WPdeeply
69 published guides
s2Member ≤ 260814 – Unauthenticated Remote Code Execution
CVE-2026-19804 allows unauthenticated remote code execution on specifically configured s2Member sites running version 260814 or earlier. Update to 260829 or newer.
YOP Poll <= 7.0.10 - Administrator Account Takeover via postMessage Origin Validation (CVE-2026-85682)
YOP Poll 7.0.10 and earlier can expose an administrator REST nonce through unsafe postMessage origin handling. Update to 7.0.11 or later and review administrator accounts.
Visual Composer <= 45.16.0 - Unauthenticated Local File Inclusion (CVE-2026-12227)
Visual Composer Website Builder 45.16.0 and earlier permits unauthenticated local file inclusion through the vcv-template parameter. Update to 45.16.1 or later immediately.
HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion (CVE-2026-92969)
HUSKY Products Filter for WooCommerce 1.4.4 and earlier permits unauthenticated local PHP file inclusion through its AJAX product rendering path. Update to 1.4.5 or later.
WordPress Core <= 7.1.1 - Unauthenticated Path Traversal and Local File Inclusion (CVE-2026-87902)
WordPress Core through 7.1.1 contains an unauthenticated template path-traversal flaw that can include local PHP files and lead to RCE on compatible theme/server configurations. Update to 7.1.2 or…
11 Secure WordPress Development Best Practices to Prevent CVEs
Most WordPress CVEs are not mysterious. They come from trusting input, skipping capability checks, forgetting nonces, unsafe SQL, unsafe output, or file handling that assumes too much.
Forminator Forms <= 1.57.2 - Unauthenticated Shortcode Execution (CVE-2026-92229)
Forminator Forms 1.57.2 and earlier can process untrusted current_url input as WordPress shortcodes. Update to 1.57.3 or later and review exposed forms and logs.
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden Field (CVE-2026-84434)
Gravity Forms 3.1.0.4 and earlier can accept an arbitrary upload through a hidden File Upload field on a public form. Update to 3.1.1 or later and inspect upload…
Tutor LMS <= 4.0.7 - Subscriber+ PHP Object Injection to RCE (CVE-2026-78175)
CVE-2026-78175 allows subscriber-level attackers to reach PHP Object Injection and remote code execution in Tutor LMS 4.0.7 and earlier. Update to 4.0.8 or later.
WordPress Core <= 7.1 - 11 Security Fixes Including Stored XSS and Click2Shell
WordPress 7.1.1 fixes 11 security issues, including CVE-2026-93485 stored XSS and the Click2Shell crafted-URL chain. Update WordPress Core immediately.