[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn556sZUgcev5fiEoIsHaPZg9VfVJwuaJNsPn3zFSO88":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"6eee9838-7483-4e84-bcee-caadc12eeb97","Vulnerability & Patch Roundup — August 2026","vulnerability-patch-roundup-august-2026-75b282","If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed. To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem. Continue reading Vulnerability & Patch Roundup — August 2026 at Sucuri Blog.","Sucuri's August 2026 roundup details several critical vulnerabilities affecting popular WordPress plugins. These include unauthenticated stored XSS and SQL injection leading to RCE in LiteSpeed Cache and All-in-One WP Migration, as well as privilege escalation and RCE in Essential Addons, WP Fastest Cache, and ElementsKit. Sucuri recommends immediate updates to patched versions to mitigate these risks.","WordPress plugins LiteSpeed Cache, All-in-One WP Migration, Essential Addons, WP Fastest Cache, and ElementsKit have","If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.PluginsLiteSpeed Cache – Unauthenticated Stored Cross-Site Scripting via Comment ContentSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comment Content CVE: CVE-2026-18978 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.8.1 Patched Versions: 7.9Mitigation steps: Update to LiteSpeed Cache version 7.9 or greater.LiteSpeed Cache – Authenticated (Author+) Stored Cross-Site Scripting via img Tag AttributesSecurity Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes CVE: CVE-2026-3129 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.7 Patched Versions: 7.8Mitigation steps: Update to LiteSpeed Cache version 7.8 or greater.All-in-One WP Migration and Backup – Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code ExecutionSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution CVE: CVE-2026-19949 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.109 Patched Versions: 7.110Mitigation steps: Update to All-in-One WP Migration and Backup version 7.110 or greater.All-in-One WP Migration and Backup – Authenticated (Administrator+) Remote Code ExecutionSecurity Risk: High Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Administrator+) Remote Code Execution CVE: CVE-2026-17533 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup \u003C 7.108 Patched Versions: 7.108Mitigation steps: Update to All-in-One WP Migration and Backup version 7.108 or greater.Essential Addons for Elementor – Unauthenticated Privilege EscalationSecurity Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Privilege Escalation CVE: CVE-2026-18039 Number of Installations: 1,000,000+ Affected Software: Essential Addons for Elementor ≤ 6.7.1 Patched Versions: 6.7.2Mitigation steps: Update to Essential Addons for Elementor version 6.7.2 or greater.WP Fastest Cache – Unauthenticated Stored Cross-Site Scripting via HTTP Host HeaderSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via HTTP Host Header CVE: CVE-2026-19760 Number of Installations: 1,000,000+ Affected Software: WP Fastest Cache ≤ 1.5.0 Patched Versions: 1.5.1Mitigation steps: Update to WP Fastest Cache version 1.5.1 or greater.ElementsKit Elementor Addons – Authenticated (Admin+) Remote Code ExecutionSecurity Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Remote Code Execution CVE: CVE-2026-13392 Number of Installations: 1,000,000+ Affected Software: ElementsKit Elementor Addons \u003C 3.10.01 Patched Versions: 3.10.01Mitigation steps: Update to ElementsKit Elementor Addons version 3.10.01 or greater.MC4WP: Mailchimp for WordPress – Authenticated (Author+) Stored Cross-Site Scripting via Form Response MessagesSecurity Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Stored Cross-Site Scripting via Form Response Messages CVE: CVE-2026-4561 Number of Installations: 1,000,000+ Affected Software: MC4WP: Mailchimp for WordPress ≤ 4.12.0 Patched Versions: 4.12.1Mitigation steps: Update to MC4WP: Mailchimp for WordPress version 4.12.1 or greater.EWWW Image Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘data-script’ Lazy Load Attribute in Post ContentSecurity Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content CVE: CVE-2026-15446 Number of Installations: 1,000,000+ Affected Software: EWWW Image Optimizer ≤ 8.7.3 Patched Versions: 8.7.4Mitigation steps: Update to EWWW Image Optimizer version 8.7.4 or greater.Speed Optimizer – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag AttributesSecurity Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes CVE: CVE-2026-15421 Number of Installations: 1,000,000+ Affected Software: Speed Optimizer ≤ 7.8.0 Patched Versions: 7.8.1Mitigation steps: Update to Speed Optimizer version 7.8.1 or greater.Loco Translate – Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted CommentsSecurity Risk: High Exploitation Level: Requires Translator or higher level authentication. Vulnerability: Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments CVE: CVE-2026-15066 Number of Installations: 1,000,000+ Affected Software: Loco Translate ≤ 2.8.7 Patched Versions: 2.8.8Mitigation steps: Update to Loco Translate version 2.8.8 or greater.AI Agent by SiteGround – Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via \u002Fgenerate-content REST EndpointSecurity Risk: Medium Exploitation Level: Requires Contributor or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via \u002Fgenerate-content REST Endpoint CVE: CVE-2026-17153 Number of Installations: 1,000,000+ Affected Software: AI Agent by SiteGround ≤ 1.2.7 Patched Versions: 1.2.8Mitigation steps: Update to AI Agent by SiteGround version 1.2.8 or greater.Smash Balloon Social Photo Feed – Reflected Cross-Site Scripting via REQUEST_URI Query StringSecurity Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via REQUEST_URI Query String CVE: CVE-2026-15452 Number of Installations: 1,000,000+ Affected Software: Smash Balloon Social Photo Feed ≤ 6.11.3 Patched Versions: 6.11.4Mitigation steps: Update to Smash Balloon Social Photo Feed version 6.11.4 or greater.W3 Total Cache – Unauthenticated Path TraversalSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Path Traversal CVE: CVE-2026-18051 Number of Installations: 900,000+ Affected Software: W3 Total Cache \u003C 2.10.5 Patched Versions: 2.10.5Mitigation steps: Update to W3 Total Cache version 2.10.5 or greater.WPvivid – Unauthenticated Path TraversalSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Path Traversal CVE: CVE-2026-19725 Number of Installations: 900,000+ Affected Software: WPvivid \u003C 0.9.131 Patched Versions: 0.9.131Mitigation steps: Update to WPvivid version 0.9.131 or greater.W3 Total Cache – Unauthenticated Stored Cross-Site Scripting via Comment Author NameSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting via Comm","https:\u002F\u002Fblog.sucuri.net\u002F2026\u002F08\u002Fvulnerability-patch-roundup-august-2026.html","https:\u002F\u002Fblog.sucuri.net\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002FVulnerability-Round-up-August-2026.png","2026-09-01T00:00:18+00:00","2026-09-01T04:00:22.631697+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"LiteSpeed Cache","product",{"name":22,"type":20},"All-in-One WP Migration and Backup",{"name":24,"type":20},"Essential Addons for Elementor",{"name":26,"type":20},"WP Fastest Cache",{"name":28,"type":20},"ElementsKit Elementor Addons",{"name":30,"type":31},"Sucuri","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,40],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",[46,50,53,56,59,62,65],{"type":47,"value":48,"context":49},"cve","CVE-2026-18978","LiteSpeed Cache - Unauthenticated Stored Cross-Site Scripting via Comment Content",{"type":47,"value":51,"context":52},"CVE-2026-3129","LiteSpeed Cache - Authenticated Stored Cross-Site Scripting via img Tag Attributes",{"type":47,"value":54,"context":55},"CVE-2026-19949","All-in-One WP Migration and Backup - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution",{"type":47,"value":57,"context":58},"CVE-2026-17533","All-in-One WP Migration and Backup - Authenticated Remote Code Execution",{"type":47,"value":60,"context":61},"CVE-2026-18039","Essential Addons for Elementor - Unauthenticated Privilege Escalation",{"type":47,"value":63,"context":64},"CVE-2026-19760","WP Fastest Cache - Unauthenticated Stored Cross-Site Scripting via HTTP Host Header",{"type":47,"value":66,"context":67},"CVE-2026-13392","ElementsKit Elementor Addons - Authenticated Remote Code Execution"]