storylinedev.wpenginepowered.com · WordPress 7.0.4 · theme hazel · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| Critical CVE | simply-gallery-block active | 2.2.6 → no fix available | CVE-2026-25345 CVSS 9.9 CRITICAL +12 more advisories | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Critical CVE | woocommerce active | 9.1.3 → no fix available | CVE-2022-50972 CVSS 9.8 CRITICAL +8 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | cubeportfolio active | 1.16.8 → no fix available | CVE-2025-52823 CVSS 8.5 HIGH | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | revslider active | 6.7.18 → no fix available | CVE-2026-6692 CVSS 8.8 HIGH +8 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | Ultimate_VC_Addons active | 3.16.19 → no fix available | CVE-2023-46205 CVSS 7.1 HIGH +8 more advisories | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | updraftplus active | 1.25.1 → no fix available | CVE-2026-10795 CVSS 8.1 HIGH +1 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | insert-headers-and-footers active | 2.2.6 → no fix available | CVE-2026-8832 CVSS 8.8 HIGH | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | wpforms-lite active | 1.9.2.3 → no fix available | CVE-2026-40764 CVSS 8.1 HIGH +10 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Med/Low CVE | contact-form-7 active | 6.0 → no fix available | CVE-2025-3247 CVSS 5.3 MEDIUM | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | enable-jquery-migrate-helper active | 1.3.0 → no fix available | CVE-2026-3279 CVSS 6.5 MEDIUM | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | jetpack active | 13.8.2 → no fix available | CVE-2024-10858 CVSS 6.1 MEDIUM +2 more advisories | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | google-site-kit active | 1.45.0 → no fix available | CVE-2026-62139 CVSS 4.3 MEDIUM +1 more advisories | N/A no update available — nothing to upgrade to | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |
| Med/Low CVE | wordpress-seo active | 22.7 → no fix available | CVE-2025-14481 CVSS 4.3 MEDIUM +3 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look. |