Security Research
Historical and current WordPress vulnerability disclosures.
36
Guides
Tutor LMS <= 4.0.7 - Subscriber+ PHP Object Injection to RCE (CVE-2026-78175)
CVE-2026-78175 allows subscriber-level attackers to reach PHP Object Injection and remote code execution in Tutor LMS 4.0.7 and earlier. Update to 4.0.8 or later.
WordPress Core <= 7.1 - 11 Security Fixes Including Stored XSS and Click2Shell
WordPress 7.1.1 fixes 11 security issues, including CVE-2026-93485 stored XSS and the Click2Shell crafted-URL chain. Update WordPress Core immediately.
How to Perform VAPT Penetration Testing on Your WordPress Site
VAPT has two parts: vulnerability assessment and penetration testing. Most WordPress owners can automate the assessment phase, then reserve manual testing for the risks that actually matter.
Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload
CVE-2026-87796 is a critical unauthenticated arbitrary file upload in Multi Uploader for Gravity Forms 1.1.9 and earlier. No patched release is known; deactivate the plugin and investigate uploads.
All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Credential Storage via Basic Auth Header
CVE-2026-89064 affects All-in-One WP Migration and Backup 7.110 and earlier. Update to 7.111 and review exposed authentication workflows.
WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Active Exploitation of Unauthenticated File Upload RCE
Active attacks are exploiting an unauthenticated file upload flaw in WooCommerce Wholesale Lead Capture 2.0.3.1 and earlier. Update to 2.0.3.2 and investigate for PHP webshells.
The Events Calendar <= 6.17.4 - Unauthenticated RCE via Widget Instance Handling
CVE-2026-78006 and CVE-2026-78159 affect The Events Calendar. Update to 6.17.4.1 or later immediately.
Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload
CVE-2026-18351 affects Drag and Drop File Upload for Elementor Forms up to version 1.6.0. Unauthenticated attackers may upload dangerous file types through weak validation. Update to 1.6.1 or…
SureCart < 4.6.3 - Subscriber Account Takeover via Customer Update Access Control Flaw
CVE-2026-18480 affects SureCart before 4.6.3. A subscriber-level user can change another user's email address, including an administrator account, and trigger account takeover through password reset. Update SureCart to…
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via Firebase JWT Forgery
CVE-2026-13447 affects MStore API