For Site Operators
If you received an email from me pointing you to one of the pages below, it is because a public version manifest on your website indicates an out-of-date or vulnerable component. Each notice explains why it matters and how to fix it. These are good-faith, responsible-disclosure notices: I am not asking for money, passwords, or access to your site.
20 site operators have written back to confirm that a notice from this project helped them fix a vulnerable component on their site.
-
iCagenda Security Notice
Guidance for Joomla site operators contacted about a version of the iCagenda (com_icagenda) extension affected by CVE-2026-48939, including the two conditions that together make a site affected, why this page disagrees with the vendor's advisory about which Joomla versions are exposed, how to read both version numbers, and how to check for compromise.
-
Balbooa Forms Security Notice
Guidance for Joomla site operators contacted about a version of the Balbooa Forms (com_baforms) extension affected by CVE-2026-56291, including why the version to update to is not the version that fixes this issue, why no older release is safe, how to read your version without being misled by the number in your page source, and how to check for compromise.
-
Content Views Security Notice
Guidance for WordPress site operators contacted about a version of the Content Views – Post Grid & Filter plugin (content-views-query-and-display-post-page) affected by CVE-2026-15361, including why the deciding question is who can get an account on your site rather than any setting, how to read your version without being misled by the plugin's bundled libraries, and how to upgrade safely.
-
Profile Builder Security Notice
Guidance for WordPress site operators contacted about a version of the Profile Builder plugin (profile-builder, by Cozmoslabs) affected by CVE-2026-15368, including how to check whether the Automatically Log In setting exposes your site at all, how to read your version without being misled by the plugin's bundled add-ons, and how to upgrade safely.
-
Link Library Security Notice
Guidance for WordPress site operators contacted about a version of the Link Library plugin (link-library) affected by CVE-2026-16532, including why the issue is reachable regardless of how the plugin is configured, how to check your version reliably, and how to upgrade safely.
-
Blog Floating Button Security Notice
Guidance for WordPress site operators contacted about a version of the Blog Floating Button plugin (blog-floating-button) affected by CVE-2026-15383, including what the issue actually reaches, how to check your version reliably, and how to upgrade safely.
-
Simple Membership Security Notice
Guidance for WordPress site operators contacted about a version of the Simple Membership plugin (simple-membership) affected by CVE-2026-15930, including how to check your version reliably, how to upgrade safely, and why the usual check for unfamiliar new administrator accounts would miss this one.
-
SMS Alert Security Notice
Guidance for WordPress and WooCommerce site operators contacted about a version of the SMS Alert plugin (sms-alert) affected by CVE-2026-11387, including how to check whether your OTP configuration is exposed at all, how to check your version reliably, and how to upgrade safely.
-
ARVE Security Notice
Guidance for WordPress site operators contacted about a backdoored release of the Advanced Responsive Video Embedder (ARVE) plugin, CVE-2026-18072, including why updating does not help, which release is clean, and what to check afterwards.
-
Bookly Security Notice
Guidance for WordPress site operators contacted about an affected version of the Bookly appointment-booking plugin (bookly-responsive-appointment-booking-tool), CVE-2026-13395, including how to check your version, upgrade safely, and why resetting administrator passwords afterwards is worth doing.
-
Realtyna WPL Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Realtyna Organic IDX plugin + WPL Real Estate plugin (real-estate-listing-realtyna-wpl), CVE-2026-13714, including how to check your version, upgrade safely, and check for signs of unauthorized file uploads.
-
ProfilePress Security Notice
Guidance for WordPress site operators contacted about a version of the ProfilePress plugin (wp-user-avatar) affected by CVE-2026-12497, including how to check whether your registration configuration is exposed at all, how to check your version, and how to upgrade safely.
-
Events Manager Security Notice
Guidance for WordPress site operators contacted about a version of the Events Manager plugin (events-manager) affected by CVE-2026-12987, including how to check whether your booking configuration is exposed at all, how to check your version, and how to upgrade safely.
-
Wallet System for WooCommerce Security Notice
Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Wallet System for WooCommerce plugin (wallet-system-for-woocommerce), CVE-2026-42654, including how to check your version and upgrade safely.
-
Premium Packages (WordPress Download Manager) Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Premium Packages plugin (wpdm-premium-packages), a WordPress Download Manager add-on, CVE-2026-15348, including how to check your version and upgrade safely.
-
JCE Security Notice
Guidance for operators running an out-of-date Joomla Content Editor (JCE) plugin, including how to check your version and upgrade safely.
-
End-of-Life Joomla Notice
Guidance for operators running an end-of-life Joomla installation (3.x or earlier), including how to check your version and upgrade to a supported release.
-
SP Page Builder Security Notice
Guidance for operators running a vulnerable version of the SP Page Builder extension, including how to check your version, upgrade, and check for compromise.
-
FunnelKit (Funnel Builder) Security Notice
Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Funnel Builder by FunnelKit plugin (funnel-builder), CVE-2026-47100, including how to check your version, upgrade, and check your checkout for injected payment-skimming code.
-
Page Builder CK Security Notice
Guidance for Joomla site operators contacted about a vulnerable version of the Page Builder CK (com_pagebuilderck) extension, CVE-2026-56290, including how to check your version, upgrade to the fixed release for your Joomla line, and check for compromise.
-
Kirki Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Kirki page builder plugin (kirki), CVE-2026-8206, including how to check your version, upgrade, and check for signs of unauthorized account access.
-
Burst Statistics Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Burst Statistics plugin (burst-statistics), CVE-2026-8181, including how to check your version, upgrade, and check for signs of unauthorized administrator access.