← all sites

norwestvpdevdevelopment

norwestvpdev.wpenginepowered.com · WordPress 7.0.4 · theme brand-nav-child-theme · wpengine

2
critical CVE
11
high CVE
0
updates available
24
total findings
PriorityPluginVersionAdvisoryBreaking riskRecommendation
Critical CVEelementor-pro
active
3.23.3 → no fix availableCVE-2026-32475
CVSS 9.0 CRITICAL
+3 more advisories
N/A
no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
Critical CVErevisionary
active
3.6.2 → no fix availableCVE-2026-32539
CVSS 9.3 CRITICAL
+1 more advisories
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEewww-image-optimizer
active
8.1.3 → no fix availableCVE-2026-84773
CVSS 7.2 HIGH
+1 more advisories
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVElink-whisper
active
0.8.0 → no fix availableCVE-2025-11262
CVSS 7.2 HIGH
+7 more advisories
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEmainwp-child
active
5.4.0.4 → no fix availableCVE-2026-27366
CVSS 7.5 HIGH
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEone-user-avatar
active
2.5.0 → no fix availableCVE-2026-18983
CVSS 7.5 HIGH
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVErevslider
active
6.7.18 → no fix availableCVE-2026-6692
CVSS 8.8 HIGH
+8 more advisories
N/A
no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEwp-optimize
active
4.1.1 → no fix availableCVE-2026-7252
CVSS 8.1 HIGH
+2 more advisories
N/A
no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEinsert-headers-and-footers
active
2.2.7 → no fix availableCVE-2026-8832
CVSS 8.8 HIGH
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEwpvivid-backuprestore
active
0.9.114 → no fix availableCVE-2025-5961
CVSS 7.2 HIGH
+9 more advisories
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEcodepress-admin-columns
inactive
4.7.7 → no fix availableCVE-2026-7654
CVSS 8.8 HIGH
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEperfmatters
inactive
2.4.0 → no fix availableCVE-2026-13251
CVSS 7.5 HIGH
+4 more advisories
N/A
no update available — nothing to upgrade to
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
High CVEupdraftplus
inactive
1.25.3 → no fix availableCVE-2026-10795
CVSS 8.1 HIGH
+1 more advisories
N/A
no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently.
Med/Low CVEadmin-site-enhancements
active
7.9.9 → no fix availableCVE-2026-32423
CVSS 5.4 MEDIUM
+3 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEam-lottieplayer
active
3.5.2 → no fix availableCVE-2025-1529
CVSS 6.4 MEDIUM
+1 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEelementor
active
3.23.4 → no fix availableCVE-2024-54444
CVSS 6.5 MEDIUM
+19 more advisories
N/A
no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEsearch-filter-pro
active
2.5.14 → no fix availableCVE-2024-6481
CVSS 4.8 MEDIUM
+1 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEsearch-exclude
active
2.4.7 → no fix availableCVE-2025-2821
CVSS 5.3 MEDIUM
+1 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEsimple-banner
active
3.0.6 → no fix availableCVE-2025-12033
CVSS 4.4 MEDIUM
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEsticky-header-effects-for-elementor
active
1.7.8 → no fix availableCVE-2025-58251
CVSS 4.3 MEDIUM
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEsvg-support
active
2.5.14 → no fix availableCVE-2026-48973
CVSS 4.3 MEDIUM
+1 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEduplicate-post
active
4.5 → no fix availableCVE-2026-53740
CVSS 5.4 MEDIUM
+2 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEwordpress-seo
active
24.8.1 → no fix availableCVE-2025-14481
CVSS 4.3 MEDIUM
+3 more advisories
N/A
no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEwordpress-seo-premium
active
24.8 → no fix availableCVE-2026-10821
CVSS 6.6 MEDIUM
+1 more advisories
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.