High-severity flaw in WP Spell Check — no patch yet, disable the plugin
A high-severity vulnerability (CVE-2026-100506) affects the WP Spell Check plugin. At time of writing, no official vendor patch is available.
What to do
- Disable the plugin now and leave it disabled until the vendor ships a fix.
- There is no safe “wait and see” window for a publicly disclosed flaw with no patch — automated scanners will find exposed installs.
- Re-check for an update before re-enabling, and review the site for compromise indicators in the meantime.
Unpatched-plugin windows are when WAF rules earn their keep: ZeroBreach applies virtual-patch rules at the edge automatically while you wait for the vendor.