 Patch Status Patched Published Aug 24, 2026 Affected Software Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] Researcher Sai Praneeth Koti More Details > LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-75982 Patch Status Patched Published Aug 24, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researcher Wordfence PRISM More Details > MW WP Form < 5.1.6 - Authenticated (Editor+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-78364 Patch Status Patched Published Aug 28, 2026 Affected Software MW WP Form [mw-wp-form] Researcher Sai Praneeth Koti More Details > Advanced Custom Fields: Extended <= 0.9.2.6 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81284 Patch Status Patched Published Aug 27, 2026 Affected Software Advanced Custom Fields: Extended [acf-extended] Researcher Ananda Dhakal More Details > BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-19801 Patch Status Patched Published Aug 24, 2026 Affected Software BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP [betterlinks] Researcher Wordfence PRISM More Details > Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.6 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81762 Patch Status Patched Published Aug 28, 2026 Affected Software Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] Researcher sungbyeongchan More Details > Booking for Appointments and Events Calendar – Amelia 1.2.32 - 2.4.8 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-77704 Patch Status Patched Published Aug 29, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Louise More Details > Content Mask 1.8.0 - 1.8.5.4 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-77003 Patch Status Patched Published Aug 28, 2026 Affected Software Content Mask [content-mask] Researchers Pablo González Fran Ramírez More Details > Directorist: AI-Powered Business Directory, Listings & Classified Ads 8.5 - 8.9.2 - Authenticated (Subscriber+) Arbitrary Image Move 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-77757 Patch Status Patched Published Aug 28, 2026 Affected Software Directorist: AI-Powered Business Directory, Listings & Classified Ads [directorist] Researcher Revanth Hari Narayana Matte More Details > Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.67 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81274 Patch Status Patched Published Aug 26, 2026 Affected Software Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] Researcher sungbyeongchan More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-16577 Patch Status Patched Published Aug 24, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher Bhaveshkumar Parmar More Details > Duplicate Post < 1.5.6 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-19435 Patch Status Patched Published Aug 24, 2026 Affected Software Duplicate Post [copy-delete-posts] Researcher Erwan LR More Details > Duplicate Post < 1.5.6 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-19085 Patch Status Patched Published Aug 24, 2026 Affected Software Duplicate Post [copy-delete-posts] Researcher Erwan LR More Details > Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.5.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81759 Patch Status Patched Published Aug 27, 2026 Affected Software Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar [mage-eventpress] Researcher sungbyeongchan More Details > Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.5.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81761 Patch Status Patched Published Aug 27, 2026 Affected Software Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar [mage-eventpress] Researcher sungbyeongchan More Details > Finale Lite – Sales Countdown Timer & Discount for WooCommerce < 2.21.0 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-78138 Patch Status Patched Published Aug 27, 2026 Affected Software Finale Lite – Sales Countdown Timer & Discount for WooCommerce [finale-woocommerce-sales-countdown-timer-discount] Researcher Shikhali Jamalzade More Details > Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-78278 Patch Status Patched Published Aug 24, 2026 Affected Software Fluent Boards Pro [fluent-boards-pro] Researcher Ananda Dhakal More Details > Fluent Support Pro <= 2.3.1 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-78279 Patch Status Patched Published Aug 24, 2026 Affected Software Fluent Support Pro [fluent-support-pro] Researcher Ananda Dhakal More Details > Fluent Support Pro <= 2.3.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-78272 Patch Status Patched Published Aug 24, 2026 Affected Software Fluent Support Pro [fluent-support-pro] Researcher Ananda Dhakal More Details > FluentBooking Pro <= 2.2.4 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81273 Patch Status Patched Published Aug 26, 2026 Affected Software Fluent Booking Pro [fluent-booking-pro] Researcher Ananda Dhakal More Details > Frontend Admin by DynamiApps < 3.29.11 - Authenticated (Subscriber+) Membership Plan Deletion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81346 Patch Status Patched Published Aug 27, 2026 Affected Software Frontend Admin by DynamiApps [acf-frontend-form-element] Researcher Sai Praneeth Koti More Details > FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-75930 Patch Status Patched Published Aug 24, 2026 Affected Software FundEngine – Donation and Crowdfunding Platform [wp-fundraising-donation] Researcher Wordfence PRISM More Details > GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.176 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81271 Patch Status Patched Published Aug 26, 2026 Affected Software GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] Researcher Brian Willows More Details > Hash Form – Drag & Drop Form Builder <= 1.4.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-78280 Patch Status Patched Published Aug 24, 2026 Affected Software Hash Form – Drag & Drop Form Builder [hash-form] Researcher sanghyeok Kim More Details > LitExtension – Automated Store Migration & Import <= 1.2.6 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15046 Patch Status Patched Published Aug 24, 2026 Affected Software LitExtension – Automated Store Migration & Import [litextension-data-migration-to-woocommerce] Researcher marim00 More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.42 - Authenticated (Custom Role+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81200 Patch Status Patched Published Aug 29, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher Revanth Hari Narayana Matte More Details > Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce <= 0.4.62 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-16568 Patch Status Patched Published Aug 27, 2026 Affected Software Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce [mobile-app-for-woocommerce] Researcher TruongLV1 From FPT Night Wolf More Details > Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce <= 0.4.69 - Missing Authorization to Authenticated (Subscriber+) Stock Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-16569 Patch Status Unpatched Published Aug 25, 2026 Affected Software Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce [mobile-app-for-woocommerce] Researcher TruongLV1 From FPT Night Wolf More Details > MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Completion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-18233 Patch Status Patched Published Aug 27, 2026 Affected Software MStore API – Create Native Android & iOS Apps On The Cloud [mstore-api] Researcher Erwan LR More Details > Newsletters < 4.17 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-17522 Patch Status Patched Published Aug 29, 2026 Affected Software Newsletters [newsletters-lite] Researcher Erwan LR More Details > Newsletters <= 4.17 - Missing Authorization to Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-75908 Patch Status Patched Published Aug 24, 2026 Affected Software Newsletters [newsletters-lite] Researcher Wordfence PRISM More Details > Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist < 3.1.4 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-78139 Patch Status Patched Published Aug 27, 2026 Affected Software Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist [woocommerce-product-stock-alert] Researcher Shikhali Jamalzade More Details > OwnerRez <= 1.2.6 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81758 Patch Status Patched Published Aug 28, 2026 Affected Software OwnerRez [ownerrez] Researcher JunHee CHO More Details > Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker < 4.0.7 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-74929 Patch Status Patched Published Aug 26, 2026 Affected Software Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker [wedevs-project-manager] Researcher Pedro Pinho More Details > Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker 2.2.0 - 4.0.6 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-74930 Patch Status Patched Published Aug 26, 2026 Affected Software Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker [wedevs-project-manager] Researcher Usama Arshad More Details > Push Notification for Post and BuddyPress <= 3.20 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81279 Patch Status Patched Published Aug 26, 2026 Affected Software Push Notification for Post and BuddyPress [push-notification-for-post-and-buddypress] Researcher JunHee CHO More Details > Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker < 11.2.4 - Authenticated (Contributor+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-79615 Patch Status Patched Published Aug 28, 2026 Affected Software Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker [quiz-master-next] Researcher Shikhali Jamalzade More Details > SureFeedback Client Site <= 1.2.12 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-80433 Patch Status Patched Published Aug 26, 2026 Affected Software SureFeedback Client Site [projecthuddle-child-site] Researcher doyz More Details > UpdraftPlus: WP Backup & Migration Plugin < 1.26.7 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-76549 Patch Status Patched Published Aug 27, 2026 Affected Software UpdraftPlus: WP Backup & Migration Plugin [updraftplus] Researcher Jashid Sany More Details > User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.5 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-79995 Patch Status Patched Published Aug 28, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researcher Sai Praneeth Koti More Details > WP Courses LMS <= 3.2.29 - Insecure Direct Object Reference to Authenticated (Custom+) Sensitive Information Disclosure via 'resultID' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10630 Patch Status Patched Published Aug 24, 2026 Affected Software WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses [wp-courses] Researcher Vapour More Details > WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.9 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81299 Patch Status Patched Published Aug 27, 2026 Affected Software WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] Researcher Md Mehedi Hasan More Details > FluentPlayer Pro <= 1.3.2 - Missing Authorization 2.7 CVSS Rating 2.7 (Low) CVE-ID CVE-2026-81272 Patch Status Patched Published Aug 26, 2026 Affected Software Fluent Player Pro [fluent-player-pro] Researcher Ananda Dhakal More Details > Rank Math SEO – AI SEO Tools to Dominate SEO Rankings < 1.0.277 - Missing Authorization 2.7 CVSS Rating 2.7 (Low) CVE-ID CVE-2026-77786 Patch Status Patched Published Aug 29, 2026 Affected Software Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] Researcher Mohammed Abd Alrahman More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026) appeared first on Wordfence .