Tag

#WordPress

newsHIGH 8.5

CVE-2026-66580: SQL Injection Vulnerability in Product Feed Manager Plugin

A SQL injection vulnerability exists in the Product Feed Manager plugin for WordPress, affecting versions up to 7.12.0. This vulnerability has a CVSS score of 8.5 and could allow an attacker to compromise the confidentiality of the database. Immediate action is required to update to a patched version.

1 source
articleHIGH 8.8

CVE-2026-78295: Unauthenticated Cross-Site Request Forgery (CSRF) in Xagio SEO Plugin

A critical vulnerability, CVE-2026-78295, with a CVSS score of 8.8, was discovered in the Xagio SEO plugin (versions <= 7.1.0.43) for WordPress. This unauthenticated Cross-Site Request Forgery (CSRF) vulnerability allows attackers to perform high-impact actions on affected sites. Although not actively exploited, the vulnerability's severity and potential impact warrant immediate attention. Organizations using the affected plugin versions should apply the available patch (version 7.1.0.44) as soon as possible.

1 source
newsMEDIUM 6.5

CVE-2026-16588: WP Directory Kit Plugin for WordPress Vulnerable to Blind SQL Injection

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL injection via the 'order_by' parameter in versions up to 1.5.4. Authenticated attackers with custom-level access and above can exploit this flaw to extract sensitive information from the database. A CVSS score of 6.5 indicates a medium severity vulnerability.

1 source
articleHIGH 8.1

CVE-2026-19991: Arbitrary File Deletion Vulnerability in UsersWP Plugin for WordPress

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70. This vulnerability allows authenticated attackers with Subscriber-level access and above to delete arbitrary files on the affected site's server, including critical files like wp-config.php. The vulnerability has a CVSS score of 8.1, indicating a high severity. Immediate patching is recommended to prevent potential exploitation.

1 source
newsCRITICAL 9.8

Critical Vulnerability in Drag and Drop File Upload for Elementor Forms Plugin

A critical vulnerability (CVE-2026-18351, CVSS 9.8) exists in the Drag and Drop File Upload for Elementor Forms plugin for WordPress, allowing unauthenticated attackers to upload arbitrary files, including potentially executable files, leading to remote code execution. All versions up to and including 1.6.0 are affected. Immediate action is required to mitigate this vulnerability.

1 source
blogHIGH 7.5

Understanding and Defending Against CVE-2026-18056: Authentication Bypass in HivePress Authentication Plugin

This educational analysis delves into CVE-2026-18056, an authentication bypass vulnerability in the HivePress Authentication plugin for WordPress. The vulnerability allows unauthenticated attackers to authenticate as any existing WordPress user, including administrators, by exploiting the access_token parameter. We will explore the root cause, attack surface, exploitation mechanics, and provide defensive strategies to mitigate this threat.

1 source
articleHIGH 8.8

Critical Vulnerability in SureCart WordPress Plugin Allows Account Takeover

The SureCart WordPress plugin before version 4.6.3 is vulnerable to an account takeover exploit, allowing users with subscriber-level accounts to change the email address of any user, including administrators, and take over their account via a password reset. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected versions are 4.0.0 to 4.6.2, and the recommended fix is to upgrade to version 4.6.3 or later. Organizations using SureCart should prioritize patching to prevent potential account takeovers.

1 source
blogHIGH 8.8

Understanding and Defending Against CVE-2026-19887: PHP Object Injection in Welcart e-Commerce Plugin

CVE-2026-19887 is a PHP Object Injection vulnerability in the Welcart e-Commerce plugin for WordPress, allowing unauthenticated attackers to delete arbitrary files and potentially achieve remote code execution. This vulnerability has a CVSS score of 8.8 and is considered high severity. The vulnerability is caused by the deserialization of untrusted input in the Telecom EDY payment callback.

1 source
articleCRITICAL 9.8

Critical Remote Code Execution Vulnerability in Hummingbird Performance Plugin for WordPress (CVE-2026-83627)

A critical vulnerability (CVE-2026-83627) with a CVSS score of 9.8 has been discovered in the Hummingbird Performance plugin for WordPress. This vulnerability allows unauthenticated attackers to execute arbitrary code on affected sites. The plugin, used for speed optimization, caching, minification, compression, and CDN integration, is vulnerable in all versions up to and including 3.21.0. Exploitation requires the site administrator to have enabled Page Caching with the Debug Log option. Immediate patching is recommended.

1 source
newsHIGH 7.5

Unrestricted File Type Upload Vulnerability in LearnDash LMS Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. Authenticated attackers with subscriber-level access and above can upload arbitrary files, including PHP files, to the server. Immediate action is required to prevent potential Remote Code Execution.

1 source
newsCRITICAL 9.8

Critical Local File Inclusion Vulnerability in Divi Ajax Filter Plugin

The Divi Ajax Filter plugin for WordPress has a critical Local File Inclusion vulnerability (CVE-2026-11613) with a CVSS score of 9.8, affecting all versions up to 5.1.2. Unauthenticated attackers can exploit this vulnerability to execute arbitrary PHP code on the server. Immediate action is required to mitigate this vulnerability.

1 source
blogCRITICAL 9.8

Understanding and Defending Against Unauthenticated Arbitrary File Upload Vulnerability in Developer Tools WordPress Plugin

This educational analysis delves into CVE-2025-9314, a critical vulnerability in the Developer Tools WordPress plugin that allows unauthenticated arbitrary file uploads due to a flaw in the bundled SWFUpload component. With a CVSS score of 9.8, this vulnerability poses a significant risk to WordPress installations using plugin versions up to 1.1.3. The analysis provides an in-depth look at the vulnerability's root cause, attack surface, exploitation mechanics, real-world impact, and essential defensive strategies.

1 source
newsCRITICAL 9.9

Critical Vulnerability in WatchMan-Site7 WordPress Plugin Allows Arbitrary Code Execution

A critical vulnerability (CVE-2026-77009, CVSS 9.9) in the WatchMan-Site7 WordPress plugin through version 4.2.0 allows any authenticated user to execute arbitrary PHP code on the server. This vulnerability is exploitable via a debugging console that does not restrict access. Immediate action is required to protect against potential exploitation.

1 source
articleCRITICAL 10.0

Critical Vulnerability in Embed HTML5 Game WordPress Plugin Allows Unauthenticated PHP Backdoor Uploads

A critical vulnerability, CVE-2026-4357, with a CVSS score of 10, was discovered in the Embed HTML5 Game WordPress plugin (version 1.3 and below). This vulnerability allows unauthenticated attackers to upload PHP backdoors on affected sites, potentially leading to remote code execution, data breaches, and site takeovers. Immediate patching or mitigation is essential to prevent exploitation. The vulnerability has not been actively exploited yet, but its severity and potential impact warrant urgent attention.

1 source
articleCRITICAL 9.8

Critical Vulnerability in SigmaForms Pro – AI Generated Forms Plugin for WordPress: Arbitrary File Deletion

A critical vulnerability, CVE-2026-78657, with a CVSS score of 9.8, was discovered in the SigmaForms Pro – AI Generated Forms plugin for WordPress. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the delete_submission_files function. This can lead to remote code execution when a critical file, such as wp-config.php, is deleted. The vulnerability affects all versions up to and including 1.4.11 of the plugin.

1 source
newsCRITICAL 9.8

Critical Vulnerability in WPLP Cookie Consent Plugin for WordPress

The WPLP Cookie Consent plugin for WordPress has a critical vulnerability (CVE-2026-75865) with a CVSS score of 9.8, allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution. All versions up to 4.4.1 are affected. Immediate action is required to mitigate this vulnerability.

1 source
newsHIGH 8.1

Unauthenticated Remote Code Execution Vulnerability in ProfilePress WordPress Plugin

The ProfilePress WordPress plugin before version 4.17.2 is vulnerable to unauthenticated remote code execution. This vulnerability allows attackers to install and activate arbitrary plugins, potentially leading to PHP code execution as the web-server user. The vulnerability has a CVSS score of 8.1, indicating high severity.

1 source
articleCRITICAL 9.8

Critical Authentication Bypass Vulnerability in MyHome Core WordPress Plugin

A critical authentication bypass vulnerability (CVE-2026-15980) with a CVSS score of 9.8 affects the MyHome Core plugin for WordPress, allowing unauthenticated attackers to generate activation tokens and obtain valid authentication cookies for unconfirmed user accounts, including administrators. This vulnerability exists in all versions up to and including 4.4.5 and requires specific configuration settings to be exploitable. Immediate patching is recommended to prevent potential exploitation.

1 source
blogHIGH 8.1

Understanding and Defending Against CVE-2026-19718: Weak Secret Generation in WordPress Plugins

CVE-2026-19718 is a high-severity vulnerability affecting several WordPress plugins, including BlogVault Backup & Staging, MalCare WordPress Security Plugin, and The WP Remote WordPress Plugin. The vulnerability allows unauthenticated attackers to obtain data derived from a secret binding a site to its remote management service, which is generated using a weak pseudo-random number generator. This enables attackers to recover the secret and gain administrative access to the site. The vulnerability has a CVSS score of 8.1 and is considered high severity.

1 source
blogCRITICAL 9.8

Understanding and Defending Against Unauthenticated Privilege Escalation in Capella Theme

This educational analysis delves into CVE-2025-15689, a critical vulnerability in the Capella theme for WordPress, which allows for unauthenticated privilege escalation. The vulnerability, with a CVSS score of 9.8, affects Capella versions up to 2.5.5 and has significant implications for WordPress site security. Understanding the root cause, attack surface, and exploitation mechanics is crucial for defenders to implement effective mitigations and detections.

1 source
articleCRITICAL 9.8

Critical Vulnerability in JSON Options WordPress Plugin Allows Full Site Takeover

A critical vulnerability, CVE-2026-75860, with a CVSS score of 9.8, was discovered in the JSON Options WordPress plugin (version 0.0.4 and below). This vulnerability allows unauthenticated users to update arbitrary WordPress options, potentially leading to privilege escalation and full site takeover. The plugin's lack of capability checks and nonce verification on one of its actions enables this exploit. Immediate patching or removal of the plugin is recommended.

1 source
blogHIGH 7.2

CVE-2026-17581: Code Injection Vulnerability in WCPOS – Point of Sale (POS) plugin for WooCommerce

The WCPOS – Point of Sale (POS) plugin for WooCommerce is vulnerable to code injection via the 'thermal' template engine. Authenticated attackers with Shop Manager-level access can inject arbitrary PHP code, leading to remote code execution on the server. This vulnerability has a CVSS score of 7.2 and is classified as CWE-94.

1 source
newsHIGH 8.8

CVE-2026-17123: Royal Elementor Addons Plugin for WordPress Server-Side Request Forgery Vulnerability

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.7.1064. An authenticated attacker with Contributor-level access and above can exploit this vulnerability to make web requests to arbitrary locations, potentially querying and modifying information from internal services. The CVSS score for this vulnerability is 8.8, indicating a high severity level.

1 source
articleHIGH 8.8

Critical Vulnerability in Podlove Podcast Publisher Plugin for WordPress: CVE-2026-16099

The Podlove Podcast Publisher plugin for WordPress, versions up to and including 4.5.3, is vulnerable to arbitrary file deletion due to insufficient file path validation. This allows authenticated attackers with contributor-level access to delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is classified as CWE-502 Deserialization. Immediate patching is recommended.

1 source
blogHIGH 8.8

Understanding and Defending Against Arbitrary File Upload Vulnerability in MaxUpload Plugin

The MaxUpload plugin for WordPress is vulnerable to an arbitrary file upload attack due to a filename-validation mismatch. This allows unauthenticated attackers to upload potentially executable files, leading to remote code execution. The vulnerability has a CVSS score of 8.8 and affects all versions up to and including 1.4.0.

1 source
articleHIGH 8.8

CVE-2026-15001: Privilege Escalation in bLoyal: Loyalty & Promotions by bLoyal WordPress Plugin

The bLoyal: Loyalty & Promotions by bLoyal WordPress plugin is vulnerable to Privilege Escalation (CVE-2026-15001, CVSS 8.8) in all versions up to 3.1.611.78. Authenticated attackers with Subscriber-level access can exploit this vulnerability to escalate privileges to Administrator, potentially leading to full site compromise. Immediate patching is recommended.

1 source
blogCRITICAL 9.8

Understanding and Defending Against CVE-2026-13600: Unauthenticated Admin Access in AutoNetTV Relay WordPress Plugin

CVE-2026-13600 is a critical vulnerability in the AutoNetTV Relay WordPress plugin that allows unauthenticated attackers to gain administrator access by exploiting a scheduled content-synchronization task. This vulnerability highlights the importance of secure authentication and authorization in WordPress plugins. Affected versions are before 3.0.14, and an upgrade to this version or later is recommended.

1 source
articleHIGH 8.0

CVE-2026-12971: LearnPress WordPress Plugin SSRF Vulnerability

The LearnPress WordPress plugin before version 4.4.4 is vulnerable to a blind and bounded server-side request forgery (SSRF) attack. This vulnerability allows users with the instructor role to induce the server to issue requests to arbitrary external hosts. The vulnerability has not been actively exploited but poses a significant risk due to its potential for abuse. Organizations using affected versions of the LearnPress plugin should upgrade to version 4.4.4 or later immediately.

1 source
newsCRITICAL 9.8

CVE-2026-14526: Critical Authorization Bypass in AI Copilot – Content Generator WordPress Plugin

The AI Copilot – Content Generator plugin for WordPress has a critical vulnerability (CVE-2026-14526, CVSS 9.8) allowing unauthenticated attackers to create administrator-level user accounts, potentially leading to full site takeover. All versions up to and including 1.5.6 are affected. Immediate action is required to mitigate this vulnerability.

1 source
newsHIGH 8.1

SQL Injection Vulnerability in Content Views WordPress Plugin

A SQL injection vulnerability exists in the Content Views WordPress plugin before version 4.5. An authenticated user, including Subscribers, can exploit this vulnerability to perform SQL injection attacks. The vulnerability has a CVSS score of 8.1, indicating a high severity level.

1 source