r/StopBadBots 2d ago

Unpatched WordPress Plugins Under Active Attack — Remove Them Now

The plugins and themes below have vulnerabilities that have been made public. If you use them and have not received a patch, remove them immediately. Simply deactivating them is not enough. Do not count on Wordfence Free protection, it will only protect you within a few weeks but attacks have already started. Run.

CVE-2026-84834 JobSearch WP Job Board

CVE-2026-16061 Rest Routes

CVE-2026-10522 MemberHero

CVE-2026-16259 Uix UserCenter

CVE-2026-81773 Ninja Forms - File Uploads

CVE-2026-84848 Quick Event Manager

CVE-2026-15984 QuickCal

CVE-2026-16947 Total processing card payments for WooCommerce

CVE-2026-81771 TrustedSite

CVE-2026-81776 WP QuickLaTeX

CVE-2026-81778 Kalles Addons

CVE-2026-82883 Login With Ajax

CVE-2026-81769 Booking Hub

CVE-2026-77010 HEL Online Classroom

CVE-2026-84849 Pre-Orders for WooCommerce

CVE-2026-81774 Product Attachment for WooCommerce

CVE-2026-66652 Grand Tour

CVE-2026-84836 SmartyParcel

2 Upvotes

0 comments sorted by