Plugin Security
How to judge, replace and remove WordPress plugins.
22
Guides
WoodMart Theme Security Audit: Known CVEs, Vulnerabilities and Risk Profile
WoodMart is a powerful WooCommerce theme, and powerful themes carry a larger attack surface. Your risk depends on the version, bundled plugins, site configuration, and whether updates are…
Ultimate Member 2.6.7 – 2.12.1 – Unauthenticated Privilege Escalation via Profile Form Role Field
WPScan published a new high-severity Ultimate Member vulnerability on August 26, 2026. Versions 2.6.7 through 2.12.1 are affected by unauthenticated privilege escalation through the profile form role field.…
TranslatePress <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
CVE-2026-19632 is a critical TranslatePress vulnerability that can expose administrator password reset links from secondary-language dictionary tables. Update to 3.3.2 or newer immediately; WordPress.org currently lists 3.3.4.
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution
CVE-2026-18431 is a critical unauthenticated RCE chain affecting Avada
Events Manager <= 7.4.0.1 - Multiple Vulnerabilities Disclosed in WordPress Plugin
Four Events Manager vulnerabilities were published on August 24, 2026, including Contributor+ SQL injection, unauthenticated information disclosure, reflected XSS, and administrator-level local file inclusion. Update to 7.4.1 or…
PPWP Password Protect Pages <= 1.9.18 - Contributor+ PHP Object Injection
CVE-2026-0551 affects PPWP Password Protect Pages up to 1.9.18. Contributor-level users can inject a PHP object through post_protection_roles; real-world impact depends on whether another plugin or theme exposes…
Security Hardener <= 2.4.4 - Subscriber+ Privilege Escalation via REST Users Permission Callback
CVE-2026-16149 is a high-severity Security Hardener flaw where user-enumeration protection can overwrite WordPress REST user endpoint capability checks, allowing Subscriber-level users to perform privileged user actions. Update to…
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router
CVE-2026-19598 is a critical Pods authorization bypass that can let unauthenticated attackers reach administrator methods, overwrite user passwords, or obtain administrator privileges. Update to 3.3.9.1 or a backported…
miniOrange SAML Single Sign On – Unauthenticated Authentication Bypass Across Seven Editions
Two miniOrange SAML Single Sign On flaws can let unauthenticated attackers sign in as existing WordPress users, including administrators. Paid editions need manual version checks because the normal…
Elementor Pro <= 4.2.1 - Unauthenticated Arbitrary File Upload to RCE
Elementor Pro versions up to 4.2.1 contain a critical unauthenticated arbitrary file upload vulnerability in the Forms module. Update to 4.2.2 or later and inspect Elementor form upload…