· Security Notices
Weekly security digest: 28 September 2026
Security advisories, releases and end-of-life dates for WordPress, Ruby, Rails, SilverStripe, PHP and databases from 22 September 2026 to 28 September 2026.
WordPress vulnerabilities
Elementor Website Builder 4.3.0 - 4.3.1 - Cross-Site Request Forgery via REST Nonce Bypass to Privilege Escalation
- Elementor Website Builder – more than just a page builder: affects 4.3.0 to 4.3.1, fixed in 4.3.2
- Severity: CVSS 8.8
- CVE: CVE-2026-62062
- Read the advisory
Ninja Forms <= 3.15.3 - Unauthenticated PHP Object Injection
- Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder: affects up to 3.15.3, fixed in 3.15.4
- Severity: CVSS 8.1
- CVE: CVE-2026-91827
- Read the advisory
WordPress Core <= 7.1.1 - Unauthenticated Local File Inclusion via locate_template() Path Traversal
- WordPress core: affects 4.7 to 4.7.36, 4.8 to 4.8.31, 4.9 to 4.9.32, 5.0 to 5.0.28, 5.1 to 5.1.25, 5.2 to 5.2.27, 5.3 to 5.3.24, 5.4 to 5.4.22, 5.5 to 5.5.21, 5.6 to 5.6.20, 5.7 to 5.7.18, 5.8 to 5.8.16, 5.9 to 5.9.17, 6.0 to 6.0.15, 6.1 to 6.1.13, 6.2 to 6.2.12, 6.3 to 6.3.11, 6.4 to 6.4.11, 6.5 to 6.5.11, 6.6 to 6.6.8, 6.7 to 6.7.8, 6.8 to 6.8.9, 6.9 to 6.9.8, 7.0 to 7.0.5, 7.1 to 7.1.1, fixed in 4.7.37
- Severity: CVSS 8.1
- CVE: CVE-2026-87902
- Read the advisory
Vulnerability data from Wordfence Intelligence. Each entry links to its record. Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation. Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
Releases
- PHP: PHP 8.2.34 released! (24 September 2026)
- PHP: PHP 8.5.11 released! (24 September 2026)
- PHP: PHP 8.4.26 released! (24 September 2026)
- PHP: PHP 8.3.35 released! (24 September 2026)
- Rails: Rails 8.1.4 (24 September 2026)
- Rails: Rails 7.2.4 (24 September 2026)
- Ruby: Ruby 3.4.11 Released (23 September 2026)
- WordPress: WordPress 7.1.2 Release (22 September 2026)