· Security Notices
Weekly security digest: 21 September 2026
Security advisories, releases and end-of-life dates for WordPress, Ruby, Rails, SilverStripe, PHP and databases from 15 September 2026 to 21 September 2026.
WordPress vulnerabilities
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field
- Gravity Forms: affects up to 3.1.0.4, fixed in 3.1.1
- Severity: CVSS 9.8
- CVE: CVE-2026-84434
- Read the advisory
WordPress Core <= 7.1 - Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 7.2
- CVE: CVE-2026-93485
- Read the advisory
WordPress Core <= 7.1 - Missing Authorization to customize_changeset Write via XML-RPC (Multisite/Custom Role edit_css Bypass)
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 5.5
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Custom Header Image Data
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.4
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Author+) Information Exposure via attachment_submitbox_metadata()
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.3
- Read the advisory
WordPress Core <= 7.1 - Forced Theme Install/Preview and Selector Injection via Theme Installer Route
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.3
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Author+) Missing Authorization to Comment/Note Reparenting via REST API
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.3
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Contributor+) Path Traversal via REST Templates Controller
- WordPress core: affects 5.8 to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.3
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Contributor+) Information Exposure via Sample Permalink AJAX Actions
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.3
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Post Overwrite
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 4.3
- Read the advisory
WordPress Core <= 7.1 - HTML API set_modifiable_text() Comment Boundary Break
- WordPress core: affects 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.7.8
- Severity: CVSS 3.7
- Read the advisory
WordPress Core <= 7.1 - Authenticated (Administrator+) Missing Authorization to Network Plugin Activation (Multisite)
- WordPress core: affects up to 6.6.7, 6.7 to 6.7.7, 6.8 to 6.8.8, 6.9 to 6.9.7, 7.0 to 7.0.4, 7.1, fixed in 6.6.8
- Severity: CVSS 2.7
- Read the advisory
Vulnerability data from Wordfence Intelligence. Each entry links to its record. Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
Releases
- MariaDB: MariaDB 13.0 Is Now Stable (17 September 2026)
- WordPress: WordPress 7.1.1 Maintenance and Security Release (17 September 2026)
- Ruby: Ruby 4.0.7 Released (15 September 2026)