Security Research
Historical and current WordPress vulnerability disclosures.
30
Guides
The Events Calendar <= 6.17.4 - Unauthenticated RCE via Widget Instance Handling
CVE-2026-78006 and CVE-2026-78159 affect The Events Calendar. Update to 6.17.4.1 or later immediately.
Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload
CVE-2026-18351 affects Drag and Drop File Upload for Elementor Forms up to version 1.6.0. Unauthenticated attackers may upload dangerous file types through weak validation. Update to 1.6.1 or…
SureCart < 4.6.3 - Subscriber Account Takeover via Customer Update Access Control Flaw
CVE-2026-18480 affects SureCart before 4.6.3. A subscriber-level user can change another user's email address, including an administrator account, and trigger account takeover through password reset. Update SureCart to…
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via Firebase JWT Forgery
CVE-2026-13447 affects MStore API
Hummingbird <= 3.21.0 - Unauthenticated Remote Code Execution via Page Cache Debug Log
CVE-2026-83627 affects Hummingbird
Super Forms <= 6.3.313 - Active Exploitation of Unauthenticated File Upload RCE
Wordfence reports active exploitation of CVE-2026-14894 in Super Forms
Elementor Pro <= 4.2.1 - Active Exploitation IOCs for Arbitrary File Upload RCE
Wordfence reports active exploitation of CVE-2026-32475 in Elementor Pro
Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload
CVE-2026-19513 affects Gravity Forms up to and including 3.0.2. Public forms with a multi-file upload field can expose an unauthenticated arbitrary file upload path through chunk-state validation confusion.…
Amelia Premium 8.0 – 9.6.2 – Unauthenticated Privilege Escalation to Administrator
CVE-2026-9055 affects Amelia Premium versions 8.0 through 9.6.2. An unauthenticated privilege escalation chain can create a wpamelia-manager user and then overwrite an administrator password. Update Amelia Premium to…
ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE
CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update to 4.17.2…