Security Advisory - Published 2026-06-27 - WordPress / CMS

WordPress access and XSS batch: check exposed forms, customer data, and editor content

This batch is lower than the critical upload and privilege group, but it still matters on public WordPress sites. Most entries involve unauthenticated access, customer-facing plugins, forms, WooCommerce extensions, contributor/editor actions, or stored content that should be reviewed after patching.

Defensive scope: check systems you own or are approved to repair. This page keeps to version checks, exposure review, logs, patching, and compromise indicators. It stays on inventory, patching, log review, and compromise triage.

Affected CVEs in this batch

CVEProductAffectedReviewCVSS
CVE-2026-56054JS Help Desk<= 3.1.1files and uploads7.7
CVE-2026-57631Popup box<= 6.0.1database logs7.6
CVE-2026-54826SupportCandy<= 3.4.6users and access7.6
CVE-2026-57628WP All Import<= 4.0.1database logs7.6
CVE-2026-54824Ads by WPQuads<= 3.0.3users and access7.5
CVE-2026-54844CheckView Automated Testing<= 2.1.0users and access7.5
CVE-2026-56029CorvusPay WooCommerce Payment Gateway<= 2.7.4users and access7.5
CVE-2026-54835Five Star Restaurant Menu<= 2.5.2users and access7.5
CVE-2026-54830Five Star Restaurant Reservations<= 2.7.19users and access7.5
CVE-2025-68064Goya Core< 1.0.9.4files and uploads7.5
CVE-2026-54832Gutenverse Companion<= 2.5.0users and access7.5
CVE-2026-9702InPost PLbefore 1.9.1logs and users7.5
CVE-2026-54837Intranet and Private Site - All-In-One Intranet<= 1.8.1users and access7.5
CVE-2026-54829Jacob N. Breetvelt WP Photo Album Plusvendor-fixed releasedatabase logs7.5
CVE-2026-27366MainWP Child<= 6.1.1users and access7.5
CVE-2026-54828Motors<= 1.4.109users and access7.5
CVE-2026-54834Object Cache 4 everyone<= 2.3.2users and access7.5
CVE-2026-57647Panorama Viewer 360 Degree Image + Video Viewer<= 1.6.1files and uploads7.5
CVE-2026-56025Paymob for WooCommerce<= 4.1.2users and access7.5
CVE-2026-56060Print Invoice & Delivery Notes for WooCommerce<= 7.1.1users and access7.5
CVE-2025-68063Splash - Sport Club WordPress Theme for Basketball, Football, Hockey<= 4.4.3files and uploads7.5
CVE-2026-54847Stylish Cost Calculator<= 8.3.9users and access7.5
CVE-2026-56061Subscriptions for WooCommerce<= 1.9.5users and access7.5
CVE-2026-54846Syncee Premium Dropshipping and Wholesale<= 1.0.27users and access7.5
CVE-2026-56069Toolset Forms<= 2.6.24users and access7.5
CVE-2026-12937Tourfic AI Powered Travel Booking, Hotel Booking & Car Rental WordPressvendor-fixed releasedatabase logs7.5
CVE-2026-54839Trinity Backup - Backup, Migrate, Restore, Clone and Schedule Backups<= 2.0.9users and access7.5
CVE-2026-54841Vitepos<= 3.4.2users and access7.5
CVE-2026-54833Enable CORS<= 2.0.3users and access7.4
CVE-2026-54821Visual Link Preview<= 2.3.1data exposure7.4
CVE-2026-54840Newsletters<= 4.13users and access7.3
CVE-2026-56042Advanced Order Export For WooCommerce<= 4.0.9content and widgets7.1
CVE-2026-56045Automatic< 3.135.1users and access7.1
CVE-2026-56044Blog2Social<= 8.9.2users and access7.1
CVE-2026-56043Customer Reviews for WooCommerce<= 5.110.1users and access7.1
CVE-2026-57312Everest Forms<= 3.4.8users and access7.1
CVE-2026-56071Forminator<= 1.53.1users and access7.1
CVE-2026-57319FOX<= 1.4.8users and access7.1
CVE-2026-56040Gutenverse Form<= 2.4.7users and access7.1
CVE-2026-57321H5P<= 1.17.7files and uploads7.1
CVE-2026-56006H5P<= 1.17.6users and access7.1
CVE-2026-56011MapPress Maps for WordPress<= 2.97.3users and access7.1
CVE-2026-56014Master Slider<= 3.11.2users and access7.1
CVE-2026-57325NanoMag<= 1.8users and access7.1
CVE-2026-56047perfmatters<= 2.6.3users and access7.1
CVE-2026-56039Quick Interest Slider<= 3.1.6users and access7.1
CVE-2026-56041Responsive Lightbox<= 2.7.6users and access7.1
CVE-2026-57317Simply Schedule Appointments<= 1.6.12.2users and access7.1
CVE-2026-57314SureCart<= 4.3.2users and access7.1
CVE-2026-56051TablePress<= 3.3.1users and access7.1
CVE-2026-57322weMail<= 2.1.2users and access7.1
CVE-2026-56072WoodMart<= 8.5.3users and access7.1
CVE-2026-56005WP Activity Log<= 5.6.3.1content and widgets7.1
CVE-2026-57635FunnelKit Payment Gateway for Stripe WooCommerce<= 1.14.0.3users and access6.5
CVE-2026-56013License Manager for WooCommerce<= 3.0.15users and access6.5
CVE-2026-56048Payment Gateway Based Fees and Discounts for WooCommerce<= 3.0.0users and access6.5
CVE-2026-56050Themeisle PPOM for WooCommercevendor-fixed releaseusers and access6.5
CVE-2026-52701User Registration<= 5.2.2users and access6.5
CVE-2026-1869User Registration & Membership Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buildervendor-fixed releaseusers and access6.5

What to check

  • Plugin and theme versions, including child-theme bundles and page-builder add-ons.
  • Public forms, customer review widgets, support tickets, maps, newsletters, booking, and WooCommerce extensions.
  • Contributor and subscriber activity, edited posts, media changes, and deleted files.
  • Sensitive data exposure reports, downloaded exports, order data changes, and unusual referers.
  • Stored or reflected script indicators in pages, widgets, templates, and plugin settings.

Safe fix path

  1. Upgrade affected plugins and themes, then clear page, CDN, and object cache after confirming the patched files are active.
  2. Limit contributor/subscriber capabilities until suspicious content and file changes are reviewed.
  3. Preserve access logs and plugin logs before bulk deleting posts, media, tickets, or forms.
  4. Ask for repair review when XSS appears in live content, customer data is exposed, or files were deleted.

Compromise indicators

  • New users, role changes, unexpected sessions, or unknown API tokens.
  • Files changed during the exposure window, especially executable files or generated configs.
  • Repeated application errors, database errors, queue failures, or unusual outbound requests.
  • Plugin, container, service, or package versions that differ from the expected deployment record.

When to ask Ping7 for repair

Use Ping7 CVE Repair when the affected component is public, logs show suspicious activity, patching may break production, or cleanup requires file, database, user, token, or container review.

References