Skip to content
Easy Form Builder by WhiteStudio
- Affected versions: 4.0.11 and earlier
- CVE / severity: CVE-2026-13439 — Critical, CVSS 9.8
- Issue: Unauthenticated privilege escalation. An attacker can reset any user’s password, including an administrator’s, and take control of the site.
- Exploit status: No active exploitation is identified in the cited Wordfence record.
- Patched version: 4.0.12
- Mitigation: Update immediately. Disable the plugin until it can be updated if necessary. (Wordfence)
MapSVG
- Affected versions: 8.14.0 and earlier
- CVE / severity: CVE-2026-1771 — High, CVSS 7.2
- Issue: Administrator-level arbitrary file upload, potentially resulting in remote code execution.
- Exploit status: Requires an authenticated administrator account. No active exploitation is identified in the cited record.
- Patched version: 8.14.1
- Mitigation: Update to 8.14.1 or later. (Wordfence)
Essential Addons for Elementor — Fancy Text Widget
- Affected versions: 6.6.11 and earlier
- CVE / severity: CVE-2026-15145 — Medium, CVSS 6.4
- Issue: Stored cross-site scripting.
- Exploit status: Requires a Contributor-level or higher account. No active exploitation is identified in the cited record.
- Patched version: 6.7.0
- Mitigation: Update to 6.7.0 or later. (Wordfence)
Essential Addons for Elementor — Reading Progress settings
- Affected versions: 6.6.11 and earlier
- CVE / severity: CVE-2026-15156 — Medium, CVSS 6.4
- Issue: Stored cross-site scripting through Reading Progress global color settings.
- Exploit status: Requires a Contributor-level or higher account. No active exploitation is identified in the cited record.
- Patched version: 6.7.0
- Mitigation: Update to 6.7.0 or later. (Wordfence)
WPForms
- Affected versions: 2.0.0.1 and earlier
- CVE / severity: CVE-2026-15782 — Medium, CVSS 4.9
- Issue: Stored cross-site scripting through the OptinMonster integration.
- Exploit status: Requires a Contributor-level or higher account, plus an active OptinMonster inline campaign on the affected page. No active exploitation is identified in the cited record.
- Patched version: 2.0.0.2
- Mitigation: Update to 2.0.0.2 or later. (Wordfence)
Tutor LMS Elementor Addons
- Affected versions: 4.0.0 and earlier
- CVE / severity: CVE-2026-1372 — Medium, CVSS 4.3
- Issue: Subscriber-level users can activate Tutor LMS and Elementor plugins without authorization.
- Exploit status: Requires an authenticated Subscriber-level or higher account. No active exploitation is identified in the cited record.
- Patch: No patch is currently available
- Mitigation: Remove or disable the plugin until a patched release is available. (Wordfence)