WordPress Security Guides
WordPress vulnerability news, plugin removals and security releases.
102
Guides
07
Topics
Timely WordPress security coverage: newly disclosed vulnerabilities, plugins pulled from the directory, important security releases and monthly roundups. Evergreen how-to material lives in security guides instead.
Bricksforge ≤ 3.1.8.9 – Actively Exploited Unauthenticated File Upload to RCE
CVE-2026-85097 is an actively exploited, unauthenticated arbitrary file upload vulnerability in Bricksforge 3.1.8.9 and earlier. Update to 3.1.8.10 or later immediately.
Kirki ≤ 6.3.1 – Unauthenticated Stored XSS via Registration Metadata
Kirki 6.3.1 and earlier are vulnerable to unauthenticated stored XSS via registration metadata. Update to 6.3.2 and review exposed registration workflows.
Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and add persistent…
WordPress Core 7.1.3 – Seven Security Fixes for XSS, SQL Injection, Data Exposure, and DoS
WordPress 7.1.3 fixes seven security issues, including stored XSS in comment moderation, unauthenticated private-comment disclosure, WXR export SQL injection, and Imgur oEmbed XSS. Update and clear caches.
Request a Quote for WooCommerce ≤ 2.9.2 – Unauthenticated Arbitrary File Upload (CVE-2026-18143)
CVE-2026-18143 lets unauthenticated attackers upload executable files through the popup quote handler in Request a Quote for WooCommerce 2.9.2 and earlier. Update to 2.9.3 immediately and inspect uploads…
WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover
CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer.
SC WordPress Malware – Self-Healing Backdoor Persistence and Cleanup
Sucuri documented SC WordPress malware, a self-healing backdoor that persists across files, database options, shared memory, cron, and database triggers. This guide covers indicators and the required cleanup…
Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload
CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update to 3.5.51…
miniOrange OTP Login ≤ 5.5.5 – Unauthenticated Administrator Login Bypass
CVE-2026-85984 can let unauthenticated attackers take over administrator accounts on miniOrange OTP Login 5.5.5 and earlier under a vulnerable settings combination. Update to 5.5.6.
Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation
CVE-2026-62062 lets a crafted link bypass REST nonce validation in Elementor 4.3.0 and 4.3.1, enabling actions permitted to a logged-in victim. Update to 4.3.2.
s2Member ≤ 260814 – Unauthenticated Remote Code Execution
CVE-2026-19804 allows unauthenticated remote code execution on specifically configured s2Member sites running version 260814 or earlier. Update to 260829 or newer.
YOP Poll <= 7.0.10 - Administrator Account Takeover via postMessage Origin Validation (CVE-2026-85682)
YOP Poll 7.0.10 and earlier can expose an administrator REST nonce through unsafe postMessage origin handling. Update to 7.0.11 or later and review administrator accounts.