Security Updates

Workhorse security updates are posted here. Note that we only post high impact / high-CVSS score vulnerabilities here. Low-impact vulnerabilities may not be posted. However, they are still remediated.

  • OptinMonster Tampered Script Incident

    in

    What happened OptinMonster has disclosed a security incident in which an attacker briefly served a tampered version of the JavaScript file that OptinMonster embeds on customer sites. The malicious file was delivered from OptinMonster’s CDN for approximately a few hours on June 12, 2026 (UTC). OptinMonster’s account and customer-data systems were not breached — the…

  • Required WordPress Two-Factor Authentication Update Coming June 16 for some Workhorse clients

    Beginning June 16, 2026, Workhorse will begin transitioning select managed WordPress sites to a new two-factor authentication provider. Many WordPress CMS users already have two-factor authentication enabled today. This update does not remove that requirement. Instead, it changes the plugin used to enforce and manage 2FA on affected sites. As part of this transition, CMS…

  • Copy Fail Vulnerability: What It Is and Why Workhorse Clients Are Protected

    in

    A recently disclosed Linux security vulnerability called Copy Fail, tracked as CVE-2026-31431, has been getting attention because it affects many Linux systems released since 2017. The issue is a local privilege escalation vulnerability, which means it could allow someone who already has limited access to a vulnerable server to gain higher-level, administrator-style access. It is…

  • Workhorse not affected by recent cPanel zero-day vulnerability

    in

    We are aware of the recently disclosed zero-day vulnerability CVE-2026-41940 affecting cPanel and WHM. cPanel is one of the most popular hosting control panels, and therefore this vulnerability affects millions of websites. This vulnerability is a critical authentication bypass issue in cPanel/WHM that could allow an unauthenticated attacker to gain unauthorized access to affected control…

  • High risk Gravity Forms vulnerability (<= 2.9.20) patched for all Workhorse clients

    in

    According to Patchstack, a very high severity (CVSS 9 out of 10) vulnerability was found in versions of <= 2.9.20 of the Gravity Forms plugin. This vulnerability would have allowed users to upload malicious files to your website to run arbitrary code. Thankfully, Workhorse was able to mitigate this within hours of disclosure thanks to…

  • Addressing recent NPM Supply Chain Attacks

    in

    Many of our clients are aware of recent Node Package Manager (NPM) supply chain attacks and so we felt it was appropriate to address our response. First, on September 8, an NPM package maintainer was phished, leading to the compromise of 18 popular NPM packages. Then, just a week later, hundreds of other packages were…

  • SQL Injection Vulnerability in The Events Calendar Plugin (≤ 6.15.1) Patched

    in

    A serious SQL injection vulnerability (CVE-2025-9807) has been discovered in versions 6.15.1 and below of The Events Calendar WordPress plugin. The troubling part is: Because of its severity and the ease of exploitation, this is a high‐priority issue for anyone running a vulnerable version. Source: Patchstack What Workhorse Has Done Here’s how we have you…

  • Elementor versions <=3.29.0 vulnerabilty to cross-site scripting

    in

    Accorinding to Patchstack, both Elementor and Elementor Pro versions <=3.29.0 are vulnerable to cross-site scripting. According to Patchstack: This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. While Elementor is not our preferred solution…

  • Gravity Forms Vulnerability for versions <= 2.9.1.3

    in

    Workhorse relies heavily on the Gravity Forms plugin to implement forms on websites we build and manage, including our own. This means a recent vulnerability disclosed on January 16, 2025 has affected many of our websites. The cross-site scripting vulnerability, affecting versions <= 2.9.1.3, was rated as a 5.4/10 on the CVSS scale, or a…

  • Workhorse websites not affected by critical “Really Simple Security” plugin vulnerability

    in

    Wordfence reported today on a vulnerability in the popular “Really Simple Security” plugin, that they described as, “one of the more serious vulnerabilities that we have reported on in our 12 year history as a security provider for WordPress.“ The vulnerability allows an attacker to easily take full control of a WordPress site. When alerted…