13 vulnerabilities across 6 products scored HIGH or above on August 16, 2026.
- π HIGH: 13
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-17083 (ibm/i) β F1: exploitable β functional, AAS: 10.9 β 12.9 (HIGH β CRITICAL). Originally in 2026-08-12 bulletin.
- [UPGRADED] CVE-2026-72886 (dokploy/dokploy) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72882 (dokploy/dokploy) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72901 (dokploy/dokploy) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72737 (dokploy/dokploy) β F1: exploitable β functional, AAS: 9.7 β 11.7 (HIGH β HIGH). Originally in 2026-08-10 bulletin.
π [HIGH] prosolution/prosolution_wp_client
2 CVEs | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:prosolution:prosolution_wp_client:*:*:*:*:*:*:*:*(< 2.0.9)
ProSolution WP Client plugin for WordPress versions up to and including 2.0.10 is affected by 2 vulnerabilities, including at least one critical-severity arbitrary file upload flaw (CVSS 9.8). An unauthenticated attacker can exploit a weakness in the file upload handler, where an attacker-controlled Content-Disposition header filename bypasses the allow-listed multipart filename check, and a post-save extension validation fails to remove the already-written file. This can lead to full site compromise through remote code execution.
WordPress administrators running any version of the ProSolution WP Client plugin should treat this as an urgent priority. Update to a patched version immediately or deactivate the plugin until a fix is available. Review web server logs for unexpected file uploads and inspect the uploads directory for unfamiliar files, particularly those with executable extensions. Consult the vendor advisory for additional remediation details.
- π CVE-2026-16098 (CVSS 3.1: 9.8)
- π CVE-2026-14524 (CVSS 3.1: 9.1)
π [HIGH] shabti/frontend_admin_by_dynamiapps
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:shabti:frontend_admin_by_dynamiapps:*:*:*:*:*:*:*:*(< 3.29.10)
The Frontend Admin by DynamiApps plugin for WordPress, versions up to and including 3.29.9, is affected by 1 critical-severity vulnerability (CVSS 9.8) enabling unauthenticated privilege escalation. The flaw resides in the authorization logic, where a capability check is bypassed entirely when a crafted non-numeric user ID value is supplied, allowing an attacker to escalate privileges or modify arbitrary user accounts without authentication.
All WordPress site operators running the Frontend Admin by DynamiApps plugin should take immediate action. Update to a version beyond 3.29.9 as soon as a patch is available, or deactivate the plugin until then. Review user account records for unauthorized modifications and audit access logs for suspicious requests targeting the plugin’s form handling endpoints.
- π CVE-2026-18432 (CVSS 3.1: 9.8)
π [HIGH] scriban/scriban
7 CVEs | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:scriban:scriban:*:*:*:*:*:*:*:*(< 7.2.2)cpe:2.3:a:scriban:scriban:*:*:*:*:*:*:*:*(>= 6.6.0)
Scriban, the .NET templating engine, versions prior to 7.2.2, is affected by 7 vulnerabilities, including multiple critical-severity flaws (max CVSS 9.3). The issues include an access-modifier bypass in TypedObjectAccessor that allows template code to write to CLR object properties regardless of setter visibility, enabling attackers to modify private, internal, or init-only setters and perform mass assignment that permanently alters live host objects after template rendering.
Development and platform teams using Scriban for server-side template rendering should treat this as a high-priority update. Upgrade to version 7.2.2 or later immediately. Review any deployments where untrusted or user-supplied templates are processed, as these are the most directly exploitable scenarios, and audit application state for unexpected property modifications that may indicate prior exploitation.
- π CVE-2026-73061 (CVSS 4.0: 9.3)
- π CVE-2026-74787 (CVSS 4.0: 8.7)
- π CVE-2026-74783 (CVSS 4.0: 8.7)
- π CVE-2026-74795 (CVSS 4.0: 8.7)
- π CVE-2026-74794 (CVSS 4.0: 8.7)
- π CVE-2026-74792 (CVSS 4.0: 8.7)
- π CVE-2026-74789 (CVSS 4.0: 8.7)
π [HIGH] solacewp/solace_extra
1 CVE | CVSS 3.1: 9.1 | AAS 9.4
cpe:2.3:a:solacewp:solace_extra:*:*:*:*:*:*:*:*(< 1.6.1)
The Solace Extra plugin for WordPress, versions up to and including 1.6.0, is affected by 1 high-severity vulnerability (CVSS 9.1) that allows unauthorized data modification and loss. The flaw exists because the import_zip() function lacks a proper capability check and is exposed to both authenticated and unauthenticated AJAX requests, relying solely on a nonce value that is leaked to all authenticated users, including subscribers, through the admin script localization hook.
WordPress administrators running the Solace Extra plugin should act immediately. Update beyond version 1.6.0 as soon as a patch is available, or deactivate the plugin until then. Audit site content and configuration for unauthorized changes, and review server logs for unexpected requests to the action-import-zip AJAX endpoint.
- π CVE-2026-18316 (CVSS 3.1: 9.1)
π [HIGH] stoatchat/stoatchat
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:stoatchat:stoatchat:*:*:*:*:*:*:*:*(< 0.15.0)
StoatChat versions prior to 0.15.0 are affected by 1 high-severity vulnerability (CVSS 8.7) that enables denial of service through memory exhaustion. The proxy endpoint fails to validate SVG viewBox dimensions, allowing an attacker to host malicious SVG files with extremely large width and height values and trigger concurrent proxy requests to consume all available memory across replicas, potentially taking the service offline.
Teams operating StoatChat instances should upgrade to version 0.15.0 or later as soon as possible. In the interim, consider restricting access to the proxy endpoint or implementing upstream resource limits to mitigate exploitation. Monitor proxy replicas for unusual memory consumption patterns that could indicate active exploitation attempts.
- π CVE-2026-73057 (CVSS 4.0: 8.7)
π [HIGH] wproyal/royal_addons_for_elementor_β_addons_and_templates_kit_for_elementor
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:wproyal:royal_addons_for_elementor_addons_and_templates_kit_for_elementor:*:*:*:*:*:*:*:*(< 1.7.1065)
The Royal Elementor Addons plugin for WordPress, versions up to and including 1.7.1064, is affected by 1 high-severity server-side request forgery vulnerability (CVSS 8.8). The Form Builder widget’s webhook URL setting is persisted from attacker-controlled input on every page render, including contributor-level draft previews, and the corresponding AJAX handler is accessible to both authenticated and unauthenticated callers, allowing attackers to direct the server to make arbitrary outbound HTTP requests to internal or external targets.
WordPress administrators using the Royal Elementor Addons plugin should update beyond version 1.7.1064 immediately or deactivate the plugin until a patch is available. Review server-side outbound request logs for unexpected connections to internal services or metadata endpoints, and restrict contributor-level access where possible to reduce the attack surface.
- π CVE-2026-17123 (CVSS 3.1: 8.8)