Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical WordPress Plugin Vulnerabilities

Wordfence has released security updates for Multiple critical vulnerabilities have been identified in WordPress plugins, including unauthenticated account takeover and hook injection vulnerabilities. Including the High‑severity  CVE-2026-15354, CVE-2026-75816, CVE-2024-11080 , CVE-2026-11613 and so on.
 
Affected Systems:
 
The affected systems and versions include, but are not limited to:
 
WordPress Plugins: 
  • Frontend Admin by DynamiApps: versions prior to 3.29.12
  • Post-grid: versions prior to 2.2.85 - 2.3.32
  • Hivepress-authentication: versions prior to 1.1.4
  • ACPT (Premium): versions prior to 2.0.66
  • Divi Ajax Filter: versions prior to 5.1.2
 
Security Risks
 
Successful exploitation of these vulnerabilities could allow authenticated attackers to execute arbitrary code, escalate privileges, or inject malicious scripts, leading to compromise of WordPress sites, exposure of sensitive data, and disruption of critical operations.
 
For the full list of security updates released by WordPress, please refer to the official WordPress security releases.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Update vulnerable plugins to their latest patched versions to address these vulnerabilities and reduce the risk of exploitation.
 
The WordPress components versions available for upgrade include, but are not limited to:
 
 
2. Before updating or patching, please ensure that you have the latest backup that can easily be restored.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

08 September 2026

© 2026 National Cyber Security Authority