WPDeeply
Download free plugin

WPDeeply WordPress Security Research

The WPDeeply archive of WordPress plugin vulnerability disclosures.

20
Disclosures
Record Finding
29 Aug 2026 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub… 29 Aug 2026 GiveWP <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Patchstack disclosed CVSS 10.0 unauthenticated PHP Object Injection to RCE in GiveWP. Sites with affected donation flows should update to 4.16.7.2 immediately and review sessions, users,… 27 Aug 2026 Ultimate Member 2.6.7 – 2.12.1 – Unauthenticated Privilege Escalation via Profile Form Role Field WPScan published a new high-severity Ultimate Member vulnerability on August 26, 2026. Versions 2.6.7 through 2.12.1 are affected by unauthenticated privilege escalation through the profile form… 26 Aug 2026 TranslatePress <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure CVE-2026-19632 is a critical TranslatePress vulnerability that can expose administrator password reset links from secondary-language dictionary tables. Update to 3.3.2 or newer immediately; WordPress.org currently lists… 26 Aug 2026 Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution CVE-2026-18431 is a critical unauthenticated RCE chain affecting Avada 25 Aug 2026 Events Manager <= 7.4.0.1 - Multiple Vulnerabilities Disclosed in WordPress Plugin Four Events Manager vulnerabilities were published on August 24, 2026, including Contributor+ SQL injection, unauthenticated information disclosure, reflected XSS, and administrator-level local file inclusion. Update to… 23 Aug 2026 PPWP Password Protect Pages <= 1.9.18 - Contributor+ PHP Object Injection CVE-2026-0551 affects PPWP Password Protect Pages up to 1.9.18. Contributor-level users can inject a PHP object through post_protection_roles; real-world impact depends on whether another plugin or… 23 Aug 2026 Security Hardener <= 2.4.4 - Subscriber+ Privilege Escalation via REST Users Permission Callback CVE-2026-16149 is a high-severity Security Hardener flaw where user-enumeration protection can overwrite WordPress REST user endpoint capability checks, allowing Subscriber-level users to perform privileged user actions.… 22 Aug 2026 Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router CVE-2026-19598 is a critical Pods authorization bypass that can let unauthenticated attackers reach administrator methods, overwrite user passwords, or obtain administrator privileges. Update to 3.3.9.1 or… 22 Aug 2026 miniOrange SAML Single Sign On – Unauthenticated Authentication Bypass Across Seven Editions Two miniOrange SAML Single Sign On flaws can let unauthenticated attackers sign in as existing WordPress users, including administrators. Paid editions need manual version checks because… 9 Aug 2026 WordPress Security Testing (2026 Update) Short answer: you can’t verify a WordPress security vendor’s claims by reading their marketing page — you verify them by checking what’s actually testable: their CVE… 11 Mar 2021 WordPress Importer — Arbitrary Post Creation The official WordPress Importer accepts a structured file and creates content from it. WPDeeply’s 2021 disclosure examined what happens when the file is not trustworthy.

WPDeeply has documented WordPress plugin vulnerabilities since 2020. The disclosures below remain at their original URLs, credited to the researcher who found them, with remediation information kept current.

Historical disclosures

Research methodology

Findings are verified against a local reproduction before publication, reported to the vendor first, and published once a patched version is available or the disclosure deadline has passed. Full detail is on the methodology page.

Responsible disclosure

If you have found a vulnerability in a WordPress plugin or theme and want it published here, read responsible disclosure first. Researchers keep their credit; WPDeeply does not claim other people’s findings.

Attribution note

The 2020–2021 disclosures in this archive were researched and published by Slavco Mihajloski (mslavco). WPDeeply’s current operators preserve and maintain that work; they did not discover it.