WPDeeply
Download free plugin

WPdeeply

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.

43 published guides
The Events Calendar <= 6.17.4 - Unauthenticated RCE via Widget Instance Handling CVE-2026-78006 and CVE-2026-78159 affect The Events Calendar. Update to 6.17.4.1 or later immediately. Plugin Security 13 Sep 2026, 3 min Why WordPress Maintenance Is Actually Security Maintenance If your maintenance plan does not include vulnerability patching, abandoned plugin detection, and component risk review, it is not maintenance. It is delay. Hardening 10 Sep 2026, 2 min Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload CVE-2026-18351 affects Drag and Drop File Upload for Elementor Forms up to version 1.6.0. Unauthenticated attackers may upload dangerous file types through weak validation. Update to 1.6.1 or… Plugin Security 10 Sep 2026, 2 min Newfold WP Module Data <= 2.9.7 - Authentication Bypass Across Bluehost, HostGator, Web.com and Crazy Domains Plugins CVE-2026-80099 affects several Newfold WordPress plugins that bundle the WP Module Data component. The public records cover WP Plugin Bluehost, WP Plugin HostGator, WP Plugin Web, WP Plugin… Plugin Security 10 Sep 2026, 2 min SureCart < 4.6.3 - Subscriber Account Takeover via Customer Update Access Control Flaw CVE-2026-18480 affects SureCart before 4.6.3. A subscriber-level user can change another user's email address, including an administrator account, and trigger account takeover through password reset. Update SureCart to… Plugin Security 8 Sep 2026, 4 min MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via Firebase JWT Forgery CVE-2026-13447 affects MStore API Plugin Security 6 Sep 2026, 1 min Hummingbird <= 3.21.0 - Unauthenticated Remote Code Execution via Page Cache Debug Log CVE-2026-83627 affects Hummingbird Plugin Security 5 Sep 2026, 1 min Super Forms <= 6.3.313 - Active Exploitation of Unauthenticated File Upload RCE Wordfence reports active exploitation of CVE-2026-14894 in Super Forms Plugin Security 4 Sep 2026, 1 min Elementor Pro <= 4.2.1 - Active Exploitation IOCs for Arbitrary File Upload RCE Wordfence reports active exploitation of CVE-2026-32475 in Elementor Pro Plugin Security 3 Sep 2026, 1 min 12 Essential WordPress Plugins and Their Hidden Security Risks An essential plugin is still third-party code with database access, admin hooks, AJAX endpoints, and update risk. The safest plugin stack is not the longest one; it is… Plugin Security 2 Sep 2026, 2 min