Back to advisories

Vulnerability & Patch Roundup — August 2026

Multiple critical RCE and privilege escalation vulnerabilities identified in popular WordPress plugins: LiteSpeed Cache, All-in-One WP Migration, Essential Addons, WP Fastest Cache, and ElementsKit. Unauthenticated attackers can exploit stored XSS and SQL injection to achieve remote code execution. Any unpatched WordPress instance running these plugins is at immediate risk.

CRITICALAdvisorySep 01, 2026
Action required
Identify all WordPress instances using affected plugins. Prioritize patching LiteSpeed Cache and All-in-One WP Migration to latest versions immediately. Scan for active exploitation indicators and review recent plugin activity logs for suspicious behavior.
Affected products
LiteSpeed CacheAll-in-One WP Migration and BackupEssential Addons for ElementorWP Fastest CacheElementsKit Elementor Addons