đ° Contexte Source : blog.sucuri.net â Publication du 1er juin 2026. Il sâagit du rĂ©capitulatif mensuel de Sucuri listant les vulnĂ©rabilitĂ©s de sĂ©curitĂ© dĂ©couvertes et patchĂ©es dans lâĂ©cosystĂšme WordPress (plugins et thĂšmes) au cours du mois de mai 2026.
đŽ VulnĂ©rabilitĂ©s critiques Trois vulnĂ©rabilitĂ©s sont classĂ©es Critical :
Advanced Custom Fields: Extended (†0.9.2.5) â Privilege Escalation sans authentification â CVE-2026-8809 â patchĂ© en 0.9.2.6 Avada (Fusion) Builder (†3.15.2) â Remote Code Execution sans authentification â CVE-2026-6279 â patchĂ© en 3.15.3 Gravity Forms (†2.10.0.1) â Arbitrary File Deletion sans authentification â CVE-2026-48866 â patchĂ© en 2.10.1 đ VulnĂ©rabilitĂ©s High sans authentification (sĂ©lection) LiteSpeed Cache (†7.7) â XSS â CVE-2026-3375 â 7M+ installations WooCommerce PayPal Payments (†4.0.1) â Broken Access Control â CVE-2026-9284 Forminator Forms (†1.52.1) â Arbitrary File Read â CVE-2026-5192 ManageWP Worker (†4.9.31) â XSS â CVE-2026-3718 Database Backup for WordPress (†2.5.2) â Arbitrary File Read + Broken Access Control (x2) â CVE-2026-4030, CVE-2026-4029, CVE-2026-4031 Kirki (†6.0.6) â Arbitrary File Read â CVE-2026-8073 Post SMTP (†3.6.2) â XSS â CVE-2026-48838 Appointment Booking Calendar (†1.6.11.8) â SQL Injection â CVE-2026-7797 Email Marketing for WooCommerce by Omnisend (†1.18.0) â Broken Authentication â CVE-2026-42668 PixelYourSite Pro (†12.5.0.1) â SSRF â CVE-2026-7049 Avada (Fusion) Builder (†3.15.1) â SQL Injection â CVE-2026-4798 Slider Revolution â Arbitrary File Upload â CVE-2026-6692 Betheme (†28.4) â Remote Code Execution â CVE-2026-6261 Roneous (†2.1.5) â Local File Inclusion sans authentification â CVE-2025-69177 â pas de patch disponible đĄ Plugins sans patch disponible au moment de la publication Meta for WooCommerce (†3.7.0) â Open Redirect â CVE-2026-49059 Adminimize (†1.11.11) â Broken Access Control â CVE-2026-49045 Duplicate Page and Post (†2.9.5) â SQL Injection â CVE-2026-49046 The Post Grid (†7.9.2) â Broken Access Control â CVE-2026-49054 Roneous (†2.1.5) â Local File Inclusion â CVE-2025-69177 đ PĂ©rimĂštre global Lâarticle couvre plus de 100 entrĂ©es CVE rĂ©parties sur des dizaines de plugins et thĂšmes WordPress, avec des bases dâinstallation allant de 90 000 Ă plus de 10 millions (Yoast SEO). Les types de vulnĂ©rabilitĂ©s incluent : XSS, Broken Access Control, SQL Injection, RCE, Privilege Escalation, Arbitrary File Read/Upload/Deletion, IDOR, SSRF, Path Traversal, Local File Inclusion, Information Disclosure, Open Redirect, Broken Authentication, Denial of Service, Content Injection.
...