WPDeeply
Download free plugin

WPdeeply

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.

69 published guides
s2Member ≤ 260814 – Unauthenticated Remote Code Execution CVE-2026-19804 allows unauthenticated remote code execution on specifically configured s2Member sites running version 260814 or earlier. Update to 260829 or newer. Plugin Security 25 Sep 2026, 4 min YOP Poll <= 7.0.10 - Administrator Account Takeover via postMessage Origin Validation (CVE-2026-85682) YOP Poll 7.0.10 and earlier can expose an administrator REST nonce through unsafe postMessage origin handling. Update to 7.0.11 or later and review administrator accounts. Plugin Security 24 Sep 2026, 2 min Visual Composer <= 45.16.0 - Unauthenticated Local File Inclusion (CVE-2026-12227) Visual Composer Website Builder 45.16.0 and earlier permits unauthenticated local file inclusion through the vcv-template parameter. Update to 45.16.1 or later immediately. Plugin Security 24 Sep 2026, 2 min HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion (CVE-2026-92969) HUSKY Products Filter for WooCommerce 1.4.4 and earlier permits unauthenticated local PHP file inclusion through its AJAX product rendering path. Update to 1.4.5 or later. Plugin Security 23 Sep 2026, 2 min WordPress Core <= 7.1.1 - Unauthenticated Path Traversal and Local File Inclusion (CVE-2026-87902) WordPress Core through 7.1.1 contains an unauthenticated template path-traversal flaw that can include local PHP files and lead to RCE on compatible theme/server configurations. Update to 7.1.2 or… Plugin Security 23 Sep 2026, 2 min 11 Secure WordPress Development Best Practices to Prevent CVEs Most WordPress CVEs are not mysterious. They come from trusting input, skipping capability checks, forgetting nonces, unsafe SQL, unsafe output, or file handling that assumes too much. Hardening 21 Sep 2026, 2 min Forminator Forms <= 1.57.2 - Unauthenticated Shortcode Execution (CVE-2026-92229) Forminator Forms 1.57.2 and earlier can process untrusted current_url input as WordPress shortcodes. Update to 1.57.3 or later and review exposed forms and logs. Plugin Security 21 Sep 2026, 2 min Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden Field (CVE-2026-84434) Gravity Forms 3.1.0.4 and earlier can accept an arbitrary upload through a hidden File Upload field on a public form. Update to 3.1.1 or later and inspect upload… Plugin Security 21 Sep 2026, 3 min Tutor LMS <= 4.0.7 - Subscriber+ PHP Object Injection to RCE (CVE-2026-78175) CVE-2026-78175 allows subscriber-level attackers to reach PHP Object Injection and remote code execution in Tutor LMS 4.0.7 and earlier. Update to 4.0.8 or later. Plugin Security 19 Sep 2026, 4 min WordPress Core <= 7.1 - 11 Security Fixes Including Stored XSS and Click2Shell WordPress 7.1.1 fixes 11 security issues, including CVE-2026-93485 stored XSS and the Click2Shell crafted-URL chain. Update WordPress Core immediately. Security News 19 Sep 2026, 4 min