3 vulnerabilities across 3 products scored HIGH or above on September 19, 2026.

  • 🟠 HIGH: 3

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-84383 (strukturag/libheif) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-09-18 bulletin.
  • [UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_β€”_dynamic_blocks_form_builder) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-09-16 bulletin.

🟠 [HIGH] gravity_forms/gravity_forms

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:gravity_forms:gravity_forms:*:*:*:*:*:*:*:* (< 3.1.0.5)

Gravity Forms for WordPress versions through 3.1.0.4 are affected by one critical vulnerability (CVE-2026-84434, CVSS 9.8) that allows unauthenticated arbitrary file upload. A validation bypass in hidden file upload fields lets attackers upload potentially executable files without authentication, which could lead to full site compromise.

All organizations running Gravity Forms on WordPress should treat this as an urgent priority. Review the Gravity Forms change log at docs.gravityforms.com for the patched release and update immediately.

Vendor Advisory


🟠 [HIGH] wpmudev/forminator_forms_–_contact_form,payment_form&_custom_form_builder

1 CVE | CVSS 3.1: 9.1 | AAS 9.9

  • cpe:2.3:a:wpmudev:forminator_forms_contact_form_payment_form_custom_form_builder:*:*:*:*:*:*:*:*

WPMU DEV Forminator Forms for WordPress versions through 1.57.2 are affected by one critical vulnerability (CVE-2026-92229, CVSS 9.1) that enables unauthenticated arbitrary shortcode execution. Insufficient input validation in the front-end action handler allows attackers to invoke any registered shortcode without authentication, potentially leading to information disclosure, privilege escalation, or further exploitation depending on installed plugins.

WordPress administrators using Forminator Forms should update to a patched version immediately and audit site activity for signs of exploitation.

Vendor Advisory


🟠 [HIGH] brechtvds/wp_recipe_maker

1 CVE | CVSS 3.1: 9.1 | AAS 9.4

  • cpe:2.3:a:brechtvds:wp_recipe_maker:*:*:*:*:*:*:*:* (< 10.8.2)

WP Recipe Maker for WordPress versions through 10.8.1 are affected by one critical vulnerability (CVE-2026-89274, CVSS 9.1) that allows arbitrary shortcode execution. The plugin’s metadata sanitization routine passes approved comment content directly to do_shortcode without stripping shortcode tokens, enabling attackers to inject and execute arbitrary shortcodes through crafted recipe comment ratings.

Site administrators running WP Recipe Maker should update beyond version 10.8.1 as soon as a patch is available and review existing recipe comments for suspicious shortcode content.

Vendor Advisory