← all sites

nvppantheonarcproduction

nvppantheonarc.wpenginepowered.com · WordPress 7.0.4 · theme nvp · wpengine

WordPress core 7.0.4 → 7.1
3
critical CVE
2
high CVE
7
updates available
8
total findings
PriorityPluginVersionAdvisoryBreaking riskRecommendation
Critical CVEadvanced-custom-fields-pro
active
5.3.8.1 → 6.8.10CVE-2024-34762
CVSS 9.9 CRITICAL
+18 more advisories
HIGH
MAJOR version jump 5.3.8.1 -> 6.8.10 (API/behavior changes expected); HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide
UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us.
Critical CVEcontact-form-7
active
5.0.2 → 6.1.7CVE-2020-35489
CVSS 10.0 CRITICAL
+7 more advisories
HIGH
MAJOR version jump 5.0.2 -> 6.1.7 (API/behavior changes expected)
UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us.
Critical CVEwp-file-manager
inactive
5.4 → 8.0.4CVE-2023-6825
CVSS 9.9 CRITICAL
+8 more advisories
HIGH
MAJOR version jump 5.4 -> 8.0.4 (API/behavior changes expected)
UPDATE — plugin is INACTIVE, near-zero front-end risk. Safe to batch.
High CVEwp-editor
active
1.2.6.3 → 1.2.9.3CVE-2026-3772
CVSS 8.8 HIGH
+7 more advisories
LOW
patch bump 1.2.6.3 -> 1.2.9.3
UPDATE THIS RUN — known high-severity CVE hits this exact version.
High CVEadmin-custom-login
inactive
2.6.1 → 3.6.8CVE-2021-34628
CVSS 8.8 HIGH
+1 more advisories
HIGH
MAJOR version jump 2.6.1 -> 3.6.8 (API/behavior changes expected)
UPDATE — plugin is INACTIVE, near-zero front-end risk. Safe to batch.
Med/Low CVEcontact-form-7-dynamic-text-extension
active
2.0.2.1 → 5.0.7CVE-2025-13146
CVSS 6.5 MEDIUM
+10 more advisories
HIGH
MAJOR version jump 2.0.2.1 -> 5.0.7 (API/behavior changes expected)
UPDATE — real but lower-severity CVE. Low urgency, still worth clearing.
Med/Low CVEpopups
active
1.9.3.1 → no fix availableCVE-2022-2305
CVSS 4.8 MEDIUM
N/A
no update available — nothing to upgrade to
No update offered for this version — likely an expired premium licence or a removed plugin. Worth a look.
Med/Low CVEsvg-support
active
2.3.15 → 2.6.1CVE-2024-10222
CVSS 6.4 MEDIUM
+7 more advisories
MEDIUM
multi-minor jump 2.3.15 -> 2.6.1 (skipped 3 minor releases)
UPDATE — real but lower-severity CVE. Low urgency, still worth clearing.