In Visual Composer Website Builder component for WordPress versions 45.16.0 and earlier a critical severity vulnerability CVE-2026-12227 was detected. This vulnerability allows unauthenticated attackers to include and execute arbitrary files on the server. To address this issue, users should upgrade Visual Composer Website Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12227.
Read more CMSIn WP Multilang – Translation and Multilingual Plugin component for WordPress versions 2.4.31 and earlier a medium severity vulnerability CVE-2026-15731 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade WP Multilang – Translation and Multilingual Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15731.
Read more CMSIn the Kirki – Freeform Page Builder, Website Builder & Customizer component for WordPress versions 6.2.0 and earlier a medium severity vulnerability CVE-2026-18335 was detected. This vulnerability allows unauthenticated attackers to make web requests to arbitrary locations from the server. To address this issue, users should upgrade the Kirki plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18335.
Read more CMSIn eesy_ID2WP – Publish InDesign HTML5 plugin component for WordPress versions 1.0.3 and earlier a high severity vulnerability CVE-2026-77193 was detected. This vulnerability allows unauthenticated attackers to read the contents of arbitrary files on the server. To address this issue, users should upgrade eesy_ID2WP – Publish InDesign HTML5 plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77193.
Read more CMSIn YOP Poll component for WordPress versions 7.0.10 and earlier a high severity vulnerability CVE-2026-85682 was detected. This vulnerability allows unauthenticated attackers to take over an administrator’s account. To address this issue, users should upgrade YOP Poll to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-85682.
Read more CMSIn HashBar – WordPress Notification Bar component for WordPress versions 2.0.3 and earlier a high severity vulnerability CVE-2026-94117 was detected. This vulnerability allows attackers to execute arbitrary SQL commands. To address this issue, users should upgrade HashBar – WordPress Notification Bar to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-94117.
Read more CMS