nvppantheonarc.wpenginepowered.com · WordPress 7.0.4 · theme nvp · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| Critical CVE | advanced-custom-fields-pro active | 5.3.8.1 → 6.8.10 | CVE-2024-34762 CVSS 9.9 CRITICAL +18 more advisories | HIGH MAJOR version jump 5.3.8.1 -> 6.8.10 (API/behavior changes expected); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us. |
| Critical CVE | contact-form-7 active | 5.0.2 → 6.1.7 | CVE-2020-35489 CVSS 10.0 CRITICAL +7 more advisories | HIGH MAJOR version jump 5.0.2 -> 6.1.7 (API/behavior changes expected) | UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us. |
| Critical CVE | wp-file-manager inactive | 5.4 → 8.0.4 | CVE-2023-6825 CVSS 9.9 CRITICAL +8 more advisories | HIGH MAJOR version jump 5.4 -> 8.0.4 (API/behavior changes expected) | UPDATE — plugin is INACTIVE, near-zero front-end risk. Safe to batch. |
| High CVE | wp-editor active | 1.2.6.3 → 1.2.9.3 | CVE-2026-3772 CVSS 8.8 HIGH +7 more advisories | LOW patch bump 1.2.6.3 -> 1.2.9.3 | UPDATE THIS RUN — known high-severity CVE hits this exact version. |
| High CVE | admin-custom-login inactive | 2.6.1 → 3.6.8 | CVE-2021-34628 CVSS 8.8 HIGH +1 more advisories | HIGH MAJOR version jump 2.6.1 -> 3.6.8 (API/behavior changes expected) | UPDATE — plugin is INACTIVE, near-zero front-end risk. Safe to batch. |
| Med/Low CVE | contact-form-7-dynamic-text-extension active | 2.0.2.1 → 5.0.7 | CVE-2025-13146 CVSS 6.5 MEDIUM +10 more advisories | HIGH MAJOR version jump 2.0.2.1 -> 5.0.7 (API/behavior changes expected) | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Med/Low CVE | popups active | 1.9.3.1 → no fix available | CVE-2022-2305 CVSS 4.8 MEDIUM | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | svg-support active | 2.3.15 → 2.6.1 | CVE-2024-10222 CVSS 6.4 MEDIUM +7 more advisories | MEDIUM multi-minor jump 2.3.15 -> 2.6.1 (skipped 3 minor releases) | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |