WPDeeply
Download free plugin

Plugin Security

How to judge, replace and remove WordPress plugins.

36
Guides
Amelia Premium 8.0 – 9.6.2 – Unauthenticated Privilege Escalation to Administrator CVE-2026-9055 affects Amelia Premium versions 8.0 through 9.6.2. An unauthenticated privilege escalation chain can create a wpamelia-manager user and then overwrite an administrator password. Update Amelia Premium to… Plugin Security 2 Sep 2026, 3 min ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update to 4.17.2… Plugin Security 1 Sep 2026, 3 min WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub SSO immediately. Plugin Security 29 Aug 2026, 3 min GiveWP <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Patchstack disclosed CVSS 10.0 unauthenticated PHP Object Injection to RCE in GiveWP. Sites with affected donation flows should update to 4.16.7.2 immediately and review sessions, users, and recent… Plugin Security 29 Aug 2026, 3 min WoodMart Theme Security Audit: Known CVEs, Vulnerabilities and Risk Profile WoodMart is a powerful WooCommerce theme, and powerful themes carry a larger attack surface. Your risk depends on the version, bundled plugins, site configuration, and whether updates are… Plugin Security 27 Aug 2026, 2 min Ultimate Member 2.6.7 – 2.12.1 – Unauthenticated Privilege Escalation via Profile Form Role Field WPScan published a new high-severity Ultimate Member vulnerability on August 26, 2026. Versions 2.6.7 through 2.12.1 are affected by unauthenticated privilege escalation through the profile form role field.… Plugin Security 27 Aug 2026, 3 min TranslatePress <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure CVE-2026-19632 is a critical TranslatePress vulnerability that can expose administrator password reset links from secondary-language dictionary tables. Update to 3.3.2 or newer immediately; WordPress.org currently lists 3.3.4. Plugin Security 26 Aug 2026, 3 min Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution CVE-2026-18431 is a critical unauthenticated RCE chain affecting Avada Plugin Security 26 Aug 2026, 3 min Events Manager <= 7.4.0.1 - Multiple Vulnerabilities Disclosed in WordPress Plugin Four Events Manager vulnerabilities were published on August 24, 2026, including Contributor+ SQL injection, unauthenticated information disclosure, reflected XSS, and administrator-level local file inclusion. Update to 7.4.1 or… Plugin Security 25 Aug 2026, 3 min PPWP Password Protect Pages <= 1.9.18 - Contributor+ PHP Object Injection CVE-2026-0551 affects PPWP Password Protect Pages up to 1.9.18. Contributor-level users can inject a PHP object through post_protection_roles; real-world impact depends on whether another plugin or theme exposes… Plugin Security 23 Aug 2026, 3 min