WordPress Mass-Takeover Wave: Two CVSS 9.8 Plugin Vulnerabilities Hand Attackers Admin Access to UK SME Websites — The 7-Day Web Stack Audit Plan
Two critical WordPress plugin vulnerabilities disclosed on 4 May 2026 — CVE-2026-5722 in MoreConvert Pro and CVE-2025-13618 in Mentoring — both score the maximum CVSS 9.8 and both hand unauthenticated attackers full administrator control of any affected UK SME website. Mass-scanning is already in progress. Here is the full UK SME decode: the seven-day web stack audit plan, the Cyber Essentials v3.3 auto-fail risk, the GDPR exposure, the realistic cost-of-compromise envelope, and the 10-step rollout for a managed WordPress posture that does not crumble at the next plugin advisory.



