· Security Notices

Weekly security digest: 21 September 2026

Security advisories, releases and end-of-life dates for WordPress, Ruby, Rails, SilverStripe, PHP and databases from 15 September 2026 to 21 September 2026.

WordPress vulnerabilities

Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field

  • Gravity Forms: affects up to 3.1.0.4, fixed in 3.1.1
  • Severity: CVSS 9.8
  • CVE: CVE-2026-84434
  • Read the advisory

WordPress Core <= 7.1 - Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 7.2
  • CVE: CVE-2026-93485
  • Read the advisory

WordPress Core <= 7.1 - Missing Authorization to customize_changeset Write via XML-RPC (Multisite/Custom Role edit_css Bypass)

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 5.5
  • Read the advisory

WordPress Core <= 7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Custom Header Image Data

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.4
  • Read the advisory

WordPress Core <= 7.1 - Authenticated (Author+) Information Exposure via attachment_submitbox_metadata()

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.3
  • Read the advisory

WordPress Core <= 7.1 - Forced Theme Install/Preview and Selector Injection via Theme Installer Route

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.3
  • Read the advisory

WordPress Core <= 7.1 - Authenticated (Author+) Missing Authorization to Comment/Note Reparenting via REST API

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.3
  • Read the advisory

WordPress Core <= 7.1 - Authenticated (Contributor+) Path Traversal via REST Templates Controller

  • WordPress core: affects 5.8 to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.3
  • Read the advisory
  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.3
  • Read the advisory

WordPress Core <= 7.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Post Overwrite

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 4.3
  • Read the advisory

WordPress Core <= 7.1 - HTML API set_modifiable_text() Comment Boundary Break

  • WordPress core: affects 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.7.8
  • Severity: CVSS 3.7
  • Read the advisory

WordPress Core <= 7.1 - Authenticated (Administrator+) Missing Authorization to Network Plugin Activation (Multisite)

  • WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
  • Severity: CVSS 2.7
  • Read the advisory

Vulnerability data from Wordfence Intelligence. Each entry links to its record. Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Releases

← All posts

Or get in touch directly

How would you like a reply?

You’ll get a reply within one working day.