| 2026-10-01 |
WPSEC-2026-0006 |
Fluent Forms | Fluent Forms <= 6.2.14 - Unauthenticated Reflected Cross-Site Scripting via 'get' Smartcode |
Medium 6.1 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0005 |
Fluent Forms | Fluent Forms <= 6.2.14 - Authenticated (Fluent Forms Manager+) Stored Cross-Site Scripting via Payment Item 'price_label' and Payment Summary 'cart_empty_text' Settings |
Medium 4.8 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0004 |
Fluent Forms | Fluent Forms <= 6.2.14 - Authenticated (Fluent Forms Manager+) Sensitive Information Exposure via User Search |
Low 2.7 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0003 |
TranslatePress | TranslatePress <= 3.3.6 - Unauthenticated Stored Cross-Site Scripting via trp-gettext Markers in URL Attributes |
High 7.2 |
3.3.7 |
| 2026-10-01 |
WPSEC-2026-0002 |
Wordfence Security – Firewall & Malware Scan | Wordfence Security – Firewall & Malware Scan <= 9.0.1 - Unauthenticated Author Information Disclosure via REST API Username Enumeration Protection Bypass |
Medium 5.3 |
9.0.2 |
| 2026-10-01 |
WPSEC-2026-0001 |
Essential Addons for Elementor – Popular Elementor Templates & Widgets | Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Woo Product Grid Pagination |
Medium 6.4 |
6.8.5 |