For Site Operators
If you received an email from me pointing you to one of the pages below, it is because a public version manifest on your website indicates an out-of-date or vulnerable component. Each notice explains why it matters and how to fix it. These are good-faith, responsible-disclosure notices: I am not asking for money, passwords, or access to your site.
18 site operators have written back to confirm that a notice from this project helped them fix a vulnerable component on their site.
-
Link Library Security Notice
Guidance for WordPress site operators contacted about a version of the Link Library plugin (link-library) affected by CVE-2026-16532, including why the issue is reachable regardless of how the plugin is configured, how to check your version reliably, and how to upgrade safely.
-
Blog Floating Button Security Notice
Guidance for WordPress site operators contacted about a version of the Blog Floating Button plugin (blog-floating-button) affected by CVE-2026-15383, including what the issue actually reaches, how to check your version reliably, and how to upgrade safely.
-
Simple Membership Security Notice
Guidance for WordPress site operators contacted about a version of the Simple Membership plugin (simple-membership) affected by CVE-2026-15930, including how to check your version reliably, how to upgrade safely, and why the usual check for unfamiliar new administrator accounts would miss this one.
-
SMS Alert Security Notice
Guidance for WordPress and WooCommerce site operators contacted about a version of the SMS Alert plugin (sms-alert) affected by CVE-2026-11387, including how to check whether your OTP configuration is exposed at all, how to check your version reliably, and how to upgrade safely.
-
ARVE Security Notice
Guidance for WordPress site operators contacted about a backdoored release of the Advanced Responsive Video Embedder (ARVE) plugin, CVE-2026-18072, including why updating does not help, which release is clean, and what to check afterwards.
-
Bookly Security Notice
Guidance for WordPress site operators contacted about an affected version of the Bookly appointment-booking plugin (bookly-responsive-appointment-booking-tool), CVE-2026-13395, including how to check your version, upgrade safely, and why resetting administrator passwords afterwards is worth doing.
-
Realtyna WPL Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Realtyna Organic IDX plugin + WPL Real Estate plugin (real-estate-listing-realtyna-wpl), CVE-2026-13714, including how to check your version, upgrade safely, and check for signs of unauthorized file uploads.
-
ProfilePress Security Notice
Guidance for WordPress site operators contacted about a version of the ProfilePress plugin (wp-user-avatar) affected by CVE-2026-12497, including how to check whether your registration configuration is exposed at all, how to check your version, and how to upgrade safely.
-
Events Manager Security Notice
Guidance for WordPress site operators contacted about a version of the Events Manager plugin (events-manager) affected by CVE-2026-12987, including how to check whether your booking configuration is exposed at all, how to check your version, and how to upgrade safely.
-
Wallet System for WooCommerce Security Notice
Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Wallet System for WooCommerce plugin (wallet-system-for-woocommerce), CVE-2026-42654, including how to check your version and upgrade safely.
-
Premium Packages (WordPress Download Manager) Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Premium Packages plugin (wpdm-premium-packages), a WordPress Download Manager add-on, CVE-2026-15348, including how to check your version and upgrade safely.
-
JCE Security Notice
Guidance for operators running an out-of-date Joomla Content Editor (JCE) plugin, including how to check your version and upgrade safely.
-
End-of-Life Joomla Notice
Guidance for operators running an end-of-life Joomla installation (3.x or earlier), including how to check your version and upgrade to a supported release.
-
SP Page Builder Security Notice
Guidance for operators running a vulnerable version of the SP Page Builder extension, including how to check your version, upgrade, and check for compromise.
-
FunnelKit (Funnel Builder) Security Notice
Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Funnel Builder by FunnelKit plugin (funnel-builder), CVE-2026-47100, including how to check your version, upgrade, and check your checkout for injected payment-skimming code.
-
Page Builder CK Security Notice
Guidance for Joomla site operators contacted about a vulnerable version of the Page Builder CK (com_pagebuilderck) extension, CVE-2026-56290, including how to check your version, upgrade to the fixed release for your Joomla line, and check for compromise.
-
Kirki Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Kirki page builder plugin (kirki), CVE-2026-8206, including how to check your version, upgrade, and check for signs of unauthorized account access.
-
Burst Statistics Security Notice
Guidance for WordPress site operators contacted about a vulnerable version of the Burst Statistics plugin (burst-statistics), CVE-2026-8181, including how to check your version, upgrade, and check for signs of unauthorized administrator access.