Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesWordPress core

WordPress core vulnerabilities

WordPress core has 61 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.

Known vulnerabilities
61
Most recent
6 Oct 2026
Attackers are using WordPress core vulnerabilities in real attacks right now. CVE-2026-60137 (listed Jul 2026), CVE-2026-63030 (listed Jul 2026) are on the US CISA Known Exploited Vulnerabilities list. If your installed version is affected, update now and check the site for signs of compromise. Get help today or call 0208 088 8371.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-66666
Medium 6.9Up to 6.6.9Check for an update1 d ago
SQL injection
Exploited in the wild
CVE-2026-60137
Medium 5.9Before 7.0.2Fixed in 7.0.217 Jul 2026
SQL injection
Exploited in the wild
CVE-2026-63030
Critical 9.8Before 7.0.2Fixed in 7.0.217 Jul 2026
Cross-site scripting (XSS)
CVE-2022-50945
Medium 6.4Not yet publishedCheck for an update10 May 2026
Security weakness
CVE-2025-54352
Low 3.7Up to 6.8.2Check for an update21 Jul 2025
Broken access control
CVE-2023-39999
Medium 4.3Up to 4.1.38Fixed in 6.3.213 Oct 2023
Security weakness
CVE-2023-22622
Medium 5.3Up to 6.1.1Check for an update5 Jan 2023
Security weakness
CVE-2021-44223
High 8.1Before 5.8Fixed in 5.825 Nov 2021
Cross-site scripting (XSS)
CVE-2020-28038
Medium 6.1Before 5.5.2Fixed in 5.5.22 Nov 2020
Cross-site request forgery (CSRF)
CVE-2020-28040
Medium 4.3Before 5.5.2Fixed in 5.5.22 Nov 2020
PHP object injection
CVE-2020-28032
Critical 9.8Before 5.5.2Fixed in 5.5.22 Nov 2020
Security weakness
CVE-2020-28033
High 7.5Before 5.5.2Fixed in 5.5.22 Nov 2020
Cross-site scripting (XSS)
CVE-2020-28034
Medium 6.1Before 5.5.2Fixed in 5.5.22 Nov 2020
Security weakness
CVE-2020-28035
Critical 9.8Before 5.5.2Fixed in 5.5.22 Nov 2020
Cross-site scripting (XSS)
CVE-2019-17672
Medium 6.1Before 5.2.4Fixed in 5.2.417 Oct 2019
Security weakness
CVE-2019-17673
High 7.5Before 5.2.4Fixed in 5.2.417 Oct 2019
Cross-site scripting (XSS)
CVE-2019-17674
Medium 5.4Before 5.2.4Fixed in 5.2.417 Oct 2019
Cross-site request forgery (CSRF)
CVE-2019-17675
High 8.8Before 5.2.4Fixed in 5.2.417 Oct 2019
Server-side request forgery (SSRF)
CVE-2019-17669
Critical 9.8Before 5.2.4Fixed in 5.2.417 Oct 2019
Server-side request forgery (SSRF)
CVE-2019-17670
Critical 9.8Before 5.2.4Fixed in 5.2.417 Oct 2019
Cross-site scripting (XSS)
CVE-2019-16221
Medium 6.1Before 5.2.3Fixed in 5.2.311 Sep 2019
Cross-site scripting (XSS)
CVE-2019-16222
Medium 6.1Before 5.2.3Fixed in 5.2.311 Sep 2019
Cross-site scripting (XSS)
CVE-2019-16223
Medium 5.4Before 5.2.3Fixed in 5.2.311 Sep 2019
Cross-site scripting (XSS)
CVE-2019-16217
Medium 6.1Before 5.2.3Fixed in 5.2.311 Sep 2019
Cross-site scripting (XSS)
CVE-2019-16218
Medium 6.1Before 5.2.3Fixed in 5.2.311 Sep 2019
Cross-site scripting (XSS)
CVE-2019-16219
Medium 6.1Before 5.2.3Fixed in 5.2.311 Sep 2019
Sensitive data exposure
CVE-2017-6514
Medium 5.3Not yet publishedCheck for an update22 May 2019
Cross-site scripting (XSS)
CVE-2019-9787
High 8.8Before 5.1.1Fixed in 5.1.114 Mar 2019
Remote code execution
CVE-2019-8942
High 8.8Before 4.9.9Fixed in 4.9.920 Feb 2019
Path traversal
CVE-2019-8943
Medium 6.5Up to 5.0.3Check for an update20 Feb 2019
Remote code execution
CVE-2018-1000773
High 8.8Up to 4.9.8Check for an update6 Sep 2018
Remote code execution
CVE-2017-1000600
High 8.8Before 4.9Fixed in 4.96 Sep 2018
Path traversal
CVE-2018-12895
High 8.8Before 4.9.7Fixed in 4.9.726 Jun 2018
Cross-site scripting (XSS)
CVE-2018-1000556
Medium 6.1Before 12.0.6Fixed in 12.0.626 Jun 2018
Security weakness
CVE-2014-6412
High 8.1Before 4.4.0Fixed in 4.4.012 Apr 2018
Cross-site scripting (XSS)
CVE-2018-5776
Medium 6.1Before 4.9.2Fixed in 4.9.218 Jan 2018
SQL injection
CVE-2017-16510
Critical 9.8Up to 4.8.2Check for an update2 Nov 2017
Security weakness
CVE-2012-6707
High 7.5Up to 4.8.2Check for an update19 Oct 2017
Security weakness
CVE-2016-9263
Medium 4.7Up to 4.8.2Check for an update12 Oct 2017
SQL injection
CVE-2017-14990
Medium 6.5Not yet publishedCheck for an update3 Oct 2017
Security weakness
CVE-2017-8295
Medium 5.9Up to 4.7.4Check for an update4 May 2017
Server-side request forgery (SSRF)
CVE-2016-4029
High 8.6Before 4.5Fixed in 4.57 Aug 2016
Security weakness
CVE-2016-5839
High 7.5Up to 4.5.2Check for an update29 Jun 2016
Security weakness
CVE-2016-5838
High 7.5Up to 4.5.2Check for an update29 Jun 2016
Security weakness
CVE-2016-5837
High 7.5Up to 4.5.2Check for an update29 Jun 2016
Sensitive data exposure
CVE-2016-5835
High 7.5Up to 4.5.2Check for an update29 Jun 2016
Broken access control
CVE-2015-5623
Not scoredUp to 4.2.2Check for an update3 Aug 2015
Security weakness
CVE-2014-9037
Not scoredUp to 3.7.4Check for an update25 Nov 2014
Security weakness
CVE-2014-0165
Not scoredUp to 3.7.1Check for an update10 Apr 2014
Security weakness
CVE-2010-5297
Not scoredUp to 3.0Check for an update21 Jan 2014
Security weakness
CVE-2013-4339
Not scoredUp to 3.6Check for an update12 Sep 2013
Security weakness
CVE-2013-2200
Not scoredUp to 3.5.1Check for an update8 Jul 2013
Sensitive data exposure
CVE-2013-2202
Not scoredUp to 3.5.1Check for an update8 Jul 2013
Security weakness
CVE-2013-2203
Not scoredUp to 3.5.1Check for an update8 Jul 2013
Sensitive data exposure
CVE-2012-5868
Not scoredNot yet publishedCheck for an update27 Dec 2012
Security weakness
CVE-2012-3385
Not scoredUp to 3.4.0Check for an update22 Jul 2012
Sensitive data exposure
CVE-2011-3818
Not scoredNot yet publishedCheck for an update24 Sep 2011
Sensitive data exposure
CVE-2011-3126
Not scoredBefore 3.1.3Fixed in 3.1.310 Aug 2011
Security weakness
CVE-2011-3127
Not scoredBefore 3.1.3Fixed in 3.1.310 Aug 2011
Sensitive data exposure
CVE-2011-3128
Not scoredBefore 3.1.3Fixed in 3.1.310 Aug 2011
Security weakness
CVE-2010-0682
Not scoredBefore 2.9.2Fixed in 2.9.223 Feb 2010
Read the published descriptions
CVE-2026-66666, 6 Oct 2026
Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9. CVE record
CVE-2026-60137, 17 Jul 2026
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CVE record
CVE-2026-63030, 17 Jul 2026
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. CVE record
CVE-2022-50945, 10 May 2026
WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed. CVE record
CVE-2025-54352, 21 Jul 2025
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior. CVE record
CVE-2023-39999, 13 Oct 2023
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38. CVE record
CVE-2023-22622, 5 Jan 2023
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits. CVE record
CVE-2021-44223, 25 Nov 2021
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory. CVE record
CVE-2020-28038, 2 Nov 2020
WordPress before 5.5.2 allows stored XSS via post slugs. CVE record
CVE-2020-28040, 2 Nov 2020
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. CVE record
CVE-2020-28032, 2 Nov 2020
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. CVE record
CVE-2020-28033, 2 Nov 2020
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. CVE record
CVE-2020-28034, 2 Nov 2020
WordPress before 5.5.2 allows XSS associated with global variables. CVE record
CVE-2020-28035, 2 Nov 2020
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. CVE record
CVE-2019-17672, 17 Oct 2019
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. CVE record
CVE-2019-17673, 17 Oct 2019
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. CVE record
CVE-2019-17674, 17 Oct 2019
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. CVE record
CVE-2019-17675, 17 Oct 2019
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. CVE record
CVE-2019-17669, 17 Oct 2019
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. CVE record
CVE-2019-17670, 17 Oct 2019
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. CVE record
CVE-2019-16221, 11 Sep 2019
WordPress before 5.2.3 allows reflected XSS in the dashboard. CVE record
CVE-2019-16222, 11 Sep 2019
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. CVE record
CVE-2019-16223, 11 Sep 2019
WordPress before 5.2.3 allows XSS in post previews by authenticated users. CVE record
CVE-2019-16217, 11 Sep 2019
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. CVE record
CVE-2019-16218, 11 Sep 2019
WordPress before 5.2.3 allows XSS in stored comments. CVE record
CVE-2019-16219, 11 Sep 2019
WordPress before 5.2.3 allows XSS in shortcode previews. CVE record
CVE-2017-6514, 22 May 2019
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring. CVE record
CVE-2019-9787, 14 Mar 2019
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php. CVE record
CVE-2019-8942, 20 Feb 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943. CVE record
CVE-2019-8943, 20 Feb 2019
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring. CVE record
CVE-2018-1000773, 6 Sep 2018
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. CVE record
CVE-2017-1000600, 6 Sep 2018
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9 CVE record
CVE-2018-12895, 26 Jun 2018
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges. CVE record
CVE-2018-1000556, 26 Jun 2018
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL with payload and send to the user. Victim need to open the link to be affected by reflected XSS. . CVE record
CVE-2014-6412, 12 Apr 2018
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach. CVE record
CVE-2018-5776, 18 Jan 2018
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). CVE record
CVE-2017-16510, 2 Nov 2017
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723. CVE record
CVE-2012-6707, 19 Oct 2017
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions. CVE record
CVE-2016-9263, 12 Oct 2017
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file. CVE record
CVE-2017-14990, 3 Oct 2017
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability). CVE record
CVE-2017-8295, 4 May 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message. CVE record
CVE-2016-4029, 7 Aug 2016
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. CVE record
CVE-2016-5839, 29 Jun 2016
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors. CVE record
CVE-2016-5838, 29 Jun 2016
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie. CVE record
CVE-2016-5837, 29 Jun 2016
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors. CVE record
CVE-2016-5835, 29 Jun 2016
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php. CVE record
CVE-2015-5623, 3 Aug 2015
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. CVE record
CVE-2014-9037, 25 Nov 2014
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash. CVE record
CVE-2014-0165, 10 Apr 2014
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php. CVE record
CVE-2010-5297, 21 Jan 2014
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. CVE record
CVE-2013-4339, 12 Sep 2013
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string. CVE record
CVE-2013-2200, 8 Jul 2013
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors. CVE record
CVE-2013-2202, 8 Jul 2013
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. CVE record
CVE-2013-2203, 8 Jul 2013
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message. CVE record
CVE-2012-5868, 27 Dec 2012
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack. CVE record
CVE-2012-3385, 22 Jul 2012
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors. CVE record
CVE-2011-3818, 24 Sep 2011
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files. CVE record
CVE-2011-3126, 10 Aug 2011
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. CVE record
CVE-2011-3127, 10 Aug 2011
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. CVE record
CVE-2011-3128, 10 Aug 2011
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php. CVE record
CVE-2010-0682, 23 Feb 2010
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. CVE record

What to do if you run WordPress core

If you run WordPress core, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support