If you received an email from me pointing you to one of the pages below, it is because a public version manifest on your website indicates an out-of-date or vulnerable component. Each notice explains why it matters and how to fix it. These are good-faith, responsible-disclosure notices: I am not asking for money, passwords, or access to your site.

20 site operators have written back to confirm that a notice from this project helped them fix a vulnerable component on their site.

  • iCagenda Security Notice

    com_icagenda (JoomliC) | CVE-2026-48939 (unauthenticated arbitrary file upload leading to remote code execution, CVSS 9.8, CISA KEV)

    Guidance for Joomla site operators contacted about a version of the iCagenda (com_icagenda) extension affected by CVE-2026-48939, including the two conditions that together make a site affected, why this page disagrees with the vendor's advisory about which Joomla versions are exposed, how to read both version numbers, and how to check for compromise.

  • Balbooa Forms Security Notice

    com_baforms (Balbooa) | CVE-2026-56291 (unauthenticated arbitrary file upload leading to remote code execution, CVSS 10.0, CISA KEV)

    Guidance for Joomla site operators contacted about a version of the Balbooa Forms (com_baforms) extension affected by CVE-2026-56291, including why the version to update to is not the version that fixes this issue, why no older release is safe, how to read your version without being misled by the number in your page source, and how to check for compromise.

  • Content Views Security Notice

    content-views-query-and-display-post-page (Content Views / PT Guy) | CVE-2026-15361 (SQL injection reachable by any logged-in user, Subscriber included)

    Guidance for WordPress site operators contacted about a version of the Content Views – Post Grid & Filter plugin (content-views-query-and-display-post-page) affected by CVE-2026-15361, including why the deciding question is who can get an account on your site rather than any setting, how to read your version without being misled by the plugin's bundled libraries, and how to upgrade safely.

  • Profile Builder Security Notice

    profile-builder (Cozmoslabs) | CVE-2026-15368 (unauthenticated account takeover via automatic login after registration)

    Guidance for WordPress site operators contacted about a version of the Profile Builder plugin (profile-builder, by Cozmoslabs) affected by CVE-2026-15368, including how to check whether the Automatically Log In setting exposes your site at all, how to read your version without being misled by the plugin's bundled add-ons, and how to upgrade safely.

  • Link Library Security Notice

    link-library | CVE-2026-16532 (unauthenticated SQL injection in link submission handling)

    Guidance for WordPress site operators contacted about a version of the Link Library plugin (link-library) affected by CVE-2026-16532, including why the issue is reachable regardless of how the plugin is configured, how to check your version reliably, and how to upgrade safely.

  • Blog Floating Button Security Notice

    blog-floating-button | CVE-2026-15383 (unauthenticated stored cross-site scripting in the admin report screen)

    Guidance for WordPress site operators contacted about a version of the Blog Floating Button plugin (blog-floating-button) affected by CVE-2026-15383, including what the issue actually reaches, how to check your version reliably, and how to upgrade safely.

  • Simple Membership Security Notice

    simple-membership | CVE-2026-15930 (unauthenticated administrator account takeover)

    Guidance for WordPress site operators contacted about a version of the Simple Membership plugin (simple-membership) affected by CVE-2026-15930, including how to check your version reliably, how to upgrade safely, and why the usual check for unfamiliar new administrator accounts would miss this one.

  • SMS Alert Security Notice

    sms-alert | CVE-2026-11387 (unauthenticated account takeover, CVSS 9.8)

    Guidance for WordPress and WooCommerce site operators contacted about a version of the SMS Alert plugin (sms-alert) affected by CVE-2026-11387, including how to check whether your OTP configuration is exposed at all, how to check your version reliably, and how to upgrade safely.

  • ARVE Security Notice

    advanced-responsive-video-embedder | CVE-2026-18072 (backdoored release, plugin closed)

    Guidance for WordPress site operators contacted about a backdoored release of the Advanced Responsive Video Embedder (ARVE) plugin, CVE-2026-18072, including why updating does not help, which release is clean, and what to check afterwards.

  • Bookly Security Notice

    bookly-responsive-appointment-booking-tool | CVE-2026-13395 (unauthenticated SQL injection)

    Guidance for WordPress site operators contacted about an affected version of the Bookly appointment-booking plugin (bookly-responsive-appointment-booking-tool), CVE-2026-13395, including how to check your version, upgrade safely, and why resetting administrator passwords afterwards is worth doing.

  • Realtyna WPL Security Notice

    real-estate-listing-realtyna-wpl | CVE-2026-13714 (unauthenticated arbitrary file upload)

    Guidance for WordPress site operators contacted about a vulnerable version of the Realtyna Organic IDX plugin + WPL Real Estate plugin (real-estate-listing-realtyna-wpl), CVE-2026-13714, including how to check your version, upgrade safely, and check for signs of unauthorized file uploads.

  • ProfilePress Security Notice

    wp-user-avatar (ProfilePress) | CVE-2026-12497 (unauthenticated privilege escalation)

    Guidance for WordPress site operators contacted about a version of the ProfilePress plugin (wp-user-avatar) affected by CVE-2026-12497, including how to check whether your registration configuration is exposed at all, how to check your version, and how to upgrade safely.

  • Events Manager Security Notice

    events-manager | CVE-2026-12987 (Patchstack CVSS 8.8)

    Guidance for WordPress site operators contacted about a version of the Events Manager plugin (events-manager) affected by CVE-2026-12987, including how to check whether your booking configuration is exposed at all, how to check your version, and how to upgrade safely.

  • Wallet System for WooCommerce Security Notice

    wallet-system-for-woocommerce | CVE-2026-42654 (CVSS 7.1)

    Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Wallet System for WooCommerce plugin (wallet-system-for-woocommerce), CVE-2026-42654, including how to check your version and upgrade safely.

  • Premium Packages (WordPress Download Manager) Security Notice

    wpdm-premium-packages | CVE-2026-15348 (unauthenticated authentication bypass)

    Guidance for WordPress site operators contacted about a vulnerable version of the Premium Packages plugin (wpdm-premium-packages), a WordPress Download Manager add-on, CVE-2026-15348, including how to check your version and upgrade safely.

  • JCE Security Notice

    Joomla Content Editor | CVE-2026-48907 (CVSS 10.0)

    Guidance for operators running an out-of-date Joomla Content Editor (JCE) plugin, including how to check your version and upgrade safely.

  • End-of-Life Joomla Notice

    Joomla core | Unsupported release

    Guidance for operators running an end-of-life Joomla installation (3.x or earlier), including how to check your version and upgrade to a supported release.

  • SP Page Builder Security Notice

    com_sppagebuilder | CVE-2026-48908 (CVSS 10.0)

    Guidance for operators running a vulnerable version of the SP Page Builder extension, including how to check your version, upgrade, and check for compromise.

  • FunnelKit (Funnel Builder) Security Notice

    Funnel Builder by FunnelKit | CVE-2026-47100 (CVSS 8.7)

    Guidance for WordPress/WooCommerce store operators contacted about a vulnerable version of the Funnel Builder by FunnelKit plugin (funnel-builder), CVE-2026-47100, including how to check your version, upgrade, and check your checkout for injected payment-skimming code.

  • Page Builder CK Security Notice

    com_pagebuilderck | CVE-2026-56290 (CVSS 10.0)

    Guidance for Joomla site operators contacted about a vulnerable version of the Page Builder CK (com_pagebuilderck) extension, CVE-2026-56290, including how to check your version, upgrade to the fixed release for your Joomla line, and check for compromise.

  • Kirki Security Notice

    kirki | CVE-2026-8206 (CVSS 9.8)

    Guidance for WordPress site operators contacted about a vulnerable version of the Kirki page builder plugin (kirki), CVE-2026-8206, including how to check your version, upgrade, and check for signs of unauthorized account access.

  • Burst Statistics Security Notice

    burst-statistics | CVE-2026-8181 (CVSS 9.8)

    Guidance for WordPress site operators contacted about a vulnerable version of the Burst Statistics plugin (burst-statistics), CVE-2026-8181, including how to check your version, upgrade, and check for signs of unauthorized administrator access.