WPDeeply
Download free plugin

Plugin Security

How to judge, replace and remove WordPress plugins.

42
Guides
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via Firebase JWT Forgery CVE-2026-13447 affects MStore API Plugin Security 6 Sep 2026, 1 min Hummingbird <= 3.21.0 - Unauthenticated Remote Code Execution via Page Cache Debug Log CVE-2026-83627 affects Hummingbird Plugin Security 5 Sep 2026, 1 min Super Forms <= 6.3.313 - Active Exploitation of Unauthenticated File Upload RCE Wordfence reports active exploitation of CVE-2026-14894 in Super Forms Plugin Security 4 Sep 2026, 1 min Elementor Pro <= 4.2.1 - Active Exploitation IOCs for Arbitrary File Upload RCE Wordfence reports active exploitation of CVE-2026-32475 in Elementor Pro Plugin Security 3 Sep 2026, 1 min 12 Essential WordPress Plugins and Their Hidden Security Risks An essential plugin is still third-party code with database access, admin hooks, AJAX endpoints, and update risk. The safest plugin stack is not the longest one; it is… Plugin Security 2 Sep 2026, 2 min Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload CVE-2026-19513 affects Gravity Forms up to and including 3.0.2. Public forms with a multi-file upload field can expose an unauthenticated arbitrary file upload path through chunk-state validation confusion.… Plugin Security 2 Sep 2026, 1 min Amelia Premium 8.0 – 9.6.2 – Unauthenticated Privilege Escalation to Administrator CVE-2026-9055 affects Amelia Premium versions 8.0 through 9.6.2. An unauthenticated privilege escalation chain can create a wpamelia-manager user and then overwrite an administrator password. Update Amelia Premium to… Plugin Security 2 Sep 2026, 3 min ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update to 4.17.2… Plugin Security 1 Sep 2026, 3 min WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub SSO immediately. Plugin Security 29 Aug 2026, 3 min GiveWP <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Patchstack disclosed CVSS 10.0 unauthenticated PHP Object Injection to RCE in GiveWP. Sites with affected donation flows should update to 4.16.7.2 immediately and review sessions, users, and recent… Plugin Security 29 Aug 2026, 3 min