b64dev.wpenginepowered.com · WordPress 7.0.3 · theme bootscore-child · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| High CVE | wp-all-export-pro active | 1.9.1 → no fix available | CVE-2024-7419 CVSS 8.8 HIGH +1 more advisories | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | wp-all-import-pro active | 4.9.0 → no fix available | CVE-2024-9624 CVSS 7.6 HIGH +3 more advisories | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Med/Low CVE | advanced-custom-fields-pro active | 6.3.8 → 6.8.10 | CVE-2024-49593 CVSS 5.3 MEDIUM +1 more advisories | HIGH multi-minor jump 6.3.8 -> 6.8.10 (skipped 5 minor releases); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Med/Low CVE | query-monitor active | 3.16.4 → 4.0.7 | CVE-2026-4267 CVSS | HIGH MAJOR version jump 3.16.4 -> 4.0.7 (API/behavior changes expected) | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Med/Low CVE | simple-banner active | 3.0.3 → 3.3.2 | CVE-2024-13898 CVSS 4.4 MEDIUM +2 more advisories | MEDIUM multi-minor jump 3.0.3 -> 3.3.2 (skipped 3 minor releases) | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Med/Low CVE | wordpress-seo active | 23.6 → 28.5 | CVE-2025-14481 CVSS 4.3 MEDIUM +3 more advisories | HIGH MAJOR version jump 23.6 -> 28.5 (API/behavior changes expected); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Major version | prevent-browser-caching active | 2.3.5 → 3.2.1 | HIGH MAJOR version jump 2.3.5 -> 3.2.1 (API/behavior changes expected) | HOLD / STAGE FIRST — major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod. | |
| Major version | wpae-acf-add-on active | 1.0.5 → 2.0.0 | HIGH MAJOR version jump 1.0.5 -> 2.0.0 (API/behavior changes expected) | HOLD / STAGE FIRST — major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod. | |
| Major version | wpai-acf-add-on active | 3.3.8 → 4.0.2 | HIGH MAJOR version jump 3.3.8 -> 4.0.2 (API/behavior changes expected) | HOLD / STAGE FIRST — major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod. | |
| Routine | megamenu active | 3.3.2 → 3.10.8 | MEDIUM multi-minor jump 3.3.2 -> 3.10.8 (skipped 7 minor releases) | UPDATE — routine maintenance bump, low risk. |