Critical Vulnerabilities in WordPress Plugins (CVE-2026-28005, CVE-2026-6235)

This text was generated using artificial intelligence (AI).Update August 8, 2026: In addition, CVE-2026-6235 (CVSS 9.8) was discovered in the Sendmachine for WordPress plugin. This vulnerability also allows unauthenticated privilege escalation. See below for details.

On August 6, 2026, the security provider Patchstack reported a critical vulnerability in the WordPress plugin Kadence WooCommerce Email Designer. The gap is identified by the identifier CVE-2026-28005 was conducted and, according to Patchstack, received a rating of 9.8 (Critical) according to the CVSS standard. It allows attackers to escalate privileges without prior authentication (Unauthenticated Privilege Escalation), enabling them to gain administrative control over affected e-commerce websites.

Are my systems affected? Check now →