WPDeeply
Download free plugin

Plugin Security

How to judge, replace and remove WordPress plugins.

42
Guides
Forminator Forms <= 1.57.2 - Unauthenticated Shortcode Execution (CVE-2026-92229) Forminator Forms 1.57.2 and earlier can process untrusted current_url input as WordPress shortcodes. Update to 1.57.3 or later and review exposed forms and logs. Plugin Security 21 Sep 2026, 2 min Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden Field (CVE-2026-84434) Gravity Forms 3.1.0.4 and earlier can accept an arbitrary upload through a hidden File Upload field on a public form. Update to 3.1.1 or later and inspect upload… Plugin Security 21 Sep 2026, 3 min Tutor LMS <= 4.0.7 - Subscriber+ PHP Object Injection to RCE (CVE-2026-78175) CVE-2026-78175 allows subscriber-level attackers to reach PHP Object Injection and remote code execution in Tutor LMS 4.0.7 and earlier. Update to 4.0.8 or later. Plugin Security 19 Sep 2026, 4 min Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload CVE-2026-87796 is a critical unauthenticated arbitrary file upload in Multi Uploader for Gravity Forms 1.1.9 and earlier. No patched release is known; deactivate the plugin and investigate uploads. Plugin Security 17 Sep 2026, 3 min All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Credential Storage via Basic Auth Header CVE-2026-89064 affects All-in-One WP Migration and Backup 7.110 and earlier. Update to 7.111 and review exposed authentication workflows. Plugin Security 17 Sep 2026, 3 min WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Active Exploitation of Unauthenticated File Upload RCE Active attacks are exploiting an unauthenticated file upload flaw in WooCommerce Wholesale Lead Capture 2.0.3.1 and earlier. Update to 2.0.3.2 and investigate for PHP webshells. Plugin Security 16 Sep 2026, 4 min The Events Calendar <= 6.17.4 - Unauthenticated RCE via Widget Instance Handling CVE-2026-78006 and CVE-2026-78159 affect The Events Calendar. Update to 6.17.4.1 or later immediately. Plugin Security 13 Sep 2026, 3 min Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload CVE-2026-18351 affects Drag and Drop File Upload for Elementor Forms up to version 1.6.0. Unauthenticated attackers may upload dangerous file types through weak validation. Update to 1.6.1 or… Plugin Security 10 Sep 2026, 2 min Newfold WP Module Data <= 2.9.7 - Authentication Bypass Across Bluehost, HostGator, Web.com and Crazy Domains Plugins CVE-2026-80099 affects several Newfold WordPress plugins that bundle the WP Module Data component. The public records cover WP Plugin Bluehost, WP Plugin HostGator, WP Plugin Web, WP Plugin… Plugin Security 10 Sep 2026, 2 min SureCart < 4.6.3 - Subscriber Account Takeover via Customer Update Access Control Flaw CVE-2026-18480 affects SureCart before 4.6.3. A subscriber-level user can change another user's email address, including an administrator account, and trigger account takeover through password reset. Update SureCart to… Plugin Security 8 Sep 2026, 4 min