← all sites

bpg1production

investors.bpgr.com · WordPress 7.0.4 · theme sage-foundation/resources · wpengine

WordPress core 7.0.4 → 7.1
3
critical CVE
2
high CVE
9
updates available
9
total findings
PriorityPluginVersionAdvisoryBreaking riskRecommendation
Critical CVEadvanced-custom-fields-pro
active
6.1.6 → 6.8.10CVE-2024-34762
CVSS 9.9 CRITICAL
+13 more advisories
HIGH
multi-minor jump 6.1.6 -> 6.8.10 (skipped 7 minor releases); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us.
Critical CVEgravityforms
active
2.7.17 → 3.1.1CVE-2025-12352
CVSS 9.8 CRITICAL
+16 more advisories
HIGH
MAJOR version jump 2.7.17 -> 3.1.1 (API/behavior changes expected); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us.
Critical CVEwp-migrate-db-pro
active
2.6.6 → 2.7.11CVE-2024-30225
CVSS 10.0 CRITICAL
MEDIUM
minor version bump 2.6.6 -> 2.7.11
UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us.
High CVEpost-duplicator
active
2.28 → 3.0.16CVE-2026-39474
CVSS 8.8 HIGH
+7 more advisories
HIGH
MAJOR version jump 2.28 -> 3.0.16 (API/behavior changes expected)
UPDATE THIS RUN — known high-severity CVE hits this exact version.
High CVEwordpress-importer
active
0.8.1 → 0.9.6CVE-2024-13889
CVSS 7.2 HIGH
MEDIUM
minor version bump 0.8.1 -> 0.9.6
UPDATE THIS RUN — known high-severity CVE hits this exact version.
Med/Low CVEadvanced-custom-fields-font-awesome
active
4.0.5 → 6.2.0CVE-2026-49044
CVSS 6.5 MEDIUM
+3 more advisories
HIGH
MAJOR version jump 4.0.5 -> 6.2.0 (API/behavior changes expected)
UPDATE — real but lower-severity CVE. Low urgency, still worth clearing.
Med/Low CVEsafe-svg
active
2.1.1 → 2.5.0CVE-2024-8378
CVSS 4.8 MEDIUM
MEDIUM
multi-minor jump 2.1.1 -> 2.5.0 (skipped 4 minor releases)
UPDATE — real but lower-severity CVE. Low urgency, still worth clearing.
Major versiondisable-gutenberg
active
2.9 → 3.3.2HIGH
MAJOR version jump 2.9 -> 3.3.2 (API/behavior changes expected)
HOLD / STAGE FIRST — major jump on a high-blast-radius plugin with no security pressure. Recommend testing on a staging twin before prod.
Routinepost-types-order
active
2.0.5 → 2.5.3MEDIUM
multi-minor jump 2.0.5 -> 2.5.3 (skipped 5 minor releases)
UPDATE — routine maintenance bump, low risk.