WPDeeply
Download free plugin

WPDeeply WordPress Security Research

The WPDeeply archive of WordPress plugin vulnerability disclosures.

53
Disclosures
Record Finding
9 Oct 2026 Bricksforge ≤ 3.1.8.9 – Actively Exploited Unauthenticated File Upload to RCE CVE-2026-85097 is an actively exploited, unauthenticated arbitrary file upload vulnerability in Bricksforge 3.1.8.9 and earlier. Update to 3.1.8.10 or later immediately. 8 Oct 2026 Kirki ≤ 6.3.1 – Unauthenticated Stored XSS via Registration Metadata Kirki 6.3.1 and earlier are vulnerable to unauthenticated stored XSS via registration metadata. Update to 6.3.2 and review exposed registration workflows. 7 Oct 2026 Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and… 7 Oct 2026 WordPress Core 7.1.3 – Seven Security Fixes for XSS, SQL Injection, Data Exposure, and DoS WordPress 7.1.3 fixes seven security issues, including stored XSS in comment moderation, unauthenticated private-comment disclosure, WXR export SQL injection, and Imgur oEmbed XSS. Update and clear… 4 Oct 2026 Request a Quote for WooCommerce ≤ 2.9.2 – Unauthenticated Arbitrary File Upload (CVE-2026-18143) CVE-2026-18143 lets unauthenticated attackers upload executable files through the popup quote handler in Request a Quote for WooCommerce 2.9.2 and earlier. Update to 2.9.3 immediately and… 2 Oct 2026 WPMobile.App ≤ 11.82 – Unauthenticated Administrator Account Takeover CVE-2026-94541 is a critical unauthenticated administrator account takeover vulnerability in WPMobile.App ≤ 11.82 when mail-to-push is enabled. Update to 11.85 or newer. 1 Oct 2026 SC WordPress Malware – Self-Healing Backdoor Persistence and Cleanup Sucuri documented SC WordPress malware, a self-healing backdoor that persists across files, database options, shared memory, cron, and database triggers. This guide covers indicators and the… 30 Sep 2026 Ultra Addons for Contact Form 7 ≤ 3.5.50 – Unauthenticated Arbitrary File Upload CVE-2026-82901 is a critical unauthenticated arbitrary file upload vulnerability in Ultra Addons for Contact Form 7 ≤ 3.5.50 when the PDF Generator module is enabled. Update… 28 Sep 2026 miniOrange OTP Login ≤ 5.5.5 – Unauthenticated Administrator Login Bypass CVE-2026-85984 can let unauthenticated attackers take over administrator accounts on miniOrange OTP Login 5.5.5 and earlier under a vulnerable settings combination. Update to 5.5.6. 26 Sep 2026 Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation CVE-2026-62062 lets a crafted link bypass REST nonce validation in Elementor 4.3.0 and 4.3.1, enabling actions permitted to a logged-in victim. Update to 4.3.2. 25 Sep 2026 s2Member ≤ 260814 – Unauthenticated Remote Code Execution CVE-2026-19804 allows unauthenticated remote code execution on specifically configured s2Member sites running version 260814 or earlier. Update to 260829 or newer. 24 Sep 2026 YOP Poll <= 7.0.10 - Administrator Account Takeover via postMessage Origin Validation (CVE-2026-85682) YOP Poll 7.0.10 and earlier can expose an administrator REST nonce through unsafe postMessage origin handling. Update to 7.0.11 or later and review administrator accounts.

WPDeeply has documented WordPress plugin vulnerabilities since 2020. The disclosures below remain at their original URLs, credited to the researcher who found them, with remediation information kept current.

Historical disclosures

Research methodology

Findings are verified against a local reproduction before publication, reported to the vendor first, and published once a patched version is available or the disclosure deadline has passed. Full detail is on the methodology page.

Responsible disclosure

If you have found a vulnerability in a WordPress plugin or theme and want it published here, read responsible disclosure first. Researchers keep their credit; WPDeeply does not claim other people’s findings.

Attribution note

The 2020–2021 disclosures in this archive were researched and published by Slavco Mihajloski (mslavco). WPDeeply’s current operators preserve and maintain that work; they did not discover it.