WPDeeply WordPress Security Research
The WPDeeply archive of WordPress plugin vulnerability disclosures.
WPDeeply has documented WordPress plugin vulnerabilities since 2020. The disclosures below remain at their original URLs, credited to the researcher who found them, with remediation information kept current.
Historical disclosures
- Loginizer < 1.6.4 — unauthenticated SQL injection (CVE-2020-27615)
- Ninja Forms < 3.4.27.1 — CSRF to remote code execution
- Abandoned Cart Lite for WooCommerce ≤ 5.8.2 — unauthenticated SQL injection
- WooCommerce before 4.1.0 — remote code execution
- WordPress Importer — arbitrary post creation
Research methodology
Findings are verified against a local reproduction before publication, reported to the vendor first, and published once a patched version is available or the disclosure deadline has passed. Full detail is on the methodology page.
Responsible disclosure
If you have found a vulnerability in a WordPress plugin or theme and want it published here, read responsible disclosure first. Researchers keep their credit; WPDeeply does not claim other people’s findings.
Attribution note
The 2020–2021 disclosures in this archive were researched and published by Slavco Mihajloski (mslavco). WPDeeply’s current operators preserve and maintain that work; they did not discover it.