12 vulnerabilities across 8 products scored HIGH or above on August 20, 2026.

  • 🟠 HIGH: 12

🟠 [HIGH] repute_infosystems/bookingpress_appointment_booking_pro

1 CVE | CVSS 3.1: 9.3 | AAS 10.3

  • cpe:2.3:a:repute_infosystems:bookingpress_appointment_booking_pro:*:*:*:*:*:*:*:* (< 6.0.3)

BookingPress Appointment Booking Pro versions 6.0.2 and earlier by Repute Infosystems are affected by a critical unauthenticated SQL injection vulnerability (CVE-2026-68566, CVSS 9.3). This flaw allows remote attackers to execute arbitrary SQL queries without authentication, potentially exposing sensitive booking and customer data stored in the WordPress database. Site administrators running this plugin should update immediately to a patched version and review database logs for signs of exploitation; refer to the Patchstack advisory for remediation details.

Vendor Advisory


🟠 [HIGH] wpmu_dev/forminator

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:wpmu_dev:forminator:*:*:*:*:*:*:*:* (< 1.58.0)

WPMU DEV Forminator versions 1.57.0 and earlier are affected by a critical unauthenticated PHP object injection vulnerability (CVE-2026-66583, CVSS 9.8). This flaw allows remote attackers to inject arbitrary PHP objects without authentication, which can lead to remote code execution, data exfiltration, or full site compromise depending on available gadget chains. WordPress administrators using Forminator should update to a patched version immediately and audit their sites for indicators of compromise; see the Patchstack advisory for full remediation guidance.

Vendor Advisory


🟠 [HIGH] tyche_softwares./abandoned_cart_pro_for_woocommerce

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:tyche_softwares.:abandoned_cart_pro_for_woocommerce:*:*:*:*:*:*:*:* (< 10.4.1)

Abandoned Cart Pro for WooCommerce by Tyche Softwares versions 10.4.0 and earlier are affected by a critical unauthenticated privilege escalation vulnerability (CVE-2026-66682, CVSS 9.8). This flaw allows remote attackers to elevate privileges without authentication, potentially gaining full administrative control over the WordPress site and its WooCommerce store data. WooCommerce site operators using this plugin should update to a patched version immediately and review user accounts for any unauthorized privilege changes; consult the Patchstack advisory for remediation details.

Vendor Advisory


🟠 [HIGH] roxnor/fundengine

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:roxnor:fundengine:*:*:*:*:*:*:*:* (< 1.7.10)

FundEngine by Roxnor versions 1.7.9 and earlier are affected by a critical unauthenticated PHP object injection vulnerability (CVE-2026-73993, CVSS 9.8). This flaw allows remote attackers to inject arbitrary PHP objects without authentication, potentially leading to remote code execution, data theft, or complete site takeover depending on available gadget chains in the WordPress environment. Organizations using FundEngine for fundraising or donation functionality should update to a patched version immediately and audit their sites for signs of compromise; refer to the Patchstack advisory for remediation guidance.

Vendor Advisory


🟠 [HIGH] wpeverest/user_registration_&_membership_pro

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:wpeverest:user_registration_membership_pro:*:*:*:*:*:*:*:* (< 5.4.6)

User Registration & Membership Pro by WPEverest versions 5.4.5 and earlier are affected by a critical unauthenticated broken authentication vulnerability (CVE-2026-74001, CVSS 9.8). This flaw enables remote attackers to take over user accounts without authentication, potentially including administrator accounts, leading to full site compromise. WordPress administrators using this plugin should update to a patched version immediately, review all user accounts for unauthorized access, and reset credentials for any potentially affected accounts; see the Patchstack advisory for full remediation details.

Vendor Advisory


🟠 [HIGH] red_hat/red_hat_enterprise_linux_10

2 CVEs | CVSS 3.1: 9.6 | AAS 9.7

  • cpe:2.3:a:redhat:enterprise_linux:*:*:*:*:*:*:*:* (>= 7.0)
  • cpe:2.3:a:redhat:enterprise_linux:*:*:*:*:*:*:*:* (>= 8.0)
  • cpe:2.3:a:redhat:enterprise_linux:*:*:*:*:*:*:*:* (>= 9.0)

Red Hat Enterprise Linux 10 is affected by 2 vulnerabilities (CVE-2026-11861, CVE-2026-13097, max CVSS 9.6), including at least one critical flaw in FreeIPA where Active Directory users in a trust relationship can bypass authentication for FreeIPA services by impersonating client names in Kerberos TGS requests due to missing PAC certificate verification. Exploitation allows authenticated AD users to escalate privileges across FreeIPA-managed services including the web portal, SMB, and LDAP. Organizations running FreeIPA with AD trust configurations on RHEL 10 should apply Red Hat’s patches immediately and audit Kerberos authentication logs for signs of ticket impersonation; see the Red Hat advisory for remediation details.

Vendor Advisory


🟠 [HIGH] n8n-io/n8n

4 CVEs | CVSS 4.0: 8.7 | AAS 9.6

  • cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:* (>= 2.0.0, < 2.33.4)
  • cpe:2.3:a:n8n-io:n8n:*:*:*:*:*:*:*:* (>= 2.34.0, < 2.34.1)

n8n workflow automation platform versions before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 are affected by 4 vulnerabilities (max CVSS 8.7), including multiple flaws that allow authenticated users to bypass n8n’s file-access restrictions through nodes such as Snowflake, enabling arbitrary file read and write operations on the host system. Exploitation by an authenticated user with valid node credentials could lead to exfiltration of sensitive server files or overwriting critical files to achieve further compromise. Organizations self-hosting n8n should update to patched versions immediately and review workflow execution logs for suspicious node activity; see the GitHub security advisories for full details.

Vendor Advisory


🟠 [HIGH] cleantalk_inc/security_&_malware_scan_by_cleantalk

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a:cleantalk_inc:security_malware_scan_by_cleantalk:*:*:*:*:*:*:*:* (< 2.185)

Security & Malware scan by CleanTalk versions 2.184 and earlier are affected by a critical unauthenticated SQL injection vulnerability (CVE-2026-66593, CVSS 9.3). This flaw is particularly notable as it exists in a security plugin itself, allowing remote attackers to execute arbitrary SQL queries without authentication and potentially compromise the entire WordPress database including user credentials and site configuration. WordPress administrators using this plugin should update to a patched version immediately and audit their databases for unauthorized access; see the Patchstack advisory for remediation guidance.

Vendor Advisory