Active exploitation — September 2026

Is your WordPress site one of the 3.25 million still exposed?

Five plugin vulnerabilities are being actively exploited or freshly disclosed right now — nearly all of them let an unauthenticated attacker take full control of your server outright, no login required. Separately, PHP 8.4 is fatal-erroring sites that haven't been updated for it. The free check below tells you, plainly, whether you're affected. It does not hand you the fix for free.

CVE-2026-19949
All-in-One WP Migration

SQLi → RCE · 3.25M+ installs, 65% unpatched

CVE-2026-3296
Everest Forms

Object injection → RCE · CVSS 9.8, unauthenticated

CVE-2026-15748
Forminator Forms

File upload → RCE · CVSS 9.8, unauthenticated

CVE-2026-32475
Elementor Pro

File upload → RCE · CVSS 9.8, unauthenticated

CVE-2026-14894
Super Forms

File upload → RCE · CVSS 9.8, unauthenticated

Free exposure check

Free · Yes or no only

Submit your URL and we'll check your site's public plugin fingerprints against the five CVEs above. You get a straight yes or no — which of the five (if any) you're running, nothing more. No version numbers, no PHP 8.4 findings, no remediation steps. That level of detail is the paid report below, on purpose: a free tool that hands over the full findings isn't actually free to us to keep producing, and it's not something we're going to give away and then bill you for after the fact.

You'll hear back the same business day with a plain yes/no. The full report — exact versions, what to fix, and the PHP 8.4 compatibility pass — is the $200 Starter tier below, and it's only sent once that's paid for.

How it works

Two separate deliverables, on purpose — a free flag, and a paid report.

STEP 01

Free: are you on the list?

Public plugin fingerprint checked against the five active CVEs. You get a yes/no, same business day.

STEP 02

Paid: the actual report

$200 gets you the full breakdown — exact versions, severity, and the PHP 8.4 compatibility scan if you share source.

STEP 03

Fix it or license it

Take the report to your own team, or have us apply the fix and keep watching the server going forward.

Pricing

The free check above is not on this list — it's a yes/no gate, not a tier.

Starter

$200

Full diagnostic report: exact versions, CVE matches, PHP 8.4 findings. This is what the free check above does not include.

Standard

$450

Report, plus patching every flagged plugin to a safe version and a re-scan to confirm it's closed.

Advanced

from $1,800

Incident response — for a site already showing signs of compromise, not just exposure. Scoped after the free check.

Ongoing

$750/mo

We keep watching the server this runs on going forward — not a plugin-alert email, actual server-level checks.

The free check confirms exposure only. Versions, severity, remediation steps, and the PHP 8.4 pass are gated behind the $200 Starter tier and are never sent as part of the free check.

Want the full report now?

Skip the free check and go straight to the $200 report — tell us your URL and we'll invoice and deliver the same business day.

This tool performs passive, publicly-visible checks only. Run it on sites you own or are authorized to assess.