Vulnerability & Patch Roundup — September 2026
September 2026 WordPress vulnerability roundup includes critical flaws in WooCommerce and WPForms.
Summary
This September 2026 roundup details several critical vulnerabilities affecting popular WordPress plugins, including WooCommerce and WPForms. Exploitable flaws like unauthenticated denial-of-service, SQL injection, and cross-site scripting are highlighted, with patches available for versions below 11.1.0 for WooCommerce and 2.0.2.1 for WPForms. Sucuri recommends updating affected plugins immediately or utilizing a web application firewall for protection.
Full text
If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software vulnerabilities, often the same ones that have been previously reported and disclosed.To assist in maintaining your security posture, we have compiled this month’s summary of essential security updates and vulnerability patches pertinent to the WordPress ecosystem.For those already utilizing the Sucuri Firewall, your website is protected, as these vulnerabilities are effectively addressed for all clients. If you do not currently have such protection, it is advisable to deploy a web application firewall to prevent attacks from reaching your environment.PluginsWooCommerce – Unauthenticated Denial of ServiceSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-48888 Number of Installations: 7,000,000+ Affected Software: WooCommerce < 11.1.0 Patched Versions: 11.1.0Mitigation steps: Update to WooCommerce version 11.1.0 or greater.LiteSpeed Cache – Unauthenticated Server-Side Request ForgerySecurity Risk: Low Exploitation Level: No authentication required. Vulnerability: Unauthenticated Server-Side Request Forgery CVE: CVE-2026-84761 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.9 Patched Versions: 7.9.1Mitigation steps: Update to LiteSpeed Cache version 7.9.1 or greater.WooCommerce – Authenticated (Shop Manager+) SQL InjectionSecurity Risk: High Exploitation Level: Requires Shop Manager or higher level authentication. Vulnerability: Authenticated (Shop Manager+) SQL Injection CVE: CVE-2026-57777 Number of Installations: 7,000,000+ Affected Software: WooCommerce ≤ 10.9.4 Patched Versions: 11.0Mitigation steps: Update to WooCommerce version 11.0 or greater.LiteSpeed Cache – Reflected Cross-Site Scripting via ESI ‘esi’ ParameterSecurity Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via ESI 'esi' Parameter CVE: CVE-2026-76579 Number of Installations: 7,000,000+ Affected Software: LiteSpeed Cache ≤ 7.9 Patched Versions: 7.9.1Mitigation steps: Update to LiteSpeed Cache version 7.9.1 or greater.WPForms – Unauthenticated Arbitrary Shortcode ExecutionSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Arbitrary Shortcode Execution CVE: CVE-2026-84744 Number of Installations: 5,000,000+ Affected Software: WPForms 1.5.0.1 - 2.0.2 Patched Versions: 2.0.2.1Mitigation steps: Update to WPForms version 2.0.2.1 or greater.WPForms – Reflected Cross-Site Scripting via ‘page_title’ POST ParameterSecurity Risk: Medium Exploitation Level: No authentication required. Vulnerability: Reflected Cross-Site Scripting via 'page_title' POST Parameter CVE: CVE-2026-88996 Number of Installations: 5,000,000+ Affected Software: WPForms ≤ 2.0.2 Patched Versions: 2.0.2.1Mitigation steps: Update to WPForms version 2.0.2.1 or greater.WPForms – Missing AuthorizationSecurity Risk: Medium Exploitation Level: No authentication required. Vulnerability: Missing Authorization CVE: CVE-2026-74991 Number of Installations: 5,000,000+ Affected Software: WPForms 1.8.8.2 - 2.0.1.1 Patched Versions: 2.0.2Mitigation steps: Update to WPForms version 2.0.2 or greater.All-in-One WP Migration and Backup – Unauthenticated Insufficient Credential Protection via Authorization Basic HeaderSecurity Risk: Medium Exploitation Level: No authentication required. Vulnerability: Unauthenticated Insufficient Credential Protection via Authorization Basic Header CVE: CVE-2026-89064 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.110 Patched Versions: 7.111Mitigation steps: Update to All-in-One WP Migration and Backup version 7.111 or greater.All-in-One WP Migration and Backup – Authenticated (Admin+) Privilege EscalationSecurity Risk: Low Exploitation Level: Requires Administrator or higher level authentication. Vulnerability: Authenticated (Admin+) Privilege Escalation CVE: CVE-2026-81810 Number of Installations: 5,000,000+ Affected Software: All-in-One WP Migration and Backup ≤ 7.110 Patched Versions: 7.111Mitigation steps: Update to All-in-One WP Migration and Backup version 7.111 or greater.Rank Math SEO – Unauthenticated Information ExposureSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Information Exposure CVE: CVE-2026-77783 Number of Installations: 4,000,000+ Affected Software: Rank Math SEO < 1.0.277 Patched Versions: 1.0.277Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.UpdraftPlus: WP Backup & Migration Plugin – Authenticated (Subscriber+) Information ExposureSecurity Risk: High Exploitation Level: Requires Subscriber or higher level authentication. Vulnerability: Authenticated (Subscriber+) Information Exposure CVE: CVE-2026-82841 Number of Installations: 4,000,000+ Affected Software: UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.26.7 Patched Versions: 2.26.8.26Mitigation steps: Update to UpdraftPlus: WP Backup & Migration Plugin version 2.26.8.26 or greater.Rank Math SEO – Missing Authorization to Authenticated (Author+) SEO Object UpdatesSecurity Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Missing Authorization to Authenticated (Author+) SEO Object Updates CVE: CVE-2026-77784 Number of Installations: 4,000,000+ Affected Software: Rank Math SEO < 1.0.277 Patched Versions: 1.0.277Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.Rank Math SEO – Authenticated (Author+) Information ExposureSecurity Risk: Medium Exploitation Level: Requires Author or higher level authentication. Vulnerability: Authenticated (Author+) Information Exposure CVE: CVE-2026-77785 Number of Installations: 4,000,000+ Affected Software: Rank Math SEO < 1.0.277 Patched Versions: 1.0.277Mitigation steps: Update to Rank Math SEO version 1.0.277 or greater.Really Simple Security – Unauthenticated Denial of ServiceSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Denial of Service CVE: CVE-2026-84775 Number of Installations: 3,000,000+ Affected Software: Really Simple Security ≤ 9.8.0 Patched Versions: 9.8.1Mitigation steps: Update to Really Simple Security version 9.8.1 or greater.Jetpack – Unauthenticated Stored Cross-Site ScriptingSecurity Risk: High Exploitation Level: No authentication required. Vulnerability: Unauthenticated Stored Cross-Site Scripting CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 16.1 - 16.1.2 Patched Versions: 16.1.3Mitigation steps: Update to Jetpack version 16.1.3 or greater.Jetpack – Authenticated (Administrator+) PHP Object InjectionSecurity Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) PHP Object Injection CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 12.0 - 12.0.2 Patched Versions: 16.1.3Mitigation steps: Update to Jetpack version 16.1.3 or greater.Jetpack – Authenticated (Administrator+) PHP Object InjectionSecurity Risk: Low Exploitation Level: Requires Administratoristrator or higher level authentication. Vulnerability: Authenticated (Administrator+) PHP Object Injection CVE: Not provided Number of Installations: 3,000,000+ Affected Software: Jetpack 16.1 - 16.1.2 Patched Versions: 16.1.3Mitigation steps: Update to Jetpack version 16.1.3 or greater.Jetpack – Reflected to Stored Cross-Site Scripting via Reader Repost ParametersSecurity Risk: Low Exploitation Level: No authentication required. Vulnerability: Reflected to Stored Cross-Site Scripting via Reader Repost Parameters CVE: Not provided Number of
Indicators of Compromise
- cve — CVE-2026-48888
- cve — CVE-2026-84761
- cve — CVE-2026-57777
- cve — CVE-2026-76579
- cve — CVE-2026-84744
- cve — CVE-2026-88996
- cve — CVE-2026-74991
- cve — CVE-2026-89064