If you received an email from me pointing you to one of the pages below, it is because a public version manifest on your website indicates an out-of-date or vulnerable component. Each notice explains why it matters and how to fix it. These are good-faith, responsible-disclosure notices: I am not asking for money, passwords, or access to your site.

18 site operators have written back to confirm that a notice from this project helped them fix a vulnerable component on their site.

  • Link Library Security Notice

    link-library | CVE-2026-16532 (unauthenticated SQL injection in link submission handling)

    Guidance for WordPress site operators contacted about a version of the Link Library plugin (link-library) affected by CVE-2026-16532, including why the issue is reachable regardless of how the plugin is configured, how to check your version reliably, and how to upgrade safely.

  • Blog Floating Button Security Notice

    blog-floating-button | CVE-2026-15383 (unauthenticated stored cross-site scripting in the admin report screen)

    Guidance for WordPress site operators contacted about a version of the Blog Floating Button plugin (blog-floating-button) affected by CVE-2026-15383, including what the issue actually reaches, how to check your version reliably, and how to upgrade safely.

  • Simple Membership Security Notice

    simple-membership | CVE-2026-15930 (unauthenticated administrator account takeover)

    Guidance for WordPress site operators contacted about a version of the Simple Membership plugin (simple-membership) affected by CVE-2026-15930, including how to check your version reliably, how to upgrade safely, and why the usual check for unfamiliar new administrator accounts would miss this one.

  • SMS Alert Security Notice

    sms-alert | CVE-2026-11387 (unauthenticated account takeover, CVSS 9.8)

    Guidance for WordPress and WooCommerce site operators contacted about a version of the SMS Alert plugin (sms-alert) affected by CVE-2026-11387, including how to check whether your OTP configuration is exposed at all, how to check your version reliably, and how to upgrade safely.

  • ARVE Security Notice

    advanced-responsive-video-embedder | CVE-2026-18072 (backdoored release, plugin closed)

    Guidance for WordPress site operators contacted about a backdoored release of the Advanced Responsive Video Embedder (ARVE) plugin, CVE-2026-18072, including why updating does not help, which release is clean, and what to check afterwards.

  • Bookly Security Notice

    bookly-responsive-appointment-booking-tool | CVE-2026-13395 (unauthenticated SQL injection)

    Guidance for WordPress site operators contacted about an affected version of the Bookly appointment-booking plugin (bookly-responsive-appointment-booking-tool), CVE-2026-13395, including how to check your version, upgrade safely, and why resetting administrator passwords afterwards is worth doing.

  • Realtyna WPL Security Notice

    real-estate-listing-realtyna-wpl | CVE-2026-13714 (unauthenticated arbitrary file upload)

    Guidance for WordPress site operators contacted about a vulnerable version of the Realtyna Organic IDX plugin + WPL Real Estate plugin (real-estate-listing-realtyna-wpl), CVE-2026-13714, including how to check your version, upgrade safely, and check for signs of unauthorized file uploads.

  • ProfilePress Security Notice

    wp-user-avatar (ProfilePress) | CVE-2026-12497 (unauthenticated privilege escalation)

    Guidance for WordPress site operators contacted about a version of the ProfilePress plugin (wp-user-avatar) affected by CVE-2026-12497, including how to check whether your registration configuration is exposed at all, how to check your version, and how to upgrade safely.

  • Events Manager Security Notice

    events-manager | CVE-2026-12987 (Patchstack CVSS 8.8)

    Guidance for WordPress site operators contacted about a version of the Events Manager plugin (events-manager) affected by CVE-2026-12987, including how to check whether your booking configuration is exposed at all, how to check your version, and how to upgrade safely.

  • Wallet System for WooCommerce Security Notice

    wallet-system-for-woocommerce | CVE-2026-42654 (CVSS 7.1)

    Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Wallet System for WooCommerce plugin (wallet-system-for-woocommerce), CVE-2026-42654, including how to check your version and upgrade safely.

  • Premium Packages (WordPress Download Manager) Security Notice

    wpdm-premium-packages | CVE-2026-15348 (unauthenticated authentication bypass)

    Guidance for WordPress site operators contacted about a vulnerable version of the Premium Packages plugin (wpdm-premium-packages), a WordPress Download Manager add-on, CVE-2026-15348, including how to check your version and upgrade safely.

  • JCE Security Notice

    Joomla Content Editor | CVE-2026-48907 (CVSS 10.0)

    Guidance for operators running an out-of-date Joomla Content Editor (JCE) plugin, including how to check your version and upgrade safely.

  • End-of-Life Joomla Notice

    Joomla core | Unsupported release

    Guidance for operators running an end-of-life Joomla installation (3.x or earlier), including how to check your version and upgrade to a supported release.

  • SP Page Builder Security Notice

    com_sppagebuilder | CVE-2026-48908 (CVSS 10.0)

    Guidance for operators running a vulnerable version of the SP Page Builder extension, including how to check your version, upgrade, and check for compromise.

  • FunnelKit (Funnel Builder) Security Notice

    Funnel Builder by FunnelKit | CVE-2026-47100 (CVSS 8.7)

    Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Funnel Builder by FunnelKit plugin (funnel-builder), CVE-2026-47100, including how to check your version, upgrade, and check your checkout for injected payment-skimming code.

  • Page Builder CK Security Notice

    com_pagebuilderck | CVE-2026-56290 (CVSS 10.0)

    Guidance for Joomla site operators contacted about a vulnerable version of the Page Builder CK (com_pagebuilderck) extension, CVE-2026-56290, including how to check your version, upgrade to the fixed release for your Joomla line, and check for compromise.

  • Kirki Security Notice

    kirki | CVE-2026-8206 (CVSS 9.8)

    Guidance for WordPress site operators contacted about a vulnerable version of the Kirki page builder plugin (kirki), CVE-2026-8206, including how to check your version, upgrade, and check for signs of unauthorized account access.

  • Burst Statistics Security Notice

    burst-statistics | CVE-2026-8181 (CVSS 9.8)

    Guidance for WordPress site operators contacted about a vulnerable version of the Burst Statistics plugin (burst-statistics), CVE-2026-8181, including how to check your version, upgrade, and check for signs of unauthorized administrator access.