WPDeeply
Download free plugin

WPdeeply

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.

69 published guides
Bricksforge ≤ 3.1.8.9 – Actively Exploited Unauthenticated File Upload to RCE CVE-2026-85097 is an actively exploited, unauthenticated arbitrary file upload vulnerability in Bricksforge 3.1.8.9 and earlier. Update to 3.1.8.10 or later immediately. Plugin Security 9 Oct 2026, 4 min Kirki ≤ 6.3.1 – Unauthenticated Stored XSS via Registration Metadata Kirki 6.3.1 and earlier are vulnerable to unauthenticated stored XSS via registration metadata. Update to 6.3.2 and review exposed registration workflows. Plugin Security 8 Oct 2026, 3 min Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and add persistent… Plugin Security 7 Oct 2026, 4 min WordPress Core 7.1.3 – Seven Security Fixes for XSS, SQL Injection, Data Exposure, and DoS WordPress 7.1.3 fixes seven security issues, including stored XSS in comment moderation, unauthenticated private-comment disclosure, WXR export SQL injection, and Imgur oEmbed XSS. Update and clear caches. Plugin Security 7 Oct 2026, 4 min Request a Quote for WooCommerce ≤ 2.9.2 – Unauthenticated Arbitrary File Upload (CVE-2026-18143) CVE-2026-18143 lets unauthenticated attackers upload executable files through the popup quote handler in Request a Quote for WooCommerce 2.9.2 and earlier. Update to 2.9.3 immediately and inspect uploads… Plugin Security 4 Oct 2026, 4 min WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer. Plugin Security 2 Oct 2026, 3 min SC WordPress Malware – Self-Healing Backdoor Persistence and Cleanup Sucuri documented SC WordPress malware, a self-healing backdoor that persists across files, database options, shared memory, cron, and database triggers. This guide covers indicators and the required cleanup… Plugin Security 1 Oct 2026, 6 min Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update to 3.5.51… Plugin Security 30 Sep 2026, 3 min miniOrange OTP Login ≤ 5.5.5 – Unauthenticated Administrator Login Bypass CVE-2026-85984 can let unauthenticated attackers take over administrator accounts on miniOrange OTP Login 5.5.5 and earlier under a vulnerable settings combination. Update to 5.5.6. Plugin Security 28 Sep 2026, 3 min Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation CVE-2026-62062 lets a crafted link bypass REST nonce validation in Elementor 4.3.0 and 4.3.1, enabling actions permitted to a logged-in victim. Update to 4.3.2. Plugin Security 26 Sep 2026, 4 min