indysoftdev1.wpenginepowered.com · WordPress 7.0.4 · theme Indysoft · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| High CVE | updraftplus active | 1.25.6 → 1.26.7 | CVE-2026-10795 CVSS 8.1 HIGH +1 more advisories | HIGH minor version bump 1.25.6 -> 1.26.7; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE THIS RUN — known high-severity CVE hits this exact version. |
| Med/Low CVE | admin-site-enhancements active | 7.9.2 → 9.1.2 | CVE-2026-32423 CVSS 5.4 MEDIUM +4 more advisories | HIGH MAJOR version jump 7.9.2 -> 9.1.2 (API/behavior changes expected) | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Routine | advanced-custom-fields-pro active | 6.4.3 → 6.8.10 | HIGH multi-minor jump 6.4.3 -> 6.8.10 (skipped 4 minor releases); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE WITH CAPTURE — routine bump but on a sitewide-impact plugin; watch the diff closely. |