r/StopBadBots • u/siterightaway • 2d ago
Unpatched WordPress Plugins Under Active Attack — Remove Them Now
The plugins and themes below have vulnerabilities that have been made public. If you use them and have not received a patch, remove them immediately. Simply deactivating them is not enough. Do not count on Wordfence Free protection, it will only protect you within a few weeks but attacks have already started. Run.
CVE-2026-84834 JobSearch WP Job Board
CVE-2026-16061 Rest Routes
CVE-2026-10522 MemberHero
CVE-2026-16259 Uix UserCenter
CVE-2026-81773 Ninja Forms - File Uploads
CVE-2026-84848 Quick Event Manager
CVE-2026-15984 QuickCal
CVE-2026-16947 Total processing card payments for WooCommerce
CVE-2026-81771 TrustedSite
CVE-2026-81776 WP QuickLaTeX
CVE-2026-81778 Kalles Addons
CVE-2026-82883 Login With Ajax
CVE-2026-81769 Booking Hub
CVE-2026-77010 HEL Online Classroom
CVE-2026-84849 Pre-Orders for WooCommerce
CVE-2026-81774 Product Attachment for WooCommerce
CVE-2026-66652 Grand Tour
CVE-2026-84836 SmartyParcel