toolingtechgroup.com · WordPress 7.1 · theme infinite-child · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| Critical CVE | woocommerce active | 11.1.0 → no fix available | CVE-2022-50972 CVSS 9.8 CRITICAL | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Critical CVE | wpdatatables active | 6.5.1.7 → no fix available | CVE-2026-49080 CVSS 9.3 CRITICAL +2 more advisories | N/A no update available — nothing to upgrade to | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| High CVE | revslider active | 6.7.58 → no fix available | CVE-2026-6692 CVSS 8.8 HIGH +4 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Routine | woocommerce-jetpack active | 8.3.0 → 8.4.0 | MEDIUM minor version bump 8.3.0 -> 8.4.0 | UPDATE — routine maintenance bump, low risk. | |
| Routine | wordpress-seo active | 28.4 → 28.5 | HIGH minor version bump 28.4 -> 28.5; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE WITH CAPTURE — routine bump but on a sitewide-impact plugin; watch the diff closely. |