Security Digest: June 16, 2026 - 15 Critical Vulnerabilities
Today’s security picture is urgent: 15 newly disclosed vulnerabilities span WordPress plugins, admin tooling, SQL injection flaws, file deletion bugs, XSS, privilege escalation, and one unauthenticated access-control issue. Several are critical and can be exploited without valid credentials, which means exposed sites should be treated as immediately at risk.
· 11 min read
Executive Summary
Today’s security picture is urgent: 15 newly disclosed vulnerabilities span WordPress plugins, admin tooling, SQL injection flaws, file deletion bugs, XSS, privilege escalation, and one unauthenticated access-control issue. Several are critical and can be exploited without valid credentials, which means exposed sites should be treated as immediately at risk.
Act now: patch or disable affected plugins, restrict admin access, and review logs for suspicious requests, unexpected file writes, database errors, and new administrator accounts. If you run any of the affected WordPress plugins, prioritize those with unauthenticated SQL injection or file upload/RCE risk first.
Critical Vulnerabilities
CVE-2026-40750: Kids Online Store dangerous file upload
- Impact: Attackers can upload a web shell and take over the server.
- Affected Systems: Kids Online Store through
0.8.9. - Immediate Action: Disable the plugin or take the site offline until patched.
- Mitigation: Update to a fixed release as soon as the vendor provides one; review uploaded files and web-accessible directories.
CVE-2026-52715: GEO my WordPress unauthenticated SQL injection
- Impact: Remote attackers can query or extract database data without logging in.
- Affected Systems: GEO my WordPress
<= 4.5.5. - Immediate Action: Patch immediately and restrict public access if possible.
- Mitigation: Upgrade to a fixed version; monitor for database error spikes and unusual parameter patterns.
CVE-2026-49772: The Events Calendar blind SQL injection
- Impact: Attackers may extract sensitive data from the database.
- Affected Systems: The Events Calendar
6.15.12through6.16.2. - Immediate Action: Update now and review any exposed event endpoints.
- Mitigation: Install the vendor fix; look for repeated, automated requests and DB timing anomalies.
CVE-2026-39574: InPost Gallery unauthenticated SQL injection
- Impact: Database data may be exposed or altered by remote attackers.
- Affected Systems: InPost Gallery
<= 2.1.4.6. - Immediate Action: Disable the plugin until patched.
- Mitigation: Upgrade immediately; validate database integrity after remediation.
CVE-2026-8444: WP Review Slider Pro subscriber SQL injection
- Impact: Authenticated attackers can extract sensitive database data.
- Affected Systems: WP Review Slider Pro
<= 12.6.8. - Immediate Action: Patch now and review subscriber accounts.
- Mitigation: Apply the vendor update; limit low-privilege access and inspect AJAX logs.
CVE-2026-6933: Premmerce Dev Tools remote code execution
- Impact: Authenticated attackers can create malicious PHP files and execute code on the server.
- Affected Systems: Premmerce Dev Tools
<= 2.0. - Immediate Action: Disable the plugin immediately if not essential.
- Mitigation: Update to a fixed version; search for unexpected PHP files in
wp-content/plugins/.
CVE-2026-8443: WP Review Slider Pro SQL injection via chart data
- Impact: Authenticated attackers can pull sensitive data from the database.
- Affected Systems: WP Review Slider Pro
<= 12.6.8. - Immediate Action: Patch immediately; treat subscriber-level accounts as high risk.
- Mitigation: Upgrade, then review SQL error logs and API responses for leaked query strings.
CVE-2026-39581: WP Sessions Time Monitoring Full Automatic subscriber SQL injection
- Impact: Low-privilege users may extract or manipulate database content.
- Affected Systems: WP Sessions Time Monitoring Full Automatic
<= 1.1.4. - Immediate Action: Update or disable the plugin now.
- Mitigation: Apply the vendor patch and audit subscriber activity.
CVE-2026-8442: WP Review Slider Pro arbitrary file deletion
- Impact: Attackers can delete arbitrary files and potentially trigger code execution.
- Affected Systems: WP Review Slider Pro
<= 12.6.8. - Immediate Action: Patch immediately and check for missing core files.
- Mitigation: Upgrade, then verify file integrity and restore from backup if needed.
CVE-2026-52712: Attendance Manager subscriber SQL injection
- Impact: Authenticated attackers can access or modify database data.
- Affected Systems: Attendance Manager
<= 0.6.2. - Immediate Action: Patch now; restrict subscriber access where possible.
- Mitigation: Install the fixed version and review database queries for abuse.
CVE-2026-52711: WooCommerce POS broken access control
- Impact: Attackers may bypass access controls and reach sensitive functions.
- Affected Systems: WooCommerce POS
<= 1.8.14. - Immediate Action: Update immediately and review POS permissions.
- Mitigation: Apply the vendor fix; verify no unauthorized actions occurred.
CVE-2026-8176: LatePoint privilege escalation to administrator
- Impact: Authenticated agents can become WordPress administrators.
- Affected Systems: LatePoint
<= 5.5.1. - Immediate Action: Patch now and review all agent accounts.
- Mitigation: Upgrade, reset suspicious passwords, and check for new admin users.
CVE-2026-39437: Min Max Step Quantity Limits Manager unauthenticated XSS
- Impact: Attackers can run script in a victim’s browser and steal sessions or redirect users.
- Affected Systems: Min Max Step Quantity Limits Manager for WooCommerce
<= 5.2.2. - Immediate Action: Patch immediately and review public-facing pages.
- Mitigation: Update the plugin; clear caches and check for injected content.
CVE-2026-54191: Pods unauthenticated XSS
- Impact: Remote attackers can execute script in users’ browsers.
- Affected Systems: Pods
<= 3.3.8. - Immediate Action: Update now and inspect any exposed forms or content blocks.
- Mitigation: Apply the fix; use a WAF rule to block suspicious payloads.
CVE-2026-54198: Media Library Assistant unauthenticated XSS
- Impact: Attackers can steal sessions or perform actions as logged-in users.
- Affected Systems: Media Library Assistant
<= 3.35. - Immediate Action: Patch immediately and invalidate active sessions if abuse is suspected.
- Mitigation: Upgrade and review browser-side indicators of compromise.
Previously Alerted
- CVE-2026-49774: CVE-2026-49774 Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch or disable every affected plugin immediately, starting with unauthenticated SQL injection, file upload, and RCE issues.
- Check for compromise: look for new PHP files, unexpected admin accounts, database errors, unusual AJAX requests, and deleted core files.
- Restrict access: limit wp-admin, remove unused subscriber/agent accounts, and rotate credentials for admins and service users.
- Verify versions: confirm each affected plugin is above the vulnerable range before reopening the site.
- Monitor closely: enable WAF rules, review web server logs, and alert on repeated requests to plugin AJAX endpoints.
Verification steps:
- Inventory all WordPress sites and plugin versions.
- Compare installed versions against the vulnerable ranges listed above.
- Confirm patches were applied from official vendor releases only.
- Scan for file integrity changes in
wp-content/plugins/and unexpected database modifications.
Monitoring recommendations: Watch for spikes in 500 errors, SQL syntax errors, outbound connections from web servers, and login/session anomalies. For sites with any exposure, assume active probing within hours of disclosure.
Related Resources
- Internal blog post: June 16, 2026 WordPress plugin emergency response guide (to be published).
- Internal blog post: How to triage SQL injection and file upload incidents (to be published).
- Official vendor advisories: check each plugin vendor’s security release notes and changelogs for fixed versions.