
🔴 WP ALERT — April 6, 2026 4 active CVEs. Act today: 🔴 W3 Total Cache CVE-2026-27384 (CVSS 9.8) — RCE, no login needed → update to 2.9.2 🔴 Royal Elementor CVE-2026-28135 — no reliable patch → DELETE it 🟠 Gutenverse CVE-2026-2924 — Stored XSS → update to 3.4.7 🟠 Ally CVE-2026-2413 — blind SQLi, unauthenticated → update to 4.0.4+ Exploits hit in 5hrs median. SwissWPSuite WAF + Sentinel blocks 3 of 4. Royal Elementor must be deleted — we tell you the truth. Full brief → https://swisswpsecure.com/%f0%9f%94%b4-wordpress-security-alert-april-6-2026-4-active-threats-you-must-act-on-today/ #WPSec #WordPress 🛡️
Post summary
The alert announces four active WordPress CVEs, provides patches or deletions, and notes that exploits are underway in the wild.


