WPdeeply
69 published guides
SureCart < 4.6.3 - Subscriber Account Takeover via Customer Update Access Control Flaw
CVE-2026-18480 affects SureCart before 4.6.3. A subscriber-level user can change another user's email address, including an administrator account, and trigger account takeover through password reset. Update SureCart to…
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via Firebase JWT Forgery
CVE-2026-13447 affects MStore API
Hummingbird <= 3.21.0 - Unauthenticated Remote Code Execution via Page Cache Debug Log
CVE-2026-83627 affects Hummingbird
Super Forms <= 6.3.313 - Active Exploitation of Unauthenticated File Upload RCE
Wordfence reports active exploitation of CVE-2026-14894 in Super Forms
Elementor Pro <= 4.2.1 - Active Exploitation IOCs for Arbitrary File Upload RCE
Wordfence reports active exploitation of CVE-2026-32475 in Elementor Pro
12 Essential WordPress Plugins and Their Hidden Security Risks
An essential plugin is still third-party code with database access, admin hooks, AJAX endpoints, and update risk. The safest plugin stack is not the longest one; it is…
Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload
CVE-2026-19513 affects Gravity Forms up to and including 3.0.2. Public forms with a multi-file upload field can expose an unauthenticated arbitrary file upload path through chunk-state validation confusion.…
Amelia Premium 8.0 – 9.6.2 – Unauthenticated Privilege Escalation to Administrator
CVE-2026-9055 affects Amelia Premium versions 8.0 through 9.6.2. An unauthenticated privilege escalation chain can create a wpamelia-manager user and then overwrite an administrator password. Update Amelia Premium to…
ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE
CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update to 4.17.2…
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion
CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub SSO immediately.