Security Research
Historical and current WordPress vulnerability disclosures.
36
Guides
Hummingbird <= 3.21.0 - Unauthenticated Remote Code Execution via Page Cache Debug Log
CVE-2026-83627 affects Hummingbird
Super Forms <= 6.3.313 - Active Exploitation of Unauthenticated File Upload RCE
Wordfence reports active exploitation of CVE-2026-14894 in Super Forms
Elementor Pro <= 4.2.1 - Active Exploitation IOCs for Arbitrary File Upload RCE
Wordfence reports active exploitation of CVE-2026-32475 in Elementor Pro
Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload
CVE-2026-19513 affects Gravity Forms up to and including 3.0.2. Public forms with a multi-file upload field can expose an unauthenticated arbitrary file upload path through chunk-state validation confusion.…
Amelia Premium 8.0 – 9.6.2 – Unauthenticated Privilege Escalation to Administrator
CVE-2026-9055 affects Amelia Premium versions 8.0 through 9.6.2. An unauthenticated privilege escalation chain can create a wpamelia-manager user and then overwrite an administrator password. Update Amelia Premium to…
ProfilePress < 4.17.2 - Unauthenticated Arbitrary Plugin Installation RCE
CVE-2026-66047 affects ProfilePress before 4.17.2. A weak 32-bit connect token in the unauthenticated ppress_connect_process AJAX handler can allow arbitrary plugin installation and PHP code execution. Update to 4.17.2…
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via Hub SSO HMAC Confusion
CVE-2026-76581 is a critical WPMU DEV Dashboard authentication bypass affecting sites with Hub SSO enabled and mapped to an administrator. Update to 5.0.2 or disable Hub SSO immediately.
GiveWP <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution
Patchstack disclosed CVSS 10.0 unauthenticated PHP Object Injection to RCE in GiveWP. Sites with affected donation flows should update to 4.16.7.2 immediately and review sessions, users, and recent…
Ultimate Member 2.6.7 – 2.12.1 – Unauthenticated Privilege Escalation via Profile Form Role Field
WPScan published a new high-severity Ultimate Member vulnerability on August 26, 2026. Versions 2.6.7 through 2.12.1 are affected by unauthenticated privilege escalation through the profile form role field.…
TranslatePress <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
CVE-2026-19632 is a critical TranslatePress vulnerability that can expose administrator password reset links from secondary-language dictionary tables. Update to 3.3.2 or newer immediately; WordPress.org currently lists 3.3.4.