5 vulnerabilities across 5 products scored HIGH or above on August 27, 2026.

  • ๐ŸŸ  HIGH: 5

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-65641 (veeam/one) โ€” F1: exploitable โ†’ functional, AAS: 10.4 โ†’ 12.4 (HIGH โ†’ CRITICAL). Originally in 2026-08-26 bulletin.
  • [UPGRADED] CVE-2026-76904 (geotools/geotools) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-21 bulletin.
  • [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-20 bulletin.

๐ŸŸ  [HIGH] acpt/acpt_(pro)_-_custom_post_types_plugin_for_wordpress

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:acpt:acpt_pro_-_custom_post_types_plugin_for_wordpress:*:*:*:*:*:*:*:* (< 2.0.64)

ACPT (Pro) - Custom Post Types Plugin for WordPress versions 2.0.63 and earlier is affected by one critical vulnerability (CVE-2026-32566, CVSS 9.8) that allows unauthenticated privilege escalation. An attacker with no credentials can exploit this flaw to elevate privileges on a vulnerable WordPress site, potentially gaining full administrative control. WordPress administrators using this plugin should update immediately to a patched version and review their sites for signs of compromise. Refer to the Patchstack advisory for patch details and additional guidance.

Vendor Advisory


๐ŸŸ  [HIGH] hashthemes/hash_form

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:hashthemes:hash_form:*:*:*:*:*:*:*:* (< 1.4.2)

Hash Form plugin for WordPress versions 1.4.1 and earlier is affected by one critical vulnerability (CVE-2026-78292, CVSS 9.8) allowing unauthenticated PHP object injection. An attacker requires no authentication to exploit this flaw, which can lead to remote code execution, data exfiltration, or full site compromise depending on the object chains available in the application environment. WordPress administrators using this plugin should update to a patched version immediately and audit their sites for unauthorized activity. See the Patchstack advisory for remediation details.

Vendor Advisory


๐ŸŸ  [HIGH] paolo/geodirectory

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:paolo:geodirectory:*:*:*:*:*:*:*:*

GeoDirectory plugin for WordPress versions 2.8.176 and earlier is affected by one high-severity vulnerability (CVE-2026-81271, CVSS 8.8) involving unauthenticated cross-site request forgery. An attacker can trick an authenticated user into executing unintended actions by visiting a malicious page, potentially leading to unauthorized changes to site configuration or directory content. WordPress administrators running GeoDirectory should update to a patched version as soon as possible and review the Patchstack advisory for further details.

Vendor Advisory


๐ŸŸ  [HIGH] weptile/mobile_app_for_woocommerce

1 CVE | CVSS 3.1: 8.6 | AAS 9.4

  • cpe:2.3:a:weptile:mobile_app_for_woocommerce:*:*:*:*:*:*:*:* (< 0.4.63)

Mobile App for WooCommerce plugin versions 0.4.62 and earlier is affected by one high-severity vulnerability (CVE-2026-27330, CVSS 8.6) involving broken access control that requires no authentication to exploit. An unauthenticated attacker can bypass authorization checks to access restricted functionality or sensitive store data, posing a significant risk to WooCommerce sites using this plugin. Site administrators should update to a patched version immediately and review the Patchstack advisory for remediation guidance.

Vendor Advisory


๐ŸŸ  [HIGH] villatheme/suggestion_engine_for_woocommerce

1 CVE | CVSS 3.1: 8.5 | AAS 9.3

  • cpe:2.3:a:villatheme:suggestion_engine_for_woocommerce:*:*:*:*:*:*:*:* (< 2.0.12)

Suggestion Engine for WooCommerce plugin versions 2.0.11 and earlier is affected by one high-severity vulnerability (CVE-2026-81277, CVSS 8.5) allowing SQL injection by users with Contributor-level access or higher. Successful exploitation could enable an attacker to extract sensitive data from the WordPress database, including customer records, credentials, and order information. WooCommerce site administrators should update to a patched version immediately and audit database access logs for suspicious queries. See the Patchstack advisory for patch details.

Vendor Advisory