Wordfence has released security updates for Multiple critical vulnerabilities have been identified in WordPress plugins, including unauthenticated account takeover and hook injection vulnerabilities. Including the High‑severity CVE-2026-15354, CVE-2026-75816, CVE-2024-11080 , CVE-2026-11613 and so on.
Affected Systems:
The affected systems and versions include, but are not limited to:
WordPress Plugins:
Frontend Admin by DynamiApps: versions prior to 3.29.12
Post-grid: versions prior to 2.2.85 - 2.3.32
Hivepress-authentication: versions prior to 1.1.4
ACPT (Premium): versions prior to 2.0.66
Divi Ajax Filter: versions prior to 5.1.2
Security Risks
Successful exploitation of these vulnerabilities could allow authenticated attackers to execute arbitrary code, escalate privileges, or inject malicious scripts, leading to compromise of WordPress sites, exposure of sensitive data, and disruption of critical operations.
For the full list of security updates released by WordPress, please refer to the official WordPress security releases.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
1. Update vulnerable plugins to their latest patched versions to address these vulnerabilities and reduce the risk of exploitation.
The WordPress components versions available for upgrade include, but are not limited to:
Frontend Admin by DynamiApps: Upgrade to version 3.29.13 or above