starcutter.com · WordPress 7.1 · theme arki-child · wpengine
| Priority | Plugin | Version | Advisory | Breaking risk | Recommendation |
|---|---|---|---|---|---|
| Critical CVE | wpdatatables active | 6.5.1.6 → 6.5.1.7 | CVE-2026-49080 CVSS 9.3 CRITICAL +2 more advisories | LOW patch bump 6.5.1.6 -> 6.5.1.7 | UPDATE NOW — actively exploitable in the installed version. Do it even though blast radius is high; capture+rollback covers us. |
| High CVE | revslider active | 6.7.58 → no fix available | CVE-2026-6692 CVSS 8.8 HIGH +4 more advisories | N/A no update available — nothing to upgrade to; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | NO FIX AVAILABLE — vulnerable and the vendor has no newer version installed//licensed here. Options: confirm the licence is active (premium plugins stop offering updates when a key lapses), replace the plugin, or accept the risk deliberately. Do NOT ignore silently. |
| Med/Low CVE | really-simple-ssl active | 9.8.1 → 9.8.3 | CVE-2026-82519 CVSS 4.3 MEDIUM | HIGH patch bump 9.8.1 -> 9.8.3; HIGH BLAST RADIUS plugin — touches page rendering / forms / cache sitewide | UPDATE — real but lower-severity CVE. Low urgency, still worth clearing. |
| Routine | all-in-one-wp-migration active | 7.110 → 7.111 | MEDIUM minor version bump 7.110 -> 7.111 | UPDATE — routine maintenance bump, low risk. | |
| Routine | admin-site-enhancements inactive | 9.1.1 → 9.1.2 | LOW patch bump 9.1.1 -> 9.1.2 | UPDATE — plugin is INACTIVE, near-zero front-end risk. Safe to batch. |