Medium 4.3
2026-03-13< 1.9.14
CVE-2026-32386
Minimum safe version
1.9.14
Update to 1.9.14 or later to address 10 fixable vulnerabilities
CVE-2026-32386
Envo Extra <= 1.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-47471
CVE-2024-10770
CVE-2024-5645
CVE-2024-4385
CVE-2024-32456
Envo Extra < 1.8.4 - Cross-Site Request Forgery
WordPress Envo Extra Plugin < 1.8.4 is vulnerable to Cross Site Request Forgery (CSRF)
Envo Extra <= 1.8.3 - Cross-Site Request Forgery