WPDeeply
Download free plugin

WPDeeply WordPress Security Research

The WPDeeply archive of WordPress plugin vulnerability disclosures.

30
Disclosures
Record Finding
13 Sep 2026 The Events Calendar <= 6.17.4 - Unauthenticated RCE via Widget Instance Handling CVE-2026-78006 and CVE-2026-78159 affect The Events Calendar. Update to 6.17.4.1 or later immediately. 10 Sep 2026 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload CVE-2026-18351 affects Drag and Drop File Upload for Elementor Forms up to version 1.6.0. Unauthenticated attackers may upload dangerous file types through weak validation. Update to… 8 Sep 2026 SureCart < 4.6.3 - Subscriber Account Takeover via Customer Update Access Control Flaw CVE-2026-18480 affects SureCart before 4.6.3. A subscriber-level user can change another user's email address, including an administrator account, and trigger account takeover through password reset. Update… 6 Sep 2026 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via Firebase JWT Forgery CVE-2026-13447 affects MStore API 5 Sep 2026 Hummingbird <= 3.21.0 - Unauthenticated Remote Code Execution via Page Cache Debug Log CVE-2026-83627 affects Hummingbird 4 Sep 2026 Super Forms <= 6.3.313 - Active Exploitation of Unauthenticated File Upload RCE Wordfence reports active exploitation of CVE-2026-14894 in Super Forms 3 Sep 2026 Elementor Pro <= 4.2.1 - Active Exploitation IOCs for Arbitrary File Upload RCE Wordfence reports active exploitation of CVE-2026-32475 in Elementor Pro 2 Sep 2026 Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload CVE-2026-19513 affects Gravity Forms up to and including 3.0.2. Public forms with a multi-file upload field can expose an unauthenticated arbitrary file upload path through chunk-state… 2 Sep 2026 Amelia Premium 8.0 – 9.6.2 – Unauthenticated Privilege Escalation to Administrator CVE-2026-9055 affects Amelia Premium versions 8.0 through 9.6.2. An unauthenticated privilege escalation chain can create a wpamelia-manager user and then overwrite an administrator password. Update Amelia… 1 Sep 2026 ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update… 29 Aug 2026 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub… 29 Aug 2026 GiveWP <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Patchstack disclosed CVSS 10.0 unauthenticated PHP Object Injection to RCE in GiveWP. Sites with affected donation flows should update to 4.16.7.2 immediately and review sessions, users,…

WPDeeply has documented WordPress plugin vulnerabilities since 2020. The disclosures below remain at their original URLs, credited to the researcher who found them, with remediation information kept current.

Historical disclosures

Research methodology

Findings are verified against a local reproduction before publication, reported to the vendor first, and published once a patched version is available or the disclosure deadline has passed. Full detail is on the methodology page.

Responsible disclosure

If you have found a vulnerability in a WordPress plugin or theme and want it published here, read responsible disclosure first. Researchers keep their credit; WPDeeply does not claim other people’s findings.

Attribution note

The 2020–2021 disclosures in this archive were researched and published by Slavco Mihajloski (mslavco). WPDeeply’s current operators preserve and maintain that work; they did not discover it.