WPDeeply
Download free plugin

WordPress Security Guides

WordPress vulnerability news, plugin removals and security releases.

102
Guides
07
Topics

Timely WordPress security coverage: newly disclosed vulnerabilities, plugins pulled from the directory, important security releases and monthly roundups. Evergreen how-to material lives in security guides instead.

Bricksforge ≤ 3.1.8.9 – Actively Exploited Unauthenticated File Upload to RCE CVE-2026-85097 is an actively exploited, unauthenticated arbitrary file upload vulnerability in Bricksforge 3.1.8.9 and earlier. Update to 3.1.8.10 or later immediately. Plugin Security 9 Oct 2026, 4 min Kirki ≤ 6.3.1 – Unauthenticated Stored XSS via Registration Metadata Kirki 6.3.1 and earlier are vulnerable to unauthenticated stored XSS via registration metadata. Update to 6.3.2 and review exposed registration workflows. Plugin Security 8 Oct 2026, 3 min Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and add persistent… Plugin Security 7 Oct 2026, 4 min WordPress Core 7.1.3 – Seven Security Fixes for XSS, SQL Injection, Data Exposure, and DoS WordPress 7.1.3 fixes seven security issues, including stored XSS in comment moderation, unauthenticated private-comment disclosure, WXR export SQL injection, and Imgur oEmbed XSS. Update and clear caches. Plugin Security 7 Oct 2026, 4 min Request a Quote for WooCommerce ≤ 2.9.2 – Unauthenticated Arbitrary File Upload (CVE-2026-18143) CVE-2026-18143 lets unauthenticated attackers upload executable files through the popup quote handler in Request a Quote for WooCommerce 2.9.2 and earlier. Update to 2.9.3 immediately and inspect uploads… Plugin Security 4 Oct 2026, 4 min WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer. Plugin Security 2 Oct 2026, 3 min SC WordPress Malware – Self-Healing Backdoor Persistence and Cleanup Sucuri documented SC WordPress malware, a self-healing backdoor that persists across files, database options, shared memory, cron, and database triggers. This guide covers indicators and the required cleanup… Plugin Security 1 Oct 2026, 6 min Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update to 3.5.51… Plugin Security 30 Sep 2026, 3 min miniOrange OTP Login ≤ 5.5.5 – Unauthenticated Administrator Login Bypass CVE-2026-85984 can let unauthenticated attackers take over administrator accounts on miniOrange OTP Login 5.5.5 and earlier under a vulnerable settings combination. Update to 5.5.6. Plugin Security 28 Sep 2026, 3 min Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation CVE-2026-62062 lets a crafted link bypass REST nonce validation in Elementor 4.3.0 and 4.3.1, enabling actions permitted to a logged-in victim. Update to 4.3.2. Plugin Security 26 Sep 2026, 4 min s2Member ≤ 260814 – Unauthenticated Remote Code Execution CVE-2026-19804 allows unauthenticated remote code execution on specifically configured s2Member sites running version 260814 or earlier. Update to 260829 or newer. Plugin Security 25 Sep 2026, 4 min YOP Poll <= 7.0.10 - Administrator Account Takeover via postMessage Origin Validation (CVE-2026-85682) YOP Poll 7.0.10 and earlier can expose an administrator REST nonce through unsafe postMessage origin handling. Update to 7.0.11 or later and review administrator accounts. Plugin Security 24 Sep 2026, 2 min