The Week in Security
WordPress had 23 vulnerabilities this week including Eventer plugin for WordPress SQL injection (CVSS 9.8). Other had 76 vulnerabilities this week including mem0's openmemory/api component unauthenticated Vulnerability (CVSS 9.8). Kubernetes got hit with a CVSS 9.8 for MCP Server Kubernetes before Vulnerability.
We tracked 100 vulnerabilities this week. 21 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.
WordPress Had a Rough Week
23 vulnerabilities across WordPress products this week. The worst: CVE-2026-9701 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run WordPress.
- CVE-2026-9701: Eventer plugin for WordPress SQL injection (CVSS 9.8)
- CVE-2026-15282: Instant Appointment plugin for Remote code execution (CVSS 9.8)
- CVE-2026-12153: WP Learn Manager plugin Authorization bypass (CVSS 9.8)
- CVE-2026-15300: GEO my WP plugin SQL injection (CVSS 9.1)
- CVE-2026-2354: Swiss Toolkit For WP Remote code execution (CVSS 8.8)
- CVE-2026-15155: Essential Addons for Elementor Vulnerability (CVSS 8.8)
- CVE-2026-14495: DoLogin Security plugin for Authentication bypass (CVSS 8.8)
- CVE-2026-14489: WHMCS Bridge plugin for Remote code execution (CVSS 8.8)
- CVE-2026-14482: 多说社会化评论框 plugin for WordPress Privilege (CVSS 8.8)
- CVE-2026-13756: WP Grid Builder plugin Privilege escalation (CVSS 8.8)
- CVE-2026-13353: WP Ultimate CSV Importer Remote code execution (CVSS 8.8)
- CVE-2025-6784: Code Engine plugin for Remote code execution (CVSS 8.8)
- CVE-2026-7655: SureCart plugin for WordPress Privilege escalation (CVSS 8.1)
- CVE-2026-12598: LoginPress Pro plugin for Authentication bypass (CVSS 8.1)
- CVE-2026-12597: LoginPress Pro plugin for Authentication bypass (CVSS 8.1)
- CVE-2026-12595: LoginPress Pro plugin for Authentication bypass (CVSS 8.1)
- CVE-2026-15293: WP Business Intelligence Lite Privilege escalation (CVSS 8.0)
- CVE-2026-9700: Eventer plugin for WordPress SQL injection (CVSS 7.5)
- CVE-2026-4661: WP CTA - Sticky SQL injection (CVSS 7.5)
- CVE-2026-15335: Booking Package plugin for SQL injection (CVSS 7.5)
- CVE-2026-13347: Hide My WP Lite Directory traversal (CVSS 7.5)
- CVE-2026-6939: CorvusPay WooCommerce Payment Gateway Cross-site scripting (CVSS 7.2)
- CVE-2026-15298: TelSender plugin for WordPress Cross-site scripting (CVSS 7.2)
Other Had a Rough Week
76 vulnerabilities across Other products this week. The worst: CVE-2026-59705 (CVSS 9.8) lets anyone bypass authentication. Patch now if you run Other.
- CVE-2026-59705: mem0's openmemory/api component unauthenticated Vulnerability (CVSS 9.8)
- CVE-2026-58480: Blocksy Companion Pro plugin Remote code execution (CVSS 9.8)
- CVE-2026-58123: Hermes WebUI before 0.51.788 Remote code execution (CVSS 9.8)
- CVE-2026-14894: Super Forms - Drag Remote code execution (CVSS 9.8)
- CVE-2026-14808: Prog Vulnerability (CVSS 9.8)
- CVE-2026-14807: ERP App developed by Vulnerability (CVSS 9.8)
- CVE-2026-14345: WPFunnels - Funnel Builder Remote code execution (CVSS 9.8)
- CVE-2026-14245: miniOrange OTP Login, Verification Authentication bypass (CVSS 9.8)
- CVE-2026-12761: miniOrange Social Login and Authentication bypass (CVSS 9.8)
- CVE-2026-59792: jetbrains intellij idea Directory traversal (CVSS 9.6)
- CVE-2026-59706: mem0 contains unauthenticated config SSRF (CVSS 9.3)
- CVE-2026-47646: Improper neutralization of input Cross-site scripting (CVSS 9.3)
- CVE-2026-15378: A flaw was found SSRF (CVSS 9.3)
- CVE-2026-58473: Cognee before 1.2.0 improper Authorization bypass (CVSS 9.1)
- CVE-2026-58122: Hermes WebUI before 0.51.307 Authentication bypass (CVSS 9.1)
- CVE-2026-14487: Simple Coherent Form plugin Remote code execution (CVSS 9.1)
- CVE-2026-59257: n8n n8n SQL injection (CVSS 8.8)
- CVE-2026-58143: Cotonti Siena 0.9.26 and Vulnerability (CVSS 8.8)
- CVE-2026-5523: Divi Form Builder plugin Vulnerability (CVSS 8.8)
- CVE-2026-15070: Salon Booking System - Remote code execution (CVSS 8.8)
- CVE-2026-14262: Simple JWT Login - Privilege escalation (CVSS 8.8)
- CVE-2026-14158: Widget Logic Visual plugin Remote code execution (CVSS 8.8)
- CVE-2026-1359: Genolve - AI image Privilege escalation (CVSS 8.8)
- CVE-2025-30007: HestiaCP before 1.9.5 authenticated Remote code execution (CVSS 8.8)
- CVE-2026-60104: Bitwarden Server before 2026.6.0 Vulnerability (CVSS 8.7)
- CVE-2026-60105: Monsta FTP before 2.14.5 Vulnerability (CVSS 8.6)
- CVE-2026-59707: LocalAI unauthenticated server-side request Vulnerability (CVSS 8.6)
- CVE-2026-54329: snipeitapp snipe-it Vulnerability (CVSS 8.5)
- CVE-2026-57850: RustDesk before 1.4.9 does Vulnerability (CVSS 8.3)
- CVE-2026-56305: Capgo before 12.128.2 Authentication bypass (CVSS 8.3)
- CVE-2026-8377: Missing Authorization vulnerability in Authorization bypass (CVSS 8.2)
- CVE-2026-59802: PasswordPusher before 2.8.1 accepts Vulnerability (CVSS 8.2)
- CVE-2026-58525: Improper access control in Authorization bypass (CVSS 8.2)
- CVE-2026-29009: U-Boot through 2026.04-rc3 Buffer overflow (CVSS 8.2)
- CVE-2026-59712: Leantime's Users::getUser method in Vulnerability (CVSS 8.1)
- CVE-2026-22659: FlaskBB through 2.2.0, fixed Authorization bypass (CVSS 8.1)
- CVE-2026-61437: PraisonAI (pip package praisonaiagents) Vulnerability (CVSS 7.8)
- CVE-2026-58459: gpsd through release-3.27.5, fixed Command injection (CVSS 7.8)
- CVE-2026-9165: A flaw was found Denial of service (CVSS 7.7)
- CVE-2026-9842: Backstage - Customizer Demo Privilege escalation (CVSS 7.5)
- CVE-2026-9282: W3 Total Cache plugin Directory traversal (CVSS 7.5)
- CVE-2026-59803: rpcx through 1.9.3, fixed Vulnerability (CVSS 7.5)
- CVE-2026-59708: GET /api/v1/public/:accessId/portfolio endpoint in Vulnerability (CVSS 7.5)
- CVE-2026-5799: Authorization bypass through User-Controlled CVSS 7.5 (CVSS 7.5)
- CVE-2026-5730: Authorization bypass through User-Controlled CVSS 7.5 (CVSS 7.5)
- CVE-2026-57026: An Improper Validation of Denial of service (CVSS 7.5)
- CVE-2026-57023: An Improper Validation of Denial of service (CVSS 7.5)
- CVE-2026-15338: LA-Studio Element Kit for Directory traversal (CVSS 7.5)
- CVE-2026-15291: Chat Help - Click Vulnerability (CVSS 7.5)
- CVE-2026-15290: Ultimate Member - User SQL injection (CVSS 7.5)
- CVE-2026-15288: SureForms - Drag and Vulnerability (CVSS 7.5)
- CVE-2026-15271: A security vulnerability has CVSS 7.5 (CVSS 7.5)
- CVE-2026-15270: A weakness has been Vulnerability (CVSS 7.5)
- CVE-2026-14809: Prog Management System developed SQL injection (CVSS 7.5)
- CVE-2026-14244: Jssor Slider by jssor.com Directory traversal (CVSS 7.5)
- CVE-2026-59806: Gradio before 6.20.0 open SSRF (CVSS 7.4)
- CVE-2026-56776: n8n n8n Authorization bypass (CVSS 7.4)
- CVE-2026-58384: A flaw was found Remote code execution (CVSS 7.3)
- CVE-2026-57028: An Improper Restriction of Vulnerability (CVSS 7.3)
- CVE-2026-15330: zhayujie CowAgent up to Vulnerability (CVSS 7.3)
- CVE-2026-15319: A security vulnerability has Authorization bypass (CVSS 7.3)
- CVE-2026-15137: A weakness has been SQL injection (CVSS 7.3)
- CVE-2026-15135: code-projects Online Food Order SQL injection (CVSS 7.3)
- CVE-2026-15134: CodeAstro Simple Online Leave SQL injection (CVSS 7.3)
- CVE-2026-14802: react create-react-app up to Command injection (CVSS 7.3)
- CVE-2026-14778: A security vulnerability has Authorization bypass (CVSS 7.3)
- CVE-2026-8848: Popup Maker - Boost Remote code execution (CVSS 7.2)
- CVE-2026-3576: Planyo Online Reservation System Vulnerability (CVSS 7.2)
- CVE-2026-15000: Connect Contact Form 7 Cross-site scripting (CVSS 7.2)
- CVE-2026-13430: Post Export Import with Remote code execution (CVSS 7.2)
- CVE-2026-13378: Form Vibes - Database Cross-site scripting (CVSS 7.2)
- CVE-2026-13114: Motors - Car Dealership Cross-site scripting (CVSS 7.2)
- CVE-2026-59704: Cap's GET /api/video/ai endpoint Vulnerability (CVSS 7.1)
- CVE-2026-59206: n8n n8n Vulnerability (CVSS 7.1)
- CVE-2026-39903: Simple Machines Forum 2.1 Authorization bypass (CVSS 7.1)
- CVE-2026-21383: Cryptographic Issue when using Vulnerability (CVSS 7.1)
Kubernetes Hit With CVSS 9.8
CVE-2026-61459 scores a 9.8. Kubernetes lets attackers run code on your systems.
- CVE-2026-61459: MCP Server Kubernetes before Vulnerability (CVSS 9.8)
By the Numbers
| Total CVEs analyzed | 100 |
| Critical (9.0+) | 21 |
| High (7.0-8.9) | 79 |
| Remote code execution | 74 |
| Authentication bypass | 21 |
| Cross-site scripting | 0 |
| SQL injection | 0 |
What To Do This Week
One action item per vendor. Start at the top and work down.
- WordPress: Update immediately. 4 critical-severity issues patched this week.
- Other: Update immediately. 16 critical-severity issues patched this week.
- Kubernetes: Update immediately. 1 critical-severity issues patched this week.