Security News

Cybersecurity news aggregator

LOW Vulnerabilities Wordfence

Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)

  • What: Weekly report of 260 WordPress plugin vulnerabilities
  • Impact: WordPress site owners need to review and patch affected plugins
Read Full Article →

Last week, there were 260 vulnerabilities disclosed in 207 WordPress Plugins that have been added to the Wordfence Intelligence Vulnerability Database, and there were 147 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , and webhook integration are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can utilize the vulnerability Database API to receive a complete dump of our database of over 40,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 217 Partially Patched 1 Unpatched 42 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Medium Severity 184 High Severity 66 Critical Severity 10 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 66 Missing Authorization 58 Exposure of Sensitive Information to an Unauthorized Actor 21 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 18 Improper Privilege Management 15 Authorization Bypass Through User-Controlled Key 13 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 11 Deserialization of Untrusted Data 10 Improper Control of Generation of Code ('Code Injection') 9 Improper Authentication 6 Unrestricted Upload of File with Dangerous Type 6 Client-Side Enforcement of Server-Side Security 5 Cross-Site Request Forgery (CSRF) 5 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 3 Insufficient Verification of Data Authenticity 2 Protection Mechanism Failure 2 URL Redirection to Untrusted Site ('Open Redirect') 2 Authentication Bypass Using an Alternate Path or Channel 1 Guessable CAPTCHA 1 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1 Incorrect Authorization 1 Missing Authentication for Critical Function 1 Server-Side Request Forgery (SSRF) 1 Uncontrolled Resource Consumption 1 Unverified Password Change 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Wordfence PRISM 25 Artus KG 10 Ananda Dhakal 10 Jakub Herman 10 Yaswanth Reddy Sunkara 6 0xBassia 6 Karthik Ramakrishnan 6 Philipp Doblhofer 5 Peng Zhou 4 daroo 4 Pedro Pinho 4 Nabil Irawan 4 Erwan LR 3 benzdeus 3 Naoki Kawahigashi 3 Charles Vosburgh 3 Nguyen Dinh Hai (HaiND) 3 Ali Mousavi 3 h0xilo 3 Kuba 3 Dmitrii Ignatyev 3 JunHee CHO 3 Farid Narimanov 3 Chloe Chamberland 3 Wordfence Argus 3 m1w34p0n 2 Nguyen Ba Khanh 2 Usama Arshad 2 Yuto Hyakumoto 2 sungbyeongchan 2 Seongwon Lee 2 Vaibhav Narkhede 2 Abdullah Kareem 2 João Ramos Maciel 2 dodoh4t 2 andrea bocchetti 2 Revanth Hari Narayana Matte 2 moonge 2 BaptouTatis 2 Sai Praneeth Koti 2 MYUNGYONG LEE 2 nobody 1 Adam Rayyan Aryasatya 1 Nguyen Anh Quan (prototw) 1 Arif Shaikh 1 care 1 Sandeep V 1 Krypt3d 1 Tiago Ventura 1 gidget smith 1 Osvaldo Noe Gonzalez Del Rio (Os) 1 Sybre Waaijer 1 kta1kri 1 0xzenko 1 Muhammad Yudha - DJ 1 William Honnér 1 Enrico Marcolini 1 Claudio Marchesini 1 Ryan Fabella 1 Jonah Burgess (CryptoCat) 1 Jetpack 1 murloc.mrglwglwgl 1 Suhayb Ahmed 1 Morato Antoine 1 WhiteFalcon 1 Mael MARTIN 1 Othmane EL AYADI 1 V1T 1 AmirSUN 1 Adam Kahlon 1 sorin vasile 1 nh4tvd 1 Michele Genito 1 d4ngvn 1 Nikola Kojic 1 Jiang CY 1 Sushi Com Abacate 1 yck 1 Sergei Pro 1 theviper17y 1 Labda 1 Jaskaranjeet Singh 1 TarPeg007 1 Naoya Takahashi (nakko) 1 Rinesa Krasniqi 1 Nhien Pham (nhienit) (nhienit) 1 thevietronin 1 braintx 1 Guillermo Álvarez Fernández 1 Md. Minaruzzaman Shovon 1 Sander Horsman 1 Andrea Fiocchi 1 TruongLV1 From FPT Night Wolf 1 Ivaylo 1 Nox Axter 1 Samuele Santonicola 1 Ryan Zegar 1 Kitch 1 Johan Buenavida 1 HEI LAI SZE 1 RIA Labs 1 Legion Hunter 1 Brian Mungai 1 uhcna 1 Afan 1 Kishan Vyas 1 LevinityCyber 1 Evan NR 1 Muni Nitish Kumar Yaddala (Stranger825) 1 Revanth Matte 1 babyhack 1 Anthony Green of Greenhat Security 1 LueRader 1 Mohammed Abd Alrahman 1 normaandersonfrank 1 Farrukh Ziyaev 1 Mitre Osman Hussein 1 Jarno Vos (jarnovos) 1 Supakiad S. (m3ez) 1 KoreaInfoSec 1 Nasur ullah 1 Sebastian Albrecht 1 Muni Nitish Kumar Yaddala 1 revblock 1 Ivaylo Atanassov 1 Shikhali Jamalzade 1 Mutantgun 1 Alex Spataru 1 Vuln Seeker Cyber Security Team 1 Maarten 1 Spy0x7 1 Osman Hussein 1 Huynh Kien Minh 1 DungNhi 1 pervinzahidli 1 Salúa Es-sair 1 zaim 1 Adrien Brunner 1 Pablo González 1 Francisco José Ramírez 1 20kilograma 1 HieuPenguinnn 1 Athiwat Tiprasaharn (Jitlada) 1 Itthidej Aramsri (Boeing777) 1 TurboNexic 1 adhikara13 1 Tony Harris 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress acymailing Advanced Contact form 7 DB advanced-cf7-db Advanced Customized Prompts advanced-customized-prompts Advanced Partial Payment or Deposit for WooCommerce advanced-partial-payment-or-deposit-for-woocommerce Advanced Product Fields Extended for WooCommerce advanced-product-fields-for-woocommerce-extended AI Builder – Generate pages, blocks, images & translate with AI ai-builder Aruba HiSpeed Cache aruba-hispeed-cache Awesome Support – WordPress HelpDesk & Support Plugin awesome-support BackWPup – WordPress Backup & Restore Plugin backwpup bbPress bbpress BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) woo-bulk-editor Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version Bold Page Builder bold-page-builder Bold Timeline Lite bold-timeline-lite Booking for Appointments and Events Calendar – Amelia ameliabooking Bookit — Booking & Appointment Calendar bookit Booktics – Appointment Booking Calendar for Service Businesses booktics BuddyPress buddypress Builderall for WordPress builderall-cheetah-for-wp Bulk Password Reset bulk-password-reset CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce woocommerce-catalog-enquiry Checkout Custom Fields Builder for WooCommerce checkout-custom-fields-builder-for-woocommerce CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard code-monkeys-proposals Contact Form to Chat Apps | Click to Chat to Order – FormyChat social-contact-form Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress contact-form-to-db Content Mask content-mask CoolClock coolclock CryptoPayment Gateway cryptopayment-gateway Csomagpontok és Címkék WooCommerce-hez hungarian-pickup-points-for-woocommerce Custom Menu Wizard Widget custom-menu-wizard Direct Download for WooCommerce direct-download-for-woocommerce Domain For Sale – Landing Page Per Domain, Domain Mapping, Offers & Listings domain-for-sale Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms DT LMS – elearning, WordPress LMS Plugin dt-lms-lite Easy Appointments easy-appointments Easy Google Fonts easy-google-fonts EDD Product Catalog Feed by PixelYourSite edd-products-feed-pro ElasticPress elasticpress ELEX WooCommerce Request a Quote elex-request-a-quote Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress email-subscribers Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar mage-eventpress Event Tickets and Registration event-tickets Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce wp-event-solution EventON – Events Calendar eventon-lite Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI everest-forms Featured Image with URL featured-image-with-url FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment firebox Flexible Quantity – Measurement Price Calculator for WooCommerce flexible-quantity-measurement-price-calculator-for-woocommerce Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty chaty Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder form-maker Frontegg SAML SSO frontegg-saml-sso GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI gamipress Gato GraphQL gatographql GEO my WP geo-my-wp Gpx2Graphics gpx2graphics Graphina – Charts and Graphs For Elementor graphina-elementor-charts-and-graphs Groundhogg — CRM, Newsletters, and Marketing Automation groundhogg Gutenverse News – News Blocks for Blog & Magazine Sites gutenverse-news Hide My WP Ghost – Security & Firewall hide-my-wp HT Menu – WordPress Mega Menu Builder for Elementor ht-menu-lite HUSKY – Products Filter for WooCommerce Professional woocommerce-products-filter Hustle – Email Marketing, Lead Generation, Optins, Popups wordpress-popup ilGhera Reviso Exporter for WooCommerce wc-exporter-for-reviso IMPress for IDX Broker idx-broker-platinum Insert or Embed Articulate Content into WordPress insert-or-embed-articulate-content-into-wordpress IP2Location Country Blocker ip2location-country-blocker IPGP Visitors Origin ipgp-visitors-origin JCH Optimize jch-optimize JetFormBuilder — Dynamic Blocks Form Builder jetformbuilder Jetpack – WP Security, Backup, Speed, & Growth jetpack Kirki – Freeform Page Builder, Website Builder & Customizer kirki LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress Live Composer – Free WordPress Website Builder live-composer-page-builder Loops & Logic tangible-loops-and-logic LukasApps CAPTCHA tools for Contact Form 7 contact-form-7-simple-recaptcha Mail Mint – Email Marketing, Automation & WooCommerce Emails with AI Assistance mail-mint MailMunch – Grow your Email List mailmunch Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits master-addons Masteriyo LMS – LMS Course Builder, Quizzes & Certificates learning-management-system MDJM Event Management mobile-dj-manager Media Library Assistant media-library-assistant MemberPress Corporate Accounts memberpress-corporate MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor metform miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniorange-2-factor-authentication MIPL Checkout Fields Manager for WooCommerce – Customize, Organize & Group Checkout Fields. mipl-wc-checkout-fields Mobile Events Manager mobile-events-manager MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO multiple-pages-generator-by-porthas MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions dc-woocommerce-multi-vendor Music Store – WordPress eCommerce music-store My Calendar – Accessible Event Manager my-calendar Nexi XPay Build nexi-xpay-build Next-Cart Store to WooCommerce Migration nextcart-woocommerce-migration Ninja Forms – The Contact Form Builder That Grows With You ninja-forms Notiqoo – Order Notification & Customer Chat for WooCommerce wc-messaging Online Scheduling and Appointment Booking System – Bookly bookly-responsive-appointment-booking-tool Open User Map – Interactive Leaflet Maps open-user-map Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More themeisle-companion OTP Login & Register Woocommerce mobile-login-woocommerce Page Visits Counter – Lite page-visits-counter-lite Passster – Password Protect Pages and Content content-protector Payment Gateway PayPay for WooCommerce wc-paypay-gateway Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce Payment Plugins for Stripe WooCommerce woo-stripe-payment PDF Builder for WooCommerce. Create invoices,packing slips and more woo-pdf-invoice-builder Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred mycred Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) buddyforms Product Filter for WooCommerce by WBW woo-product-filter Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More product-xml-feeds-for-woocommerce PublishPress Capabilities: User Role Access Control, Admin Area Permissions capability-manager-enhanced Quads Ads Manager for Google AdSense quick-adsense-reloaded Quentn WP quentn-wp Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker quiz-master-next Rara One Click Demo Import rara-one-click-demo-import Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) really-simple-ssl Redux Framework redux-framework Registration Form for WooCommerce registration-form-for-woocommerce Relevanssi – A Better Search relevanssi RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress computer-repair-shop Repeater Fields for Gravity Forms repeater-for-gravity-forms Return Refund and Exchange For WooCommerce woo-refund-and-exchange-lite Robokassa payment gateway for Woocommerce robokassa Rox Appointment Booking – Appointment Booking Scheduling Solution rox-appointment-booking Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons rtMedia for WordPress, BuddyPress and bbPress buddypress-media RTMKit rometheme-for-elementor Salon Booking System – Appointment Booking for Salons, Barbershops & Spas salon-booking-system SEO Flow by LupsOnline lupsonline-link-netwerk Shirt Product Designer for WooCommerce woo-shirt-product-designer Shopping Cart & eCommerce Store wp-easycart Sidebar Manager Light sidebar-manager-light Simple Ajax Chat – Add a Fast, Secure Chat Box simple-ajax-chat Simple CAPTCHA with Cloudflare Turnstile simple-cloudflare-turnstile Simple Membership simple-membership Simple Payment simple-payment Sina Extension for Elementor sina-extension-for-elementor Site Kit by Google – Analytics, Search Console, AdSense, Speed google-site-kit Site Reviews site-reviews SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor & WordPress WebOps siteskite Sky Addons for Elementor sky-elementor-addons Slim SEO – AI SEO Plugin, Lightweight, Fast & Automated slim-seo Smart Marketing SMS and Newsletters Forms smart-marketing-for-wp SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert Spam protection, Honeypot, Anti-Spam by CleanTalk cleantalk-spam-protect Sprout Invoices – Client Invoicing & Estimates sprout-invoices SSL Zen — SSL Certificate Installer & HTTPS Redirects ssl-zen Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg astra-sites Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons sticky-chat-widget Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers sunshine-photo-cart SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent supportcandy SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments surecart SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema & Open Graph surerank Teddy Bear Customize Addon teddy-bear-customize-addon Temporary Login Without Password temporary-login-without-password Thanko Thank You Page Customizer for WooCommerce – Increase Your Sales woo-thank-you-page-customizer The Events Calendar the-events-calendar ThemeREX Addons trx_addons Themify – WooCommerce Product Filter themify-wc-product-filter Translate WordPress with GTranslate gtranslate Tutor LMS – eLearning and online course solution tutor Ultimate Gift Cards for WooCommerce woo-gift-cards-lite Unbounce Landing Pages unbounce Unlimited Elements For Elementor unlimited-elements-for-elementor User Access Manager user-access-manager User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder user-registration UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP userswp Verified Reviews (Avis Vérifiés) netreviews Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… vigilante Visual Composer Website Builder visualcomposer Visualizer – Tables & Charts Manager with Built-in AI Generator visualizer WebTotem Backups wt-backups Wise Chat wise-chat WooCommerce woocommerce WP BackItUp Community Edition wp-backitup WP Compress – Instant Performance & Speed Optimization wp-compress-image-optimizer WP Crowdfunding wp-crowdfunding WP Directory Kit wpdirectorykit WP Docs wp-docs WP Express Checkout (Fast Payments via PayPal & Stripe) wp-express-checkout WP Fast Total Search – The Power of Indexed Search fulltext-search WP Fusion (Pro) wp-fusion WP Highlight Box wp-highlight-box WP Module Data wp-module-data WP Photo Album Plus wp-photo-album-plus WP Plugin Bluehost bluehost-wordpress-plugin WP Plugin Crazy Domains wp-plugin-crazy-domains WP Plugin Hostgator wp-plugin-hostgator WP Plugin Web wp-plugin-web WP Recipe Maker wp-recipe-maker WP Travel – Ultimate Travel Booking System, Tour Management Engine wp-travel WP-Members Membership Plugin wp-members WP-Stateless – Google Cloud Storage wp-stateless WPAdverts – Classifieds Plugin wpadverts WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services chatbot WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System wp-cafe WPCS – WordPress Currency Switcher Professional currency-switcher WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell wpfunnels WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode gdpr-cookie-consent WPML Multilingual CMS sitepress-multilingual-cms WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping wp-product-feed-manager YITH WooCommerce Waitlist Premium yith-woocommerce-waiting-list-premium YITH WooCommerce Wishlist yith-woocommerce-wishlist Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress youzify Zephyr Project Manager zephyr-project-manager ZHBackup – Backup, Restore & Migration zhbackup zipMoney(Zip Co) Payments Plugin for WooCommerce zipmoney-payments-woocommerce المنتور فارسی persian-elementor Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. Advanced Customized Prompts <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-14563 Patch Status Unpatched Published Sep 9, 2026 Affected Software Advanced Customized Prompts [advanced-customized-prompts] Researcher 0xBassia More Details > Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-18351 Patch Status Patched Published Sep 9, 2026 Affected Software Drag and Drop File Upload for Elementor Forms [drag-and-drop-file-upload-for-elementor-forms] Researcher Adam Rayyan Aryasatya More Details > Frontegg SAML SSO <= 1.0.1 - Authentication Bypass to Admin 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-75800 Patch Status Unpatched Published Sep 10, 2026 Affected Software Frontegg SAML SSO [frontegg-saml-sso] Researcher moonge More Details > MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-8778 Patch Status Patched Published Sep 10, 2026 Affected Software MIPL Checkout Fields Manager for WooCommerce – Customize, Organize & Group Checkout Fields. [mipl-wc-checkout-fields] Researcher Farrukh Ziyaev More Details > Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-14560 Patch Status Unpatched Published Sep 9, 2026 Affected Software Teddy Bear Customize Addon [teddy-bear-customize-addon] Researcher 0xBassia More Details > Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Privilege Escalation via Account Takeover 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-14559 Patch Status Unpatched Published Sep 9, 2026 Affected Software Teddy Bear Customize Addon [teddy-bear-customize-addon] Researcher 0xBassia More Details > The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-78159 Patch Status Patched Published Sep 11, 2026 Affected Software The Events Calendar [the-events-calendar] Researchers Chloe Chamberland Wordfence Argus More Details > The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-78006 Patch Status Patched Published Sep 11, 2026 Affected Software The Events Calendar [the-events-calendar] Researchers Chloe Chamberland Wordfence Argus More Details > Advanced Product Fields Extended for WooCommerce <= 3.1.6 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-81789 Patch Status Unpatched Published Sep 9, 2026 Affected Software Advanced Product Fields Extended for WooCommerce [advanced-product-fields-for-woocommerce-extended] Researcher Maarten More Details > CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-81648 Patch Status Unpatched Published Sep 10, 2026 Affected Software CryptoPayment Gateway [cryptopayment-gateway] Researcher Pedro Pinho More Details > FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-76801 Patch Status Patched Published Sep 8, 2026 Affected Software FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment [firebox] Researcher Wordfence PRISM More Details > Gpx2Graphics <= 0.3 - Cross-Site Request Forgery to Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-81090 Patch Status Unpatched Published Sep 10, 2026 Affected Software Gpx2Graphics [gpx2graphics] Researcher Huynh Kien Minh More Details > Insert or Embed Articulate Content into WordPress < 4.3000000025 - Authenticated (Author+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2024-0757 Patch Status Patched Published Sep 10, 2026 Affected Software Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] Researcher Dmitrii Ignatyev More Details > Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection via Shortcode 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-16502 Patch Status Patched Published Sep 7, 2026 Affected Software Live Composer – Free WordPress Website Builder [live-composer-page-builder] Researcher Muhammad Yudha - DJ More Details > MemberPress Corporate Accounts <= 1.5.39 - Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-15451 Patch Status Patched Published Sep 11, 2026 Affected Software MemberPress Corporate Accounts [memberpress-corporate] Researcher andrea bocchetti More Details > RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1224 - Authenticated (Subscriber+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-81803 Patch Status Patched Published Sep 9, 2026 Affected Software RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress [computer-repair-shop] Researcher Nasur ullah More Details > SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments < 4.6.3 - Authenticated (Subscriber+) Arbitrary Account Email Takeover 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-18480 Patch Status Patched Published Sep 7, 2026 Affected Software SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] Researcher Jakub Herman More Details > Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-78175 Patch Status Patched Published Sep 11, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researchers Chloe Chamberland Wordfence Argus More Details > Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-80099 Patch Status Patched Published Sep 8, 2026 Affected Software WP Module Data [wp-module-data] WP Plugin Bluehost [bluehost-wordpress-plugin] WP Plugin Crazy Domains [wp-plugin-crazy-domains] WP Plugin Hostgator [wp-plugin-hostgator] WP Plugin Web [wp-plugin-web] Researcher sorin vasile More Details > YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-14359 Patch Status Patched Published Sep 8, 2026 Affected Software YITH WooCommerce Waitlist Premium [yith-woocommerce-waiting-list-premium] Researcher Michele Genito More Details > CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard <= 1.0.1 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-77005 Patch Status Unpatched Published Sep 10, 2026 Affected Software CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard [code-monkeys-proposals] Researcher João Ramos Maciel More Details > Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.6.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-62103 Patch Status Patched Published Sep 11, 2026 Affected Software Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI [everest-forms] Researcher LueRader More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 3.4.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-62107 Patch Status Patched Published Sep 11, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher 20kilograma More Details > Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-76009 Patch Status Patched Published Sep 8, 2026 Affected Software Next-Cart Store to WooCommerce Migration [nextcart-woocommerce-migration] Researcher Samuele Santonicola More Details > Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-82925 Patch Status Patched Published Sep 11, 2026 Affected Software Site Reviews [site-reviews] Researcher Jakub Herman More Details > ThemeREX Addons < 2.45.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-62105 Patch Status Patched Published Sep 11, 2026 Affected Software ThemeREX Addons [trx_addons] Researcher nh4tvd More Details > UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-19991 Patch Status Patched Published Sep 10, 2026 Affected Software UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP [userswp] Researcher daroo More Details > Visualizer – Tables & Charts Manager with Built-in AI Generator < 4.0.6 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-86779 Patch Status Patched Published Sep 9, 2026 Affected Software Visualizer – Tables & Charts Manager with Built-in AI Generator [visualizer] Researcher Yaswanth Reddy Sunkara More Details > WebTotem Backups <= 1.0.1 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-77006 Patch Status Unpatched Published Sep 10, 2026 Affected Software WebTotem Backups [wt-backups] Researcher João Ramos Maciel More Details > Wise Chat <= 3.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-81784 Patch Status Unpatched Published Sep 8, 2026 Affected Software Wise Chat [wise-chat] Researcher Peng Zhou More Details > Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password Reset 8.0 CVSS Rating 8.0 (High) CVE-ID CVE-2026-14873 Patch Status Unpatched Published Sep 9, 2026 Affected Software Bulk Password Reset [bulk-password-reset] Researchers Afan moonge More Details > AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-77807 Patch Status Patched Published Sep 10, 2026 Affected Software AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress [acymailing] Researcher daroo More Details > Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-15019 Patch Status Unpatched Published Sep 9, 2026 Affected Software Direct Download for WooCommerce [direct-download-for-woocommerce] Researcher Spy0x7 More Details > ELEX WooCommerce Request a Quote <= 2.4.0 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-14962 Patch Status Patched Published Sep 7, 2026 Affected Software ELEX WooCommerce Request a Quote [elex-request-a-quote] Researcher Artus KG More Details > Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-3174 Patch Status Patched Published Sep 7, 2026 Affected Software Event Tickets and Registration [event-tickets] Researcher h0xilo More Details > Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-15667 Patch Status Patched Published Sep 8, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Wordfence PRISM More Details > Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-15406 Patch Status Patched Published Sep 8, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Wordfence PRISM More Details > GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-85200 Patch Status Patched Published Sep 11, 2026 Affected Software GEO my WP [geo-my-wp] Researcher yck More Details > Masteriyo LMS <= 3.4.0 - Authenticated (Subscriber+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-82845 Patch Status Patched Published Sep 10, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher Karthik Ramakrishnan More Details > Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-82304 Patch Status Patched Published Sep 7, 2026 Affected Software Music Store – WordPress eCommerce [music-store] Researcher nobody More Details > Quentn WP 1.2.13 - 1.2.14 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-84068 Patch Status Patched Published Sep 10, 2026 Affected Software Quentn WP [quentn-wp] Researcher Yaswanth Reddy Sunkara More Details > rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection via 'compare' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-16482 Patch Status Patched Published Sep 11, 2026 Affected Software rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] Researcher Wordfence PRISM More Details > Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-15462 Patch Status Patched Published Sep 10, 2026 Affected Software Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons [sticky-chat-widget] Researcher WhiteFalcon More Details > Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-18561 Patch Status Patched Published Sep 10, 2026 Affected Software Unlimited Elements For Elementor [unlimited-elements-for-elementor] Researcher Yuto Hyakumoto More Details > Verified Reviews (Avis Vérifiés) <= 2.4.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-81800 Patch Status Unpatched Published Sep 9, 2026 Affected Software Verified Reviews (Avis Vérifiés) [netreviews] Researchers Mael MARTIN Othmane EL AYADI More Details > WooCommerce < 11.1.0 - Unauthenticated Denial of Service 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-48888 Patch Status Patched Published Sep 7, 2026 Affected Software WooCommerce [woocommerce] Researcher Ananda Dhakal More Details > WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-14444 Patch Status Patched Published Sep 7, 2026 Affected Software WP Fusion (Pro) [wp-fusion] Researcher Jarno Vos (jarnovos) More Details > CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce <= 6.1.4 - Unauthenticated Privilege Escalation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-81792 Patch Status Unpatched Published Sep 7, 2026 Affected Software CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce [woocommerce-catalog-enquiry] Researcher Peng Zhou More Details > miniOrange 2FA – Two Factor Authentication for WordPress 5.3.24 - 6.3.0 - Missing Authorization to Unauthenticated Arbitrary Option Deletion 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-77770 Patch Status Patched Published Sep 8, 2026 Affected Software miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) [miniorange-2-factor-authentication] Researcher Osman Hussein More Details > SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-78362 Patch Status Patched Published Sep 7, 2026 Affected Software SEO Flow by LupsOnline [lupsonline-link-netwerk] Researcher Naoki Kawahigashi More Details > SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor & WordPress WebOps <= 2.1.5 - Unauthenticated Privilege Escalation 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-81805 Patch Status Patched Published Sep 9, 2026 Affected Software SiteSkite MCP AI – Connector for Claude, ChatGPT, Cursor & WordPress WebOps [siteskite] Researcher Ananda Dhakal More Details > Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-13359 Patch Status Patched Published Sep 8, 2026 Affected Software Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress [contact-form-to-db] Researcher Nabil Irawan More Details > Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-14989 Patch Status Patched Published Sep 8, 2026 Affected Software WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode [gdpr-cookie-consent] Researcher Naoya Takahashi (nakko) More Details > Easy Appointments <= 4.0.2.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81798 Patch Status Unpatched Published Sep 7, 2026 Affected Software Easy Appointments [easy-appointments] Researcher 0xzenko More Details > Gutenverse News – News Blocks for Blog & Magazine Sites < 3.3.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-85677 Patch Status Patched Published Sep 11, 2026 Affected Software Gutenverse News – News Blocks for Blog & Magazine Sites [gutenverse-news] Researcher Artus KG More Details > Hide My WP Ghost – Security & Firewall <= 7.0.09 - Unauthenticated Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81806 Patch Status Patched Published Sep 7, 2026 Affected Software Hide My WP Ghost – Security & Firewall [hide-my-wp] Researcher Ananda Dhakal More Details > JetFormBuilder — Dynamic Blocks Form Builder <= 3.6.5.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84817 Patch Status Patched Published Sep 7, 2026 Affected Software JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] Researcher Anthony Green of Greenhat Security More Details > Jetpack – WP Security, Backup, Speed, & Growth 16.1 - 16.1.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) Patch Status Patched Published Sep 8, 2026 Affected Software Jetpack – WP Security, Backup, Speed, & Growth [jetpack] Researcher Jetpack More Details > Kirki – Freeform Page Builder, Website Builder & Customizer 6.2.1 - 6.2.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84219 Patch Status Patched Published Sep 8, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Jakub Herman More Details > Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-17037 Patch Status Patched Published Sep 10, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher daroo More Details > Open User Map – Interactive Leaflet Maps <= 1.4.50 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84818 Patch Status Patched Published Sep 7, 2026 Affected Software Open User Map – Interactive Leaflet Maps [open-user-map] Researcher care More Details > Page Visits Counter – Lite <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81795 Patch Status Patched Published Sep 8, 2026 Affected Software Page Visits Counter – Lite [page-visits-counter-lite] Researcher Nguyen Ba Khanh More Details > PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-75927 Patch Status Patched Published Sep 8, 2026 Affected Software PublishPress Capabilities: User Role Access Control, Admin Area Permissions [capability-manager-enhanced] Researcher Wordfence PRISM More Details > Rara One Click Demo Import <= 1.3.4 - Authenticated (Admin+) Arbitrary File Upload 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-26212 Patch Status Patched Published Sep 9, 2026 Affected Software Rara One Click Demo Import [rara-one-click-demo-import] Researcher Rinesa Krasniqi More Details > Repeater Fields for Gravity Forms <= 3.0.4 - Unauthenticated Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84293 Patch Status Patched Published Sep 8, 2026 Affected Software Repeater Fields for Gravity Forms [repeater-for-gravity-forms] Researcher andrea bocchetti More Details > Shopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-17553 Patch Status Patched Published Sep 8, 2026 Affected Software Shopping Cart & eCommerce Store [wp-easycart] Researcher Wordfence PRISM More Details > Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-76562 Patch Status Unpatched Published Sep 9, 2026 Affected Software Sidebar Manager Light [sidebar-manager-light] Researcher Nabil Irawan More Details > Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81825 Patch Status Patched Published Sep 10, 2026 Affected Software Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] Researcher HEI LAI SZE More Details > Unlimited Elements For Elementor <= 2.0.17 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84820 Patch Status Patched Published Sep 7, 2026 Affected Software Unlimited Elements For Elementor [unlimited-elements-for-elementor] Researcher daroo More Details > User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.8 - Unauthenticated Open Redirect 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-80072 Patch Status Patched Published Sep 11, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researcher Sai Praneeth Koti More Details > Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-81754 Patch Status Patched Published Sep 10, 2026 Affected Software Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… [vigilante] Researcher Sebastian Albrecht More Details > WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-18579 Patch Status Patched Published Sep 10, 2026 Affected Software WP Photo Album Plus [wp-photo-album-plus] Researcher Jonah Burgess (CryptoCat) More Details > WPAdverts – Classifieds Plugin <= 2.3.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84819 Patch Status Patched Published Sep 8, 2026 Affected Software WPAdverts – Classifieds Plugin [wpadverts] Researcher Ivaylo Atanassov More Details > WPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-83593 Patch Status Patched Published Sep 8, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services [chatbot] Researcher Ivaylo More Details > WPCS – WordPress Currency Switcher Professional <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-84816 Patch Status Patched Published Sep 9, 2026 Affected Software WPCS – WordPress Currency Switcher Professional [currency-switcher] Researcher JunHee CHO More Details > EDD Product Catalog Feed by PixelYourSite <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter 7.1 CVSS Rating 7.1 (High) CVE-ID CVE-2026-9331 Patch Status Patched Published Sep 7, 2026 Affected Software EDD Product Catalog Feed by PixelYourSite [edd-products-feed-pro] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-11363 Patch Status Patched Published Sep 8, 2026 Affected Software Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] Researcher DungNhi More Details > Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-18021 Patch Status Patched Published Sep 7, 2026 Affected Software Beaver Builder Page Builder – Drag and Drop Website Builder [beaver-builder-lite-version] Researcher Kishan Vyas More Details > Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-12757 Patch Status Patched Published Sep 7, 2026 Affected Software Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress [email-subscribers] Researcher Sander Horsman More Details > GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-15439 Patch Status Patched Published Sep 10, 2026 Affected Software GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI [gamipress] Researcher Nox Axter More Details > Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.7.1 - Authenticated (Import_contacts+) Path Traversal 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-85310 Patch Status Patched Published Sep 9, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher Sergei Pro More Details > Hustle – Email Marketing, Lead Generation, Optins, Popups < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-80440 Patch Status Patched Published Sep 7, 2026 Affected Software Hustle – Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] Researcher Jakub Herman More Details > LukasApps CAPTCHA tools for Contact Form 7 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-85117 Patch Status Patched Published Sep 7, 2026 Affected Software LukasApps CAPTCHA tools for Contact Form 7 [contact-form-7-simple-recaptcha] Researcher Jakub Herman More Details > MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-85198 Patch Status Patched Published Sep 11, 2026 Affected Software MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO [multiple-pages-generator-by-porthas] Researchers Nhien Pham (nhienit) (nhienit) thevietronin More Details > Simple CAPTCHA with Cloudflare Turnstile <= 1.42.1 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-85116 Patch Status Patched Published Sep 9, 2026 Affected Software Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] Researcher Jakub Herman More Details > Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Injection via Parameter Name 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-77161 Patch Status Patched Published Sep 11, 2026 Affected Software Smart Marketing SMS and Newsletters Forms [smart-marketing-for-wp] Researcher Wordfence PRISM More Details > Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-19855 Patch Status Patched Published Sep 7, 2026 Affected Software Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] Researcher Jakub Herman More Details > Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-11496 Patch Status Patched Published Sep 10, 2026 Affected Software PDF Builder for WooCommerce. Create invoices,packing slips and more [woo-pdf-invoice-builder] Researcher Jaskaranjeet Singh More Details > WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’ 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-17509 Patch Status Patched Published Sep 7, 2026 Affected Software WPML Multilingual CMS [sitepress-multilingual-cms] Researcher h0xilo More Details > WPMR Google Feed Manager for WooCommerce <= 2.23.7 - Authenticated (Administrator+) SQL Injection via 'feed' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-19778 Patch Status Patched Published Sep 8, 2026 Affected Software WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping [wp-product-feed-manager] Researcher Wordfence PRISM More Details > Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.7 - Authenticated (Subscriber+) Arbitrary File Read 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-81275 Patch Status Unpatched Published Sep 8, 2026 Affected Software Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] Researcher dodoh4t More Details > Advanced Customized Prompts <= 1.0.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-14565 Patch Status Unpatched Published Sep 9, 2026 Affected Software Advanced Customized Prompts [advanced-customized-prompts] Researcher 0xBassia More Details > AI Builder – Generate pages, blocks, images & translate with AI 2.4.1 - 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-85678 Patch Status Patched Published Sep 11, 2026 Affected Software AI Builder – Generate pages, blocks, images & translate with AI [ai-builder] Researcher Md. Minaruzzaman Shovon More Details > Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15889 Patch Status Patched Published Sep 9, 2026 Affected Software Aruba HiSpeed Cache [aruba-hispeed-cache] Researcher theviper17y More Details > Bold Page Builder <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-62110 Patch Status Patched Published Sep 11, 2026 Affected Software Bold Page Builder [bold-page-builder] Researcher LevinityCyber More Details > Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-7438 Patch Status Patched Published Sep 10, 2026 Affected Software Bold Timeline Lite [bold-timeline-lite] Researcher zaim More Details > Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'load_manually' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-10148 Patch Status Patched Published Sep 11, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Nguyen Anh Quan (prototw) More Details > Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15796 Patch Status Unpatched Published Sep 9, 2026 Affected Software Builderall for WordPress [builderall-cheetah-for-wp] Researcher Wordfence PRISM More Details > Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module 'attributes' Setting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15820 Patch Status Unpatched Published Sep 9, 2026 Affected Software Builderall for WordPress [builderall-cheetah-for-wp] Researcher Wordfence PRISM More Details > Content Mask 1.7.1 - 1.8.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-15690 Patch Status Patched Published Sep 9, 2026 Affected Software Content Mask [content-mask] Researcher Andrea Fiocchi More Details > CoolClock < 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-83545 Patch Status Patched Published Sep 11, 2026 Affected Software CoolClock [coolclock] Researcher Philipp Doblhofer More Details > CoolClock <= 4.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-83546 Patch Status Patched Published Sep 8, 2026 Affected Software CoolClock [coolclock] Researcher Philipp Doblhofer More Details > Custom Menu Wizard Widget <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-83532 Patch Status Unpatched Published Sep 12, 2026 Affected Software Custom Menu Wizard Widget [custom-menu-wizard] Researcher Artus KG More Details > Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4657 Patch Status Unpatched Published Sep 9, 2026 Affected Software Easy Google Fonts [easy-google-fonts] Researcher Kitch More Details > EventON – Events Calendar <= 2.5.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-81791 Patch Status Patched Published Sep 8, 2026 Affected Software EventON – Events Calendar [eventon-lite] Researcher Nguyen Ba Khanh More Details > Featured Image with URL < 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-86780 Patch Status Patched Published Sep 11, 2026 Affected Software Featured Image with URL [featured-image-with-url] Researcher Artus KG More Details > Graphina <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13709 Patch Status Patched Published Sep 8, 2026 Affected Software Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] Researchers Athiwat Tiprasaharn (Jitlada) Itthidej Aramsri (Boeing777) More Details > HT Menu – WordPress Mega Menu Builder for Elementor < 1.2.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-84935 Patch Status Patched Published Sep 7, 2026 Affected Software HT Menu – WordPress Mega Menu Builder for Elementor [ht-menu-lite] Researcher Artus KG More Details > JCH Optimize < 6.0.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-84934 Patch Status Patched Published Sep 7, 2026 Affected Software JCH Optimize [jch-optimize] Researcher Artus KG More Details > LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12230 Patch Status Patched Published Sep 7, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researchers Muni Nitish Kumar Yaddala (Stranger825) Revanth Matte More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates < 3.4.1 - Authenticated (Custom Role+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-82847 Patch Status Patched Published Sep 12, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher Karthik Ramakrishnan More Details > Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6642 Patch Status Patched Published Sep 10, 2026 Affected Software Media Library Assistant [media-library-assistant] Researcher TruongLV1 From FPT Night Wolf More Details > Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6641 Patch Status Patched Published Sep 10, 2026 Affected Software Media Library Assistant [media-library-assistant] Researcher gidget smith More Details > Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6640 Patch Status Patched Published Sep 10, 2026 Affected Software Media Library Assistant [media-library-assistant] Researcher normaandersonfrank More Details > My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-77187 Patch Status Patched Published Sep 8, 2026 Affected Software My Calendar – Accessible Event Manager [my-calendar] Researcher Wordfence PRISM More Details > My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fallback' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-77186 Patch Status Patched Published Sep 8, 2026 Affected Software My Calendar – Accessible Event Manager [my-calendar] Researcher Wordfence PRISM More Details > myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-17149 Patch Status Patched Published Sep 8, 2026 Affected Software Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred [mycred] Researcher Wordfence PRISM More Details > Orbit Fox <= 3.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-85418 Patch Status Patched Published Sep 7, 2026 Affected Software Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] Researcher Farid Narimanov More Details > Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-75966 Patch Status Patched Published Sep 8, 2026 Affected Software Podlove Podcast Publisher [podlove-podcasting-plugin-for-wordpress] Researcher Wordfence PRISM More Details > Redux Framework <= 4.5.13.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5399 Patch Status Patched Published Sep 9, 2026 Affected Software Redux Framework [redux-framework] Researcher h0xilo More Details > Simple Payment <= 2.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-62111 Patch Status Patched Published Sep 11, 2026 Affected Software Simple Payment [simple-payment] Researcher V1T More Details > Sina Extension for Elementor 3.7.1 - 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-83541 Patch Status Patched Published Sep 9, 2026 Affected Software Sina Extension for Elementor [sina-extension-for-elementor] Researcher Dmitrii Ignatyev More Details > Visual Composer Website Builder <= 45.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-62138 Patch Status Patched Published Sep 10, 2026 Affected Software Visual Composer Website Builder [visualcomposer] Researcher sungbyeongchan More Details > WP Crowdfunding <= 2.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'first_name' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-19945 Patch Status Patched Published Sep 8, 2026 Affected Software WP Crowdfunding [wp-crowdfunding] Researcher Wordfence PRISM More Details > WP Docs <= 2.3.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-81782 Patch Status Unpatched Published Sep 9, 2026 Affected Software WP Docs [wp-docs] Researcher dodoh4t More Details > WP Highlight Box <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-86790 Patch Status Unpatched Published Sep 12, 2026 Affected Software WP Highlight Box [wp-highlight-box] Researchers Pablo González Francisco José Ramírez More Details > Zephyr Project Manager <= 3.3.205 - Authenticated (Custom+) Stored Cross-Site Scripting via 'message' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-76931 Patch Status Patched Published Sep 7, 2026 Affected Software Zephyr Project Manager [zephyr-project-manager] Researcher Nabil Irawan More Details > Gato GraphQL <= 19.2.3 - Authenticated (Subscriber+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-62102 Patch Status Patched Published Sep 11, 2026 Affected Software Gato GraphQL [gatographql] Researcher benzdeus More Details > MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions 5.0.0 - 5.0.15 - Authenticated (Custom Role+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-74925 Patch Status Patched Published Sep 11, 2026 Affected Software MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions [dc-woocommerce-multi-vendor] Researcher Philipp Doblhofer More Details > Registration Form for WooCommerce 1.1.0 - 1.1.2 - Authenticated (Contributor+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-81431 Patch Status Patched Published Sep 11, 2026 Affected Software Registration Form for WooCommerce [registration-form-for-woocommerce] Researcher Sai Praneeth Koti More Details > SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.9 - Authenticated (Subscriber+) Privilege Escalation 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-62106 Patch Status Patched Published Sep 11, 2026 Affected Software SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery [sms-alert] Researcher benzdeus More Details > Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button <= 3.5.9 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-18964 Patch Status Patched Published Sep 10, 2026 Affected Software Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] Researcher uhcna More Details > Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-85645 Patch Status Patched Published Sep 9, 2026 Affected Software Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] Researcher braintx More Details > Groundhogg — CRM, Newsletters, and Marketing Automation < 4.7.2 - Unauthenticated Open Redirect 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-81741 Patch Status Patched Published Sep 7, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher Yaswanth Reddy Sunkara More Details > HUSKY <= 1.4.3 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-18562 Patch Status Patched Published Sep 10, 2026 Affected Software HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] Researcher Kuba More Details > IPGP Visitors Origin < 1.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-81404 Patch Status Patched Published Sep 7, 2026 Affected Software IPGP Visitors Origin [ipgp-visitors-origin] Researcher Vuln Seeker Cyber Security Team More Details > Product Filter for WooCommerce by WBW <= 3.4.2 - Reflected Cross-Site Scripting via 'wpf_fid' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-7804 Patch Status Patched Published Sep 8, 2026 Affected Software Product Filter for WooCommerce by WBW [woo-product-filter] Researcher Yuto Hyakumoto More Details > Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-19985 Patch Status Patched Published Sep 10, 2026 Affected Software Relevanssi – A Better Search [relevanssi] Researcher Mutantgun More Details > Simple CAPTCHA with Cloudflare Turnstile <= 1.42.1 - Unauthenticated Arbitrary Shortcode Execution 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-66632 Patch Status Patched Published Sep 8, 2026 Affected Software Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] Researcher kta1kri More Details > Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-78172 Patch Status Patched Published Sep 10, 2026 Affected Software Themify – WooCommerce Product Filter [themify-wc-product-filter] Researcher Adrien Brunner More Details > Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-77150 Patch Status Patched Published Sep 10, 2026 Affected Software Unlimited Elements For Elementor [unlimited-elements-for-elementor] Researcher Kuba More Details > User Access Manager <= 2.3.18 - Reflected Cross-Site Scripting via 'tab_group_section' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-19797 Patch Status Patched Published Sep 8, 2026 Affected Software User Access Manager [user-access-manager] Researcher Wordfence PRISM More Details > WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-84960 Patch Status Patched Published Sep 10, 2026 Affected Software WP-Members Membership Plugin [wp-members] Researcher Kuba More Details > Eventin <= 4.1.17 - Missing Authorization to Authenticated (Subscriber+) Notification Flow Management via notification-flow REST API Endpoint 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-11821 Patch Status Patched Published Sep 8, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Sushi Com Abacate More Details > Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-2520 Patch Status Patched Published Sep 7, 2026 Affected Software Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] Researcher KoreaInfoSec More Details > Advanced Partial Payment or Deposit for WooCommerce <= 3.1.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27378 Patch Status Patched Published Sep 10, 2026 Affected Software Advanced Partial Payment or Deposit for WooCommerce [advanced-partial-payment-or-deposit-for-woocommerce] Researcher Arif Shaikh More Details > bbPress <= 2.6.14 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-62137 Patch Status Patched Published Sep 11, 2026 Affected Software bbPress [bbpress] Researcher Ananda Dhakal More Details > Booking for Appointments and Events Calendar – Amelia 9.0 - 9.8.0 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77689 Patch Status Patched Published Sep 10, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Pedro Pinho More Details > Bookit — Booking & Appointment Calendar < 2.6.0.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-88995 Patch Status Patched Published Sep 13, 2026 Affected Software Bookit — Booking & Appointment Calendar [bookit] Researcher Philipp Doblhofer More Details > Booktics – Appointment Booking Calendar for Service Businesses <= 1.0.24 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-62135 Patch Status Patched Published Sep 10, 2026 Affected Software Booktics – Appointment Booking Calendar for Service Businesses [booktics] Researcher Supakiad S. (m3ez) More Details > Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-11446 Patch Status Patched Published Sep 10, 2026 Affected Software Booktics – Appointment Booking Calendar for Service Businesses [booktics] Researcher revblock More Details > Csomagpontok és Címkék WooCommerce-hez < 4.2.8 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81790 Patch Status Patched Published Sep 7, 2026 Affected Software Csomagpontok és Címkék WooCommerce-hez [hungarian-pickup-points-for-woocommerce] Researcher Peng Zhou More Details > Directory Kit <= 1.5.7 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-18232 Patch Status Unpatched Published Sep 12, 2026 Affected Software WP Directory Kit [wpdirectorykit] Researcher Erwan LR More Details > Domain For Sale – Landing Page Per Domain, Domain Mapping, Offers & Listings <= 3.5.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-89023 Patch Status Patched Published Sep 13, 2026 Affected Software Domain For Sale – Landing Page Per Domain, Domain Mapping, Offers & Listings [domain-for-sale] Researcher Labda More Details > DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-11355 Patch Status Patched Published Sep 11, 2026 Affected Software DT LMS – elearning, WordPress LMS Plugin [dt-lms-lite] Researcher adhikara13 More Details > ElasticPress <= 5.3.4 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-62088 Patch Status Patched Published Sep 11, 2026 Affected Software ElasticPress [elasticpress] Researcher murloc.mrglwglwgl More Details > Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.6.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81802 Patch Status Patched Published Sep 7, 2026 Affected Software Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar [mage-eventpress] Researcher benzdeus More Details > Eventin <= 4.1.22 - Missing Authorization to Unauthenticated Arbitrary Order Creation and Status Manipulation via 'status' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12956 Patch Status Patched Published Sep 8, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Wordfence PRISM More Details > Express Checkout <= 2.4.0 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-83537 Patch Status Patched Published Sep 7, 2026 Affected Software WP Express Checkout (Fast Payments via PayPal & Stripe) [wp-express-checkout] Researcher Ryan Zegar More Details > Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-62136 Patch Status Patched Published Sep 10, 2026 Affected Software Flexible Quantity – Measurement Price Calculator for WooCommerce [flexible-quantity-measurement-price-calculator-for-woocommerce] Researcher sungbyeongchan More Details > IMPress for IDX Broker <= 3.3.0 - Unauthenticated Unauthorized Lead and Search Manipulation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81787 Patch Status Patched Published Sep 8, 2026 Affected Software IMPress for IDX Broker [idx-broker-platinum] Researcher Nguyen Dinh Hai (HaiND) More Details > IP2Location Country Blocker <= 2.44.0 - IP Soofing 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82530 Patch Status Patched Published Sep 9, 2026 Affected Software IP2Location Country Blocker [ip2location-country-blocker] Researcher AmirSUN More Details > JetFormBuilder — Dynamic Blocks Form Builder < 3.6.5.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-19858 Patch Status Patched Published Sep 7, 2026 Affected Software JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] Researcher Jakub Herman More Details > Kirki – Freeform Page Builder, Website Builder & Customizer 6.2.1 - 6.2.5 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-84222 Patch Status Patched Published Sep 9, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Mohammed Abd Alrahman More Details > Loops & Logic <= 4.2.0 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-16960 Patch Status Patched Published Sep 7, 2026 Affected Software Loops & Logic [tangible-loops-and-logic] Researcher Philipp Doblhofer More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates 1.3.1 - 2.3.3 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82848 Patch Status Patched Published Sep 9, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher Karthik Ramakrishnan More Details > MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor < 4.1.9 - Unauthenticated Email Header Injection 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-86813 Patch Status Patched Published Sep 9, 2026 Affected Software MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] Researcher Artus KG More Details > miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) 6.2.8 - 6.3.0 - Unauthenticated Second Factor Authentication Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77771 Patch Status Patched Published Sep 8, 2026 Affected Software miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) [miniorange-2-factor-authentication] Researcher pervinzahidli More Details > Mobile Events Manager <= 1.4.8.3 & MDJM Event Management < 1.7.8.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-88802 Patch Status Partially Patched Published Sep 11, 2026 Affected Software MDJM Event Management [mobile-dj-manager] Mobile Events Manager [mobile-events-manager] Researchers Enrico Marcolini Claudio Marchesini More Details > Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82213 Patch Status Unpatched Published Sep 11, 2026 Affected Software Nexi XPay Build [nexi-xpay-build] Researcher Ryan Fabella More Details > OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12215 Patch Status Patched Published Sep 10, 2026 Affected Software OTP Login & Register Woocommerce [mobile-login-woocommerce] Researcher d4ngvn More Details > Passster – Password Protect Pages and Content <= 4.3.13 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-62114 Patch Status Patched Published Sep 11, 2026 Affected Software Passster – Password Protect Pages and Content [content-protector] Researcher Salúa Es-sair More Details > Payment Gateway PayPay for WooCommerce 0.5 - 0.9.3 - Unauthenticated Payment Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82215 Patch Status Unpatched Published Sep 11, 2026 Affected Software Payment Gateway PayPay for WooCommerce [wc-paypay-gateway] Researcher Pedro Pinho More Details > Payment Plugins for PayPal WooCommerce <= 2.0.25 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-80340 Patch Status Patched Published Sep 7, 2026 Affected Software Payment Plugins for PayPal WooCommerce [pymntpl-paypal-woocommerce] Researcher Erwan LR More Details > Payment Plugins for Stripe WooCommerce <= 4.0.11 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-80339 Patch Status Patched Published Sep 7, 2026 Affected Software Payment Plugins for Stripe WooCommerce [woo-stripe-payment] Researcher m1w34p0n More Details > Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.9.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81785 Patch Status Unpatched Published Sep 9, 2026 Affected Software Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) [buddyforms] Researcher Peng Zhou More Details > Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.5 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-62140 Patch Status Patched Published Sep 10, 2026 Affected Software Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker [quiz-master-next] Researcher Adam Kahlon More Details > Really Simple Security <= 9.8.0 - Unauthenticated Two-Factor Authentication Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-89080 Patch Status Patched Published Sep 11, 2026 Affected Software Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] Researcher Charles Vosburgh More Details > Return Refund and Exchange For WooCommerce <= 4.6.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81799 Patch Status Unpatched Published Sep 8, 2026 Affected Software Return Refund and Exchange For WooCommerce [woo-refund-and-exchange-lite] Researcher babyhack More Details > Robokassa payment gateway for Woocommerce <= 1.8.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78536 Patch Status Unpatched Published Sep 9, 2026 Affected Software Robokassa payment gateway for Woocommerce [robokassa] Researcher Nguyen Dinh Hai (HaiND) More Details > Rox Appointment Booking – Appointment Booking Scheduling Solution < 1.2.0 - Payment Bypass to Unauthenticated Arbitrary Booking Price and Payment Method Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-87892 Patch Status Patched Published Sep 10, 2026 Affected Software Rox Appointment Booking – Appointment Booking Scheduling Solution [rox-appointment-booking] Researcher Morato Antoine More Details > Rox Appointment Booking – Appointment Booking Scheduling Solution 1.0.9 - 1.2.2 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-87894 Patch Status Patched Published Sep 12, 2026 Affected Software Rox Appointment Booking – Appointment Booking Scheduling Solution [rox-appointment-booking] Researcher Farid Narimanov More Details > Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-17585 Patch Status Patched Published Sep 11, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher TarPeg007 More Details > Salon Booking System – Appointment Booking for Salons, Barbershops & Spas <= 10.31.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81793 Patch Status Unpatched Published Sep 8, 2026 Affected Software Salon Booking System – Appointment Booking for Salons, Barbershops & Spas [salon-booking-system] Researcher Tiago Ventura More Details > Shirt Product Designer for WooCommerce 1.0.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81794 Patch Status Unpatched Published Sep 9, 2026 Affected Software Shirt Product Designer for WooCommerce [woo-shirt-product-designer] Researcher Evan NR More Details > Simple CAPTCHA with Cloudflare Turnstile <= 1.42.1 - Captcha Bypass 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-66674 Patch Status Patched Published Sep 8, 2026 Affected Software Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] Researcher Ananda Dhakal More Details > Social Contact Form (FormyChat) <= 2.15.7 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-77773 Patch Status Patched Published Sep 11, 2026 Affected Software Contact Form to Chat Apps | Click to Chat to Order – FormyChat [social-contact-form] Researcher Vaibhav Narkhede More Details > Sunshine Photo Cart <= 3.6 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-85037 Patch Status Patched Published Sep 7, 2026 Affected Software Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers [sunshine-photo-cart] Researcher Farid Narimanov More Details > SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Read 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81021 Patch Status Patched Published Sep 7, 2026 Affected Software SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent [supportcandy] Researcher Muni Nitish Kumar Yaddala More Details > SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent 3.3.6 - 3.5.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81022 Patch Status Patched Published Sep 9, 2026 Affected Software SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent [supportcandy] Researcher Mitre Osman Hussein More Details > SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments < 4.7.0 - Unauthorized WordPress Account Creation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-75793 Patch Status Patched Published Sep 8, 2026 Affected Software SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] Researcher Jakub Herman More Details > SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema & Open Graph 1.6.2 - 1.10.0 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78152 Patch Status Patched Published Sep 12, 2026 Affected Software SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema & Open Graph [surerank] Researcher Vaibhav Narkhede More Details > Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-14562 Patch Status Unpatched Published Sep 9, 2026 Affected Software Teddy Bear Customize Addon [teddy-bear-customize-addon] Researcher 0xBassia More Details > Thanko Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.2.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81786 Patch Status Unpatched Published Sep 8, 2026 Affected Software Thanko Thank You Page Customizer for WooCommerce – Increase Your Sales [woo-thank-you-page-customizer] Researcher Tony Harris More Details > Travel <= 12.0.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-18042 Patch Status Patched Published Sep 7, 2026 Affected Software WP Travel – Ultimate Travel Booking System, Tour Management Engine [wp-travel] Researcher Erwan LR More Details > Travel <= 12.0.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13144 Patch Status Patched Published Sep 7, 2026 Affected Software WP Travel – Ultimate Travel Booking System, Tour Management Engine [wp-travel] Researcher Revanth Hari Narayana Matte More Details > Travel <= 12.0.1 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13146 Patch Status Patched Published Sep 7, 2026 Affected Software WP Travel – Ultimate Travel Booking System, Tour Management Engine [wp-travel] Researcher Revanth Hari Narayana Matte More Details > Ultimate Gift Cards for WooCommerce < 3.2.10 - Unauthenticated Inflated Gift Card Credit Acquisition 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-19436 Patch Status Patched Published Sep 8, 2026 Affected Software Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] Researcher Guillermo Álvarez Fernández More Details > Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-19439 Patch Status Patched Published Sep 10, 2026 Affected Software Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] Researcher Usama Arshad More Details > User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 5.0 - 5.2.7 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-86407 Patch Status Patched Published Sep 13, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researcher Karthik Ramakrishnan More Details > WP Compress <= 7.22.01 - Missing Authorization to Unauthenticated Account Linking / Site Takeover via 'force_ic_connect' and 'apikey' Parameters 5.3 CVSS Rating 5.3 (Medium) Patch Status Patched Published Sep 8, 2026 Affected Software WP Compress – Instant Performance & Speed Optimization [wp-compress-image-optimizer] Researcher Wordfence PRISM More Details > WP Fast Total Search – The Power of Indexed Search <= 1.82.284 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-84821 Patch Status Patched Published Sep 9, 2026 Affected Software WP Fast Total Search – The Power of Indexed Search [fulltext-search] Researcher William Honnér More Details > WP Travel – Ultimate Travel Booking System, Tour Management Engine <= 12.0.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81796 Patch Status Unpatched Published Sep 8, 2026 Affected Software WP Travel – Ultimate Travel Booking System, Tour Management Engine [wp-travel] Researcher Sandeep V More Details > WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services < 8.5.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-87918 Patch Status Patched Published Sep 12, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services [chatbot] Researcher Pedro Pinho More Details > WPBot <= 8.5.9 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-87916 Patch Status Patched Published Sep 10, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services [chatbot] Researcher Seongwon Lee More Details > WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System 3.0.10 - 3.0.17 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-86812 Patch Status Patched Published Sep 11, 2026 Affected Software WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] Researcher Artus KG More Details > WPFunnels <= 3.12.13 - Missing Authorization to Unauthenticated Arbitrary Product Price Manipulation via 'wpfnl_load_payment' AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-84908 Patch Status Patched Published Sep 8, 2026 Affected Software WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell [wpfunnels] Researcher Wordfence PRISM More Details > WPLP Cookie Consent <= 4.4.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82184 Patch Status Patched Published Sep 7, 2026 Affected Software WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode [gdpr-cookie-consent] Researcher Alex Spataru More Details > YITH WooCommerce Wishlist < 4.18.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-82305 Patch Status Patched Published Sep 11, 2026 Affected Software YITH WooCommerce Wishlist [yith-woocommerce-wishlist] Researcher Abdullah Kareem More Details > ZHBackup – Backup, Restore & Migration <= 2.4.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-81804 Patch Status Patched Published Sep 9, 2026 Affected Software ZHBackup – Backup, Restore & Migration [zhbackup] Researcher Ananda Dhakal More Details > zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-78361 Patch Status Patched Published Sep 11, 2026 Affected Software zipMoney(Zip Co) Payments Plugin for WooCommerce [zipmoney-payments-woocommerce] Researcher Naoki Kawahigashi More Details > المنتور فارسی 2.7.10 - 2.8.1 - Payment Bypass to Unauthenticated Unauthorized Order Completion 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-86809 Patch Status Patched Published Sep 9, 2026 Affected Software المنتور فارسی [persian-elementor] Researcher Artus KG More Details > Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticated (Editor+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-62112 Patch Status Patched Published Sep 11, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Ananda Dhakal More Details > Directory Kit <= 1.5.7 - Authenticated (Editor+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-16593 Patch Status Unpatched Published Sep 12, 2026 Affected Software WP Directory Kit [wpdirectorykit] Researcher Yaswanth Reddy Sunkara More Details > Mail Mint <= 1.31.0 - Authenticated (Custom+) SQL Injection via 'status' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-19800 Patch Status Patched Published Sep 8, 2026 Affected Software Mail Mint – Email Marketing, Automation & WooCommerce Emails with AI Assistance [mail-mint] Researcher Wordfence PRISM More Details > Quentn WP <= 1.2.14 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-84113 Patch Status Patched Published Sep 7, 2026 Affected Software Quentn WP [quentn-wp] Researcher Yaswanth Reddy Sunkara More Details > Sky Addons for Elementor <= 3.8.4 - Authenticated (Editor+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-62109 Patch Status Patched Published Sep 11, 2026 Affected Software Sky Addons for Elementor [sky-elementor-addons] Researcher Ananda Dhakal More Details > WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-18386 Patch Status Unpatched Published Sep 9, 2026 Affected Software WP BackItUp Community Edition [wp-backitup] Researcher Nikola Kojic More Details > WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-19944 Patch Status Patched Published Sep 8, 2026 Affected Software WP Crowdfunding [wp-crowdfunding] Researcher Wordfence PRISM More Details > Temporary Login Without Password 1.5 - 1.9.8 - Authenticated (Administrator+) Privilege Escalation 4.7 CVSS Rating 4.7 (Medium) CVE-ID CVE-2026-77752 Patch Status Patched Published Sep 12, 2026 Affected Software Temporary Login Without Password [temporary-login-without-password] Researcher BaptouTatis More Details > Translate WordPress with GTranslate < 3.0.10 - Authenticated (Administrator+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2025-15695 Patch Status Patched Published Sep 9, 2026 Affected Software Translate WordPress with GTranslate [gtranslate] Researcher Dmitrii Ignatyev More Details > Advanced Contact form 7 DB <= 2.1.3 - Missing Authorization to Authenticated (Custom+) Unauthorized Data Import via 'import_cf7_id' 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-18594 Patch Status Unpatched Published Sep 9, 2026 Affected Software Advanced Contact form 7 DB [advanced-cf7-db] Researcher Jiang CY More Details > Advanced Customized Prompts <= 1.0.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-14566 Patch Status Unpatched Published Sep 9, 2026 Affected Software Advanced Customized Prompts [advanced-customized-prompts] Researcher 0xBassia More Details > Awesome Support <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via 'user_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-19946 Patch Status Patched Published Sep 8, 2026 Affected Software Awesome Support – WordPress HelpDesk & Support Plugin [awesome-support] Researcher Wordfence PRISM More Details > BackWPup – WordPress Backup & Restore Plugin 5.2.2 - 5.7.4 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-86815 Patch Status Patched Published Sep 11, 2026 Affected Software BackWPup – WordPress Backup & Restore Plugin [backwpup] Researcher Charles Vosburgh More Details > BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) < 1.2.2 - Authenticated (Custom Role+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-84025 Patch Status Patched Published Sep 12, 2026 Affected Software BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) [woo-bulk-editor] Researcher Ali Mousavi More Details > BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) < 1.2.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-84023 Patch Status Patched Published Sep 12, 2026 Affected Software BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) [woo-bulk-editor] Researcher Ali Mousavi More Details > BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) < 1.2.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-84024 Patch Status Patched Published Sep 12, 2026 Affected Software BEAR – Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server) [woo-bulk-editor] Researcher Ali Mousavi More Details > BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2024-12145 Patch Status Patched Published Sep 10, 2026 Affected Software BuddyPress [buddypress] Researcher Brian Mungai More Details > Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15823 Patch Status Unpatched Published Sep 9, 2026 Affected Software Builderall for WordPress [builderall-cheetah-for-wp] Researcher Wordfence PRISM More Details > Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-19802 Patch Status Patched Published Sep 8, 2026 Affected Software Checkout Custom Fields Builder for WooCommerce [checkout-custom-fields-builder-for-woocommerce] Researcher Nabil Irawan More Details > Directory Kit <= 1.5.7 - Authenticated (Contributor+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-16592 Patch Status Unpatched Published Sep 12, 2026 Affected Software WP Directory Kit [wpdirectorykit] Researcher Yaswanth Reddy Sunkara More Details > Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.22 - Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15398 Patch Status Patched Published Sep 8, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Wordfence PRISM More Details > ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8615 Patch Status Patched Published Sep 8, 2026 Affected Software ilGhera Reviso Exporter for WooCommerce [wc-exporter-for-reviso] Researcher Legion Hunter More Details > IMPress for IDX Broker <= 3.3.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81788 Patch Status Patched Published Sep 8, 2026 Affected Software IMPress for IDX Broker [idx-broker-platinum] Researcher Nguyen Dinh Hai (HaiND) More Details > MailMunch – Grow your Email List <= 3.2.5 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81783 Patch Status Unpatched Published Sep 8, 2026 Affected Software MailMunch – Grow your Email List [mailmunch] Researcher Jakub Herman More Details > Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits <= 3.2.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-62089 Patch Status Patched Published Sep 11, 2026 Affected Software Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits [master-addons] Researcher TurboNexic More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 3.4.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-62132 Patch Status Patched Published Sep 10, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher MYUNGYONG LEE More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates 1.14.0 - 3.4.0 - Authenticated (Custom Role+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-82851 Patch Status Patched Published Sep 12, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher Karthik Ramakrishnan More Details > Notiqoo – Order Notification & Customer Chat for WooCommerce < 1.4.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Option Modification 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-19840 Patch Status Patched Published Sep 10, 2026 Affected Software Notiqoo – Order Notification & Customer Chat for WooCommerce [wc-messaging] Researcher Seongwon Lee More Details > Payment Plugins for PayPal WooCommerce <= 2.0.25 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-80341 Patch Status Patched Published Sep 7, 2026 Affected Software Payment Plugins for PayPal WooCommerce [pymntpl-paypal-woocommerce] Researchers m1w34p0n Krypt3d More Details > Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More < 3.1.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-87919 Patch Status Patched Published Sep 12, 2026 Affected Software Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More [product-xml-feeds-for-woocommerce] Researcher Abdullah Kareem More Details > Quads Ads Manager for Google AdSense 3.0.4 - Authenticated (Subscriber+) Payment Bypass to Unpaid Ad Placement Acquisition 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-89050 Patch Status Patched Published Sep 11, 2026 Affected Software Quads Ads Manager for Google AdSense [quick-adsense-reloaded] Researcher JunHee CHO More Details > rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-88912 Patch Status Patched Published Sep 13, 2026 Affected Software rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] Researcher JunHee CHO More Details > RTMKit <= 2.1.5 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-62133 Patch Status Patched Published Sep 10, 2026 Affected Software RTMKit [rometheme-for-elementor] Researcher MYUNGYONG LEE More Details > Simple Membership < 4.7.8 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-88764 Patch Status Patched Published Sep 11, 2026 Affected Software Simple Membership [simple-membership] Researcher Charles Vosburgh More Details > Site Kit by Google – Analytics, Search Console, AdSense, Speed <= 1.186.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-62139 Patch Status Patched Published Sep 10, 2026 Affected Software Site Kit by Google – Analytics, Search Console, AdSense, Speed [google-site-kit] Researcher Ananda Dhakal More Details > Slim SEO – AI SEO Plugin, Lightweight, Fast & Automated <= 4.10.0 - Authenticated (Contributor+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-62113 Patch Status Patched Published Sep 11, 2026 Affected Software Slim SEO – AI SEO Plugin, Lightweight, Fast & Automated [slim-seo] Researcher Sybre Waaijer More Details > Sprout Invoices – Client Invoicing & Estimates < 20.8.16 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-87797 Patch Status Patched Published Sep 12, 2026 Affected Software Sprout Invoices – Client Invoicing & Estimates [sprout-invoices] Researcher Usama Arshad More Details > SSL Zen — SSL Certificate Installer & HTTPS Redirects < 4.7.40 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-86781 Patch Status Patched Published Sep 11, 2026 Affected Software SSL Zen — SSL Certificate Installer & HTTPS Redirects [ssl-zen] Researcher Suhayb Ahmed More Details > Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg <= 4.7.5 - Authenticated (Contributor+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-62134 Patch Status Patched Published Sep 10, 2026 Affected Software Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg [astra-sites] Researcher Ananda Dhakal More Details > Temporary Login Without Password < 1.9.9 - Authenticated (Custom Role+) Persistent Access After Login Revocation 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-77753 Patch Status Patched Published Sep 10, 2026 Affected Software Temporary Login Without Password [temporary-login-without-password] Researcher BaptouTatis More Details > Ultimate Gift Cards for WooCommerce <= 3.2.9 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-75861 Patch Status Patched Published Sep 7, 2026 Affected Software Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] Researcher Shikhali Jamalzade More Details > Unbounce Landing Pages <= 1.1.4 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81781 Patch Status Patched Published Sep 7, 2026 Affected Software Unbounce Landing Pages [unbounce] Researcher HieuPenguinnn More Details > Visualizer – Tables & Charts Manager with Built-in AI Generator 4.0.0 - 4.0.5 - Authenticated (Contributor+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-86782 Patch Status Patched Published Sep 11, 2026 Affected Software Visualizer – Tables & Charts Manager with Built-in AI Generator [visualizer] Researcher Artus KG More Details > WP Recipe Maker <= 10.8.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via '[wprm-recipe]' Shortcode 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-75905 Patch Status Patched Published Sep 8, 2026 Affected Software WP Recipe Maker [wp-recipe-maker] Researcher Wordfence PRISM More Details > WP-Stateless – Google Cloud Storage <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-81801 Patch Status Patched Published Sep 8, 2026 Affected Software WP-Stateless – Google Cloud Storage [wp-stateless] Researcher Johan Buenavida More Details > WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 4.0.2 - 4.4.1 - Missing Authorization to Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-85132 Patch Status Patched Published Sep 7, 2026 Affected Software WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode [gdpr-cookie-consent] Researcher Karthik Ramakrishnan More Details > WPLP Cookie Consent <= 4.4.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-85133 Patch Status Patched Published Sep 7, 2026 Affected Software WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode [gdpr-cookie-consent] Researcher Naoki Kawahigashi More Details > WPLP Cookie Consent <= 4.4.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-82185 Patch Status Patched Published Sep 7, 2026 Affected Software WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode [gdpr-cookie-consent] Researcher RIA Labs More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026) appeared first on Wordfence .

Share this article