WordPress Plugin Security Roundup: August 2026
A 9.0 unauthenticated file-upload-to-RCE in Elementor Pro, a 9.8 flaw on 600,000 Forminator sites, plus two more criticals — every one of them patched weeks before the details went public. August's lesson is the patch gap, not the CVSS score.