indico2025dev.wpenginepowered.com · WordPress 7.0.4 · theme bootscore-child · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| Critical CVE | wp-security-audit-log active | 5.5.0 → no fix available | CVE-2026-54806 CVSS 9.8 CRITICAL +4 more advisories | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | insert-headers-and-footers active | 2.3.0 → no fix available | CVE-2026-8832 CVSS 8.8 HIGH | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Med/Low CVE | admin-site-enhancements active | 7.9.9 → no fix available | CVE-2026-32423 CVSS 5.4 MEDIUM +3 more advisories | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | smtp2go active | 1.12.2 → no fix available | CVE-2026-7621 CVSS 4.3 MEDIUM | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | wordpress-seo active | 26.0 → no fix available | CVE-2025-14481 CVSS 4.3 MEDIUM +3 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |