Top/Articles/27 WordPress plugin flaws, no-login admin takeover (CVE-2026-15930)
wordpress-plugins-2026-08-03-unauthenticated-takeover-roundup-cover-en

27 WordPress plugin flaws, no-login admin takeover (CVE-2026-15930)

27 WordPress plugin flaws landed August 3, 2026. Simple Membership (40,000+ sites) gives up the admin account with no login. Eleven need no login, 7 unfixed.

NewsPublished Aug. 3, 2026 Updated today
Table of contents
Key takeaways

27 WordPress plugin flaws landed August 3, 2026. Simple Membership (40,000+ sites) gives up the admin account with no login. Eleven need no login, 7 unfixed.

On August 3, 2026, 27 WordPress plugin vulnerabilities were published to the NVD in a single batch by WPScan. If you run a membership site, the most immediate one is in Simple Membership: someone who is not logged in can overwrite the email address attached to an administrator account and then use the standard password-reset flow to take the dashboard. It is installed on more than 40,000 sites.

The largest by reach is SVG Support, which lets WordPress accept SVG image files and runs on more than 1,000,000 sites. Also on the list: Simply Schedule Appointments (60,000+), which holds customer booking data; Import and export users and customers (70,000+); and Clearfy Cache (50,000+). Adding up only the 15 plugins whose install counts are published gives more than 1,320,000 sites running at least one affected product.

Three things up front. First, 11 of the 27 need no login at all. Second, seven have no fix, and six of those plugins have been pulled from WordPress.org entirely β€” for those, the action is deletion, not an update. Third, none of the 27 carry an NVD severity score yet. With no numbers to sort by, this article orders everything by whether an attacker needs an account. Earlier batches are covered the same way in the nine flaws of July 29, the 18 of July 28, and the four of July 23.

One published detail did not match reality. Blog Floating Button is listed as having no fix, but it was actually patched in 1.4.21, released July 31. We pulled the source from the official repository and diffed it. Details below.

What the 27 flaws actually are

The set splits cleanly in two: 11 that anyone can reach from outside and 16 that require some kind of account on the site. The first group is reachable simply by being online, so the order of work decides itself.

The 11 no-login issues cover administrator takeover (Simple Membership), unauthorized database queries (Link Library, LogMyTrip, Super Store Finder), planting executable files on the server (Webinfos, Personal QR Message), signing in as someone else (SoftMarket, ChamaWP), scripts injected into the admin dashboard (Simple Membership, Blog Floating Button), and abuse of an internal data-restoration routine (ChamaWP). Because there are no prerequisites on the attacker's side, these are the ones automated scanners pick up.

The remaining 16 need a contributor, author, editor, or subscriber account. "Needs an account" is not the same as "safe." On sites with open registration, multi-author publications, or self-enrolment courses, an attacker can obtain that account through the normal front door. The Academy LMS issue (CVE-2026-16563) is exactly that: a student account anyone can create is enough to read unpublished lesson content.

All 27 are in plugins, not WordPress core. Sites that do not run the affected plugin are unaffected. Core issues are tracked separately in our WordPress core vulnerability roundup.

Affected products at a glance

All 27 are listed below, no-login issues first. Install counts are approximate figures from the WordPress.org plugin API; blanks mean the plugin is either closed there or not distributed there at all, so no count is retrievable. Every severity cell reads "not yet scored" because the NVD has not assigned one β€” we have not substituted a number of our own.

CVEProductPurposeInstallsAffectedSafe versionLoginSeverity
CVE-2026
-15930
Simple
Membership
Paid memberships40,000+< 4.7.84.7.8+
(latest 4.7.9)
NoneNot yet scored
CVE-2026
-15931
Simple
Membership
Paid memberships40,000+< 4.7.84.7.8+NoneNot yet scored
CVE-2026
-16532
Link LibraryLink directories,
visitor submissions
10,000+< 7.9.37.9.3+
(latest 7.9.4)
NoneNot yet scored
CVE-2026
-15383
Blog Floating
Button
Floating button,
traffic reports
9,000+<= 1.4.201.4.21+
(advisory says
"no known fix")
NoneNot yet scored
CVE-2026
-16572
LogMyTripTravel logsClosed β€”
not retrievable
<= 1.9
(all versions)
No fix
Delete it
NoneNot yet scored
CVE-2026
-12965
Super Store
Finder
Store locator mapsβ€”<= 7.8
(all versions)
No fix
Ask the vendor
NoneNot yet scored
CVE-2026
-14557
SoftMarketDigital product
storefronts
Closed β€”
not retrievable
<= 1.0.0
(all versions)
No fix
Delete it
NoneNot yet scored
CVE-2026
-12872
WebinfosSite information
display
Closed β€”
not retrievable
<= 1.2
(all versions)
No fix
Delete it
NoneNot yet scored
CVE-2026
-16250
Personal QR
Message
QR code messagesClosed β€”
not retrievable
<= 1.0
(all versions)
No fix
Delete it
NoneNot yet scored
CVE-2025
-15672
ChamaWPDonations,
crowdfunding
10+< 1.0.131.0.13+NoneNot yet scored
CVE-2026
-16300
ChamaWPDonations,
crowdfunding
10+< 1.0.131.0.13+NoneNot yet scored
CVE-2026
-13340
SVG SupportAllows SVG
image uploads
1,000,000+< 2.5.172.5.17+
(latest 2.6.1)
AuthorNot yet scored
CVE-2026
-16534
Import and
export users
Bulk user import70,000+< 2.4.22.4.2+
(latest 2.4.9)
User-creation
capability
Not yet scored
CVE-2025
-15673
Import and
export users
Bulk user import70,000+< 2.4.32.4.3+AdministratorNot yet scored
CVE-2026
-15254
Simply Schedule
Appointments
Appointment
booking
60,000+< 1.6.12.111.6.12.11+
(latest 1.6.12.13)
ContributorNot yet scored
CVE-2026
-16297
Clearfy CachePerformance
optimisation
50,000+< 2.4.32.4.3+
(discontinued)
AdministratorNot yet scored
CVE-2026
-15231
TaxoPressTag and category
management
40,000+< 3.51.03.51.0+ContributorNot yet scored
CVE-2026
-16564
DokanMulti-vendor
marketplaces
30,000+< 5.0.95.0.9+
(latest 5.0.11)
VendorNot yet scored
CVE-2026
-16565
DokanMulti-vendor
marketplaces
30,000+< 5.0.95.0.9+VendorNot yet scored
CVE-2026
-16274
Classified
Listing
Classified ad sites9,000+< 5.4.45.4.4+
(latest 6.0.0)
ContributorNot yet scored
CVE-2026
-16276
Classified
Listing
Classified ad sites9,000+< 5.4.45.4.4+ContributorNot yet scored
CVE-2026
-16289
ProfileGridMember profiles
and groups
5,000+< 6.0.0.06.0.0.0+
(latest 6.0.0.1)
SubscriberNot yet scored
CVE-2026
-15260
GEO my WPMaps and
proximity search
3,000+< 4.5.5.34.5.5.3+SubscriberNot yet scored
CVE-2026
-16563
Academy LMSOnline courses2,000+< 3.8.33.8.3+
(latest 3.8.5)
SubscriberNot yet scored
CVE-2026
-16060
Insert or Embed
Articulate Content
E-learning content
embedding
Closed β€”
not retrievable
<= 4.3000000027
(all versions)
No fix
Delete it
EditorNot yet scored
CVE-2026
-16057
Contest GalleryPhoto contests,
submission galleries
1,000+< 30.0.730.0.7+
(latest 31.0.0)
AuthorNot yet scored
CVE-2026
-16539
SM Page
Duplicator
Page duplicationClosed β€”
not retrievable
<= 1.0.0
(all versions)
No fix
Delete it
EditorNot yet scored

Super Store Finder is a commercial product not distributed through WordPress.org, so no install count is available. The six closed plugins (LogMyTrip, SoftMarket, Webinfos, Personal QR Message, Insert or Embed Articulate Content, SM Page Duplicator) replace their stats block with a closure notice, so those counts cannot be retrieved either. A blank means we looked and could not find out.

Who comes looking, what they do, and what it costs you

The first thing to reach a flaw like these is not a person who picked your site. It is an automated program working its way through WordPress sites worldwide, matching plugin names and version numbers against a list. Nobody decides you are worth attacking; a machine notices you match. When the location of a hole is published, a new entry joins that list the next day. A personal blog with fifty members is not exempt.

Once something matches, the goal is usually the same: establish a way back in that survives whatever you do next. In this batch that means overwriting the administrator's email address through the Simple Membership flaw, or dropping an executable file onto the server through Webinfos or Personal QR Message. With a way back in secured, there is no hurry about the rest.

What gets lost differs by who you are. Members stand to lose names, email addresses, and payment records. This batch includes booking customers' personal details (Simply Schedule Appointments), unpurchased course content (Academy LMS), and the list of people who applied to join a private group (ProfileGrid) β€” each becoming visible to someone who should not see it. Site owners lose something slower and more expensive: a compromised site quietly redirecting visitors to fraud pages or relaying spam, then dropping out of search results, then losing the domain's reputation outright. Recovery at that stage runs from days to weeks. Which is the argument for handling this while "run the update" is still the whole job.

The 11 that need no login

Taking them individually, starting with the ones that need no account. If you run any of these, today is the day.

CVE-2026-15930: Simple Membership hands over the administrator account

Simple Membership adds paid membership functionality to WordPress β€” gating posts behind a subscription, handling recurring billing. Over 40,000 sites run it.

Before 4.7.8, the routine that creates a new member does not check the return value when creation fails, and uses it as a user ID anyway. Exploiting that, an attacker can overwrite the email address registered to an existing administrator account with their own. From there, WordPress's own "lost your password" link delivers a reset to the attacker. No login is required at any point. WPScan rates it 9.4 out of 10, the highest of all 27.

The fix is 4.7.8; the current release is 4.7.9. We checked the NVD entry and it still carries no severity score. Reading that absence as "not serious" would be flatly wrong here.

CVE-2026-15931: A trap planted in the Simple Membership dashboard from outside

A second issue in the same plugin, closed by the same 4.7.8 release. The subscriber name arriving in a payment-approval notification was rendered straight into the admin dashboard without being made safe first. Put program code in the name field and it runs in the administrator's browser β€” triggered by nothing more than opening the member list.

This class of flaw is called stored cross-site scripting: once the trap is saved, it fires every time the administrator loads that screen. It can be driven as far as silently creating new administrator accounts. Because payment-approval notifications can be sent without logging in, the whole thing is reachable from outside. WPScan rates it 8.8. One update closes both.

CVE-2026-16532: Link Library's submission form reaches the database

Link Library builds link directory pages and can accept submissions from visitors. Over 10,000 sites use it. Before 7.9.3, values from that submission form were dropped straight into a database query.

The result: a specially written string in the form makes the database run a query the developer never intended. Member email addresses, stored password values, unpublished posts β€” essentially anything in that site's database becomes reachable. The technique is SQL injection, well understood for over twenty years and still among the most damaging. WPScan rates it 8.6. The fix is 7.9.3; 7.9.4 is current and its changelog notes "Fixed potential security issue."

CVE-2026-15383: Blog Floating Button is listed as unfixed, but it is fixed

This is where the published record and reality diverged. Blog Floating Button adds a sticky on-screen button and traffic analytics, and runs on over 9,000 sites.

In 1.4.20 and earlier, the user-agent string β€” a self-declared identifier the visitor's browser sends and the visitor fully controls β€” was written into the admin analytics report as-is. One visit that declares itself as program code is enough to make that code run the moment an administrator opens the report. No login needed.

The WPScan advisory says "no known fix." But WordPress.org has 1.4.21, released July 31. To settle it, we pulled every file of both 1.4.20 and 1.4.21 from the official source repository and diffed them.

It is fixed. In 1.4.20 the admin report file (inc/report/report-detail-access.php) interpolated the user-agent value with no conversion; in 1.4.21 it is escaped before output. Input handling was hardened too, with sanitisation added at all four places that touch the value, including the one that stores it. The 1.4.21 changelog states it plainly: "Fixed a stored XSS vulnerability in the access analytics report screen."

The dates explain the mismatch. WPScan published on July 24; the fix shipped on July 31. The advisory simply predates the patch and has not been updated. If you run this plugin, update to 1.4.21 β€” there is no need to conclude that deletion is your only option.

CVE-2026-16572: LogMyTrip has no fix and is no longer distributed

LogMyTrip displays travel logs. In 1.9 and earlier β€” that is, every version β€” a value read from a browser cookie went straight into a database query. Someone who is not logged in only has to edit that cookie to reach the database, and it works from any page that renders one of the plugin's shortcodes.

WPScan rates it 8.6 with no known fix. Querying the WordPress.org plugin API directly returns closed_date: 2026-07-23 β€” distribution stopped the day before WPScan published. Last updated eleven years ago, tested only up to WordPress 4.1. A fix is not coming. Delete it.

CVE-2026-12965: Super Store Finder's store search reaches the database

Super Store Finder is a commercial plugin that plots store locations on a map. In 7.8 and earlier β€” all versions β€” a tracking routine callable without logging in fails to validate its input, allowing unauthorized database queries. WPScan rates it 8.6; no fix has been released.

Because it ships through a commercial marketplace rather than WordPress.org, there is no way to count installations from outside. It is the kind of product that ends up on the sites of companies with physical stores. Ask the vendor about a fix and disable the feature in the meantime.

CVE-2026-14557: SoftMarket lets anyone sign in as someone else

SoftMarket builds digital product storefronts. In 1.0.0 and earlier β€” all versions β€” email verification tokens are not properly validated, so someone with no account can enter the site as another user. WPScan rates it 9.1, second-highest in this batch.

There is no fix, and WordPress.org stopped distributing it on July 6, 2026, described as "temporary, pending a full review." Deletion is the only option.

CVE-2026-12872: Webinfos lets anyone drop files on the server

In Webinfos 1.2 and earlier β€” all versions β€” the file upload routine has no authentication, no capability check, and no file type validation. Anyone can place a server-executable program file somewhere publicly reachable, which is functionally equivalent to handing over control of the server.

WPScan lists no fix. WordPress.org closed it on July 21; the last update was ten years ago. The install count is unavailable, but running a plugin untouched for a decade is itself the problem.

CVE-2026-16250: Personal QR Message has the same shape of flaw

Personal QR Message creates QR-coded messages; 1.0 and earlier are affected. An upload routine with no file type restriction lets someone with no account place a program file and then request it directly. The same structure as Webinfos above.

No fix exists, and WordPress.org closed it on July 21. Last updated four years ago, and WPScan records zero active installations. Real-world exposure is likely negligible, but if it is present, remove it. Reported by JoΓ£o Ramos Maciel.

CVE-2025-15672 / CVE-2026-16300: Both ChamaWP issues need no login

ChamaWP handles donations, membership dues, and crowdfunding. The install base is small β€” 10+ β€” but both flaws are severe enough to note. A slug caveat: on WordPress.org this plugin is chama, not chamawp.

CVE-2025-15672 passes externally supplied data to a PHP deserialization function without validating it. That function turns stored text back into live program values; fed a malicious string, it can combine with other code already present on the site to produce whatever the attacker intended. WPScan rates it 8.1.

CVE-2026-16300 is more direct: password reset requests are not properly validated, so anyone, without logging in, can reset the password of any user including administrators. The advisory title says exactly that: "Unauthenticated Arbitrary User Password Reset." Both are fixed in 1.0.13.

SVG Support, on a million sites, left one compressed back door open

SVG Support (CVE-2026-13340) dwarfs the rest on reach: over 1,000,000 sites. WordPress refuses SVG image uploads by default, and this plugin exists to allow them.

The reason for that default is that an SVG, despite being an image, is written as text β€” a kind of blueprint β€” and program code can be written into it. So SVG Support runs a sanitisation step that strips dangerous instructions out of uploaded files.

Before 2.5.17, that sanitisation was not applied to files with the .svgz extension. That is simply a compressed SVG, and the plugin registered and served it as an SVG β€” it just skipped the cleaning step. Compressing the file was enough to walk code past the check.

Exploiting it requires author-level access or above. But the code runs in the browser of whoever views the file afterwards, so it escalates toward administrator the moment an administrator looks. On multi-author publications, or anywhere outside contributors hold author accounts, that is a realistic path. WPScan rates it 6.8; reported by Shivamani Vastrala, with coordinated disclosure by Erwan Le Rousseau of Automattic.

The fix is 2.5.17 and the current release is 2.6.1 (July 25). One caveat worth knowing: the 2.5.17 changelog does not mention CVE-2026-13340. It cites CVE-2024-10222 and CVE-2023-6708 instead, framing the change as completing those earlier fixes. Searching the changelog by this CVE number returns nothing, so confirm by version number and the NVD record instead. This is a hole that survived two previous rounds of patching and only closed on the third.

The other 15, reachable with an account

Sixteen issues require an account; SVG Support was covered above, leaving 15. If registration is closed on your site these drop in priority β€” if it is open, they do not. Ordered by install base.

CVE-2026-16534: Import and export users escalates a limited role to administrator

Import and export users and customers bulk-loads member data from spreadsheets and runs on over 70,000 sites. Before 2.4.2, it checked neither which roles could be assigned during import nor whether the importer was allowed to edit the users being touched.

An account holding only the "create users" capability can mint a new administrator, or overwrite an existing administrator's email address and password. WPScan calls it "Custom Role Privilege Escalation to Administrator" and rates it 7.2. The more carefully you have scoped your membership manager's permissions, the more this bypass matters. Fixed in 2.4.2; 2.4.9 is current.

CVE-2025-15673: File reads in the same plugin (administrator required)

The same plugin, before 2.4.3, does not restrict the path of the import file, so files elsewhere on the server can be read. It needs administrator rights to trigger, and administrators already hold broad power on the site, so the practical impact is limited. WPScan rates it 4.9, modestly. Updating to 2.4.3 closes this and the previous item together, so there is no reason to stop short.

CVE-2026-15254: Simply Schedule Appointments leaks booking customers' details

Simply Schedule Appointments takes bookings for meetings and visits, on over 60,000 sites. Before 1.6.12.11 an authorization check was missing, so a contributor-level account can read the personal details of booked customers. A booking system by its nature holds names, contact details, and the reason for the appointment. WPScan rates it 2.7 β€” a figure that prices in the account requirement, not the sensitivity of what leaks. Fixed in 1.6.12.11; 1.6.12.13 is current.

CVE-2026-16297: Clearfy Cache is discontinued and 2.4.3 is the end of the line

Clearfy Cache speeds up page delivery on over 50,000 sites. Before 2.4.3, its settings-import routine deserialized data without restricting which classes were allowed β€” the same category as the first ChamaWP issue. Administrator rights are required to trigger it, which pulls the practical severity down.

The plugin's future is the bigger concern. Clearfy Cache was acquired by Super Page Cache in October 2025 and development has been announced as ending. The listing is still live, but 2.4.3 looks like the final release β€” leaving 50,000 sites holding a plugin that will receive no further fixes. How to handle software that has stopped moving is the subject of our OSS supply chain scanner.

CVE-2026-15231: TaxoPress exposes unpublished posts

TaxoPress manages tags and categories on over 40,000 sites. Before 3.51.0, a contributor-level account can read the contents of drafts and private posts. WPScan rates it 2.7. On an editorial site or one handling investor communications, pre-publication content is exactly what matters. Note that the NVD lists this product under a different name β€” "Tag, Category, and Taxonomy Manager" β€” and its WordPress.org slug is simple-tags. Fixed in 3.51.0.

CVE-2026-16564 / CVE-2026-16565: Dokan vendors can touch each other's orders and products

Dokan turns one site into a marketplace hosting many vendors, on over 30,000 sites. Both issues before 5.0.9 come down to the same omission: no check that the order or product in question actually belongs to the caller.

CVE-2026-16564 leaves the bulk order-action endpoint without an ownership check, so anyone with a vendor account can change the status of another vendor's orders. CVE-2026-16565 has the same gap on the product-attribute write endpoint, allowing another vendor's product data to be edited. WPScan rates both 4.3. Vendor accounts are not handed out freely, but on an open marketplace a hostile vendor only needs to apply through the normal process. Both fixed in 5.0.9; 5.0.11 is current.

CVE-2026-16274 / CVE-2026-16276: Classified Listing exposes private posts and revenue

Classified Listing builds job boards and secondhand marketplaces, on over 9,000 sites. Both issues before 5.4.4 are missing permission checks.

CVE-2026-16274 leaves the routine that returns post content without capability or ownership checks, so a contributor-level account can read every draft, pending, and private post on the site, including other people's. CVE-2026-16276 leaves the revenue search without a capability check, exposing site-wide sales totals. WPScan rates both 2.7, but listing sites are built to accept posters broadly, which makes a contributor account one of the easier things to obtain. Both fixed in 5.4.4; 6.0.0 is current.

CVE-2026-16289: ProfileGrid exposes everyone who applied to join a group

ProfileGrid provides member profiles and group features on over 5,000 sites. Before 6.0.0.0, the routine returning pending group join requests had no authorization check. A single subscriber account β€” the lowest role there is β€” reveals the names and request dates of applicants to every group, private ones included. On a site with open registration, an attacker just signs up. Fixed in 6.0.0.0; 6.0.0.1 is current.

CVE-2026-15260: GEO my WP lets subscribers edit other people's locations

GEO my WP handles maps and proximity search on over 3,000 sites. Before 4.5.5.3, the routines handling location data had no ownership check, so a subscriber-level account can modify or delete other users' location records. WPScan rates it 4.3. Fixed in 4.5.5.3.

CVE-2026-16563: Academy LMS gives away courses nobody paid for

Academy LMS builds online course sites, on over 2,000 sites. Before 3.8.3, the endpoint returning an individual lesson checked neither enrolment nor publication status. One self-service student account is enough to read unpurchased courses and unpublished lessons.

For anyone selling paid courses, that is revenue walking out the door. WPScan rates it 4.3; reported by Pedro Pinho. Fixed in 3.8.3; 3.8.5 is current.

CVE-2026-16060: Insert or Embed Articulate Content has no fix

Insert or Embed Articulate Content into WordPress embeds e-learning packages into pages. In every version, the validation of archive contents can be bypassed to place a server-executable file. It needs editor-level access, but success means control of the server.

WPScan lists no fix and is withholding proof-of-concept code until one exists. WordPress.org closed the plugin on July 21, and WPScan's records show roughly 2,000 installs. That is 2,000 sites running something with no path to a patch β€” a product that tends to appear on corporate training and school sites. Deletion is the only remedy.

CVE-2026-16057: Contest Gallery lets authors delete any post

Contest Gallery runs photo contests and submission galleries on over 1,000 sites. Before 30.0.7, the routine that removes a video from the library had neither a per-object capability check nor a tampering guard, so an author-level account can delete any post or page on the site. WPScan rates it 6.5. Contest sites hand out posting rights to entrants by design, so the precondition is easy to meet. Fixed in 30.0.7; 31.0.0 is current.

CVE-2026-16539: SM Page Duplicator, seven years untouched, no fix

SM Page Duplicator copies pages. In 1.0.0 and earlier β€” all versions β€” a stored value is placed directly into a SQL statement during duplication, letting an editor-level account reach the database. WPScan rates it 6.8; there is no fix.

WordPress.org closed it on June 21, 2026, and the last update was seven years ago β€” the version number never moved past 1.0.0. The install count is hidden by the closure, but nothing is coming. Remove it.

Seven with no fix, six pulled from distribution

Seven of the 27 have no fix: LogMyTrip, Super Store Finder, SoftMarket, Webinfos, Personal QR Message, Insert or Embed Articulate Content, and SM Page Duplicator. All but Super Store Finder have also been pulled from WordPress.org.

Line up the closure dates and a pattern appears. SM Page Duplicator on June 21, SoftMarket on July 6, Webinfos and Personal QR Message and Insert or Embed Articulate Content on July 21, LogMyTrip on July 23. Every one of them was pulled days before WPScan published. The notice is identical each time β€” "temporary, pending a full review." In other words, on receiving a report, WordPress.org is removing plugins whose developers have gone quiet or whose fixes look unlikely, ahead of disclosure.

That helps, but only so far. Closure stops new downloads only. Nothing happens to sites that already have the plugin: no dashboard notice, no further updates, and it keeps running. The last-updated dates for these six are, in order, seven years, unknown, ten years, four years, twelve months, and eleven years ago. Whether you are carrying one of these is something only you can find out.

The check is simple: open the plugin list in your WordPress dashboard and click each plugin's name. Closed plugins fail to return their details. Our OSS supply chain scanner covers how to surface this class of abandoned component more broadly, including outside WordPress.

What to do today

None of the 27 carry an NVD severity score. Scores can take days or weeks to appear, so waiting for one accomplishes nothing.

Start by comparing the table above against your plugin list. No matches, and you are done. If there are matches, the 11 no-login issues come first. If you run Simple Membership, update to 4.7.8 or later today β€” the administrator account is takeable from outside and there is nothing to gain by waiting. Link Library needs 7.9.3 or later; Blog Floating Button needs 1.4.21 or later.

For the seven with no fix, the options are deletion or disabling the affected feature. For the six that have been pulled from distribution, waiting for a patch is not a reasonable plan β€” last updates of ten and eleven years ago mean the developer left long before this.

Then check whether anyone already got in. Look for administrator accounts you do not recognise, confirm the administrator email address is still yours, and check for .php files sitting under wp-content/uploads. An update prevents the next intrusion; it does not remove a back door already in place. That is the same lesson as the Cisco phone platform case, where patching left previously planted web shells untouched.

As of August 3, none of the 27 appear in CISA's catalog of vulnerabilities confirmed to be under attack. No public evidence of exploitation exists yet. "Yet" is doing real work in that sentence: once the location of a hole is published, the automated sweeps do not take long to arrive.

Sources

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django