WPdeeply
69 published guides
Bricksforge ≤ 3.1.8.9 – Actively Exploited Unauthenticated File Upload to RCE
CVE-2026-85097 is an actively exploited, unauthenticated arbitrary file upload vulnerability in Bricksforge 3.1.8.9 and earlier. Update to 3.1.8.10 or later immediately.
Kirki ≤ 6.3.1 – Unauthenticated Stored XSS via Registration Metadata
Kirki 6.3.1 and earlier are vulnerable to unauthenticated stored XSS via registration metadata. Update to 6.3.2 and review exposed registration workflows.
Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and add persistent…
WordPress Core 7.1.3 – Seven Security Fixes for XSS, SQL Injection, Data Exposure, and DoS
WordPress 7.1.3 fixes seven security issues, including stored XSS in comment moderation, unauthenticated private-comment disclosure, WXR export SQL injection, and Imgur oEmbed XSS. Update and clear caches.
Request a Quote for WooCommerce ≤ 2.9.2 – Unauthenticated Arbitrary File Upload (CVE-2026-18143)
CVE-2026-18143 lets unauthenticated attackers upload executable files through the popup quote handler in Request a Quote for WooCommerce 2.9.2 and earlier. Update to 2.9.3 immediately and inspect uploads…
WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover
CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer.
SC WordPress Malware – Self-Healing Backdoor Persistence and Cleanup
Sucuri documented SC WordPress malware, a self-healing backdoor that persists across files, database options, shared memory, cron, and database triggers. This guide covers indicators and the required cleanup…
Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload
CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update to 3.5.51…
miniOrange OTP Login ≤ 5.5.5 – Unauthenticated Administrator Login Bypass
CVE-2026-85984 can let unauthenticated attackers take over administrator accounts on miniOrange OTP Login 5.5.5 and earlier under a vulnerable settings combination. Update to 5.5.6.
Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation
CVE-2026-62062 lets a crafted link bypass REST nonce validation in Elementor 4.3.0 and 4.3.1, enabling actions permitted to a logged-in victim. Update to 4.3.2.