French DGSSI warns of critical vulnerabilities in popular WordPress plugins
France's DGSSI (Direction générale de la sécurité des systèmes d’information), part of the national defense administration, has issued a warning regarding serious security flaws in several widely used WordPress plugins.
In its security bulletin 62021303/26, the DGSSI emphasized that these vulnerabilities could expose websites—including e-commerce platforms and news portals—to cyberattacks if updates are not applied promptly. The agency classified the severity of these flaws as “high,” noting that attackers could gain extended privileges on affected systems.
Among the most affected plugins are WooCommerce, a platform for managing online stores; Ally, designed to improve web accessibility; and wpDiscuz, a popular comment management system. Technical analyses indicate that these vulnerabilities may allow remote code execution (RCE), privilege escalation, and arbitrary file modification, putting both server integrity and user data at risk.
Specific security references include CVE-2026-3891, which could allow attackers to delete or add files and access administrator accounts. Exploitation could compromise databases and expose sensitive user and client information.
The DGSSI has urged administrators in both public institutions and private companies to immediately update affected plugins to secure versions. Recommended practices also include regular software updates, server activity monitoring, and robust database protection to mitigate the risk of cyberattacks and strengthen digital infrastructure security.
-
17:30
-
17:00
-
16:50
-
16:30
-
16:20
-
16:10
-
16:00
-
15:50
-
15:47
-
15:40
-
15:38
-
15:30
-
15:20
-
15:00
-
14:50
-
14:45
-
14:40
-
14:30
-
14:20
-
14:17
-
14:06
-
14:00
-
13:50
-
13:44
-
13:37
-
13:31
-
13:30
-
13:20
-
13:00
-
12:50
-
12:30
-
12:25
-
12:20
-
12:01
-
12:00
-
11:50
-
11:20
-
10:50
-
10:40
-
10:20
-
10:10
-
09:50
-
09:40
-
09:20
-
08:50
-
08:20
-
07:50
-
07:20
-
07:00