Security Research
Historical and current WordPress vulnerability disclosures.
54
Guides
Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation
CVE-2026-62062 lets a crafted link bypass REST nonce validation in Elementor 4.3.0 and 4.3.1, enabling actions permitted to a logged-in victim. Update to 4.3.2.
s2Member ≤ 260814 – Unauthenticated Remote Code Execution
CVE-2026-19804 allows unauthenticated remote code execution on specifically configured s2Member sites running version 260814 or earlier. Update to 260829 or newer.
YOP Poll <= 7.0.10 - Administrator Account Takeover via postMessage Origin Validation (CVE-2026-85682)
YOP Poll 7.0.10 and earlier can expose an administrator REST nonce through unsafe postMessage origin handling. Update to 7.0.11 or later and review administrator accounts.
Visual Composer <= 45.16.0 - Unauthenticated Local File Inclusion (CVE-2026-12227)
Visual Composer Website Builder 45.16.0 and earlier permits unauthenticated local file inclusion through the vcv-template parameter. Update to 45.16.1 or later immediately.
HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion (CVE-2026-92969)
HUSKY Products Filter for WooCommerce 1.4.4 and earlier permits unauthenticated local PHP file inclusion through its AJAX product rendering path. Update to 1.4.5 or later.
WordPress Core <= 7.1.1 - Unauthenticated Path Traversal and Local File Inclusion (CVE-2026-87902)
WordPress Core through 7.1.1 contains an unauthenticated template path-traversal flaw that can include local PHP files and lead to RCE on compatible theme/server configurations. Update to 7.1.2 or…
Forminator Forms <= 1.57.2 - Unauthenticated Shortcode Execution (CVE-2026-92229)
Forminator Forms 1.57.2 and earlier can process untrusted current_url input as WordPress shortcodes. Update to 1.57.3 or later and review exposed forms and logs.
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden Field (CVE-2026-84434)
Gravity Forms 3.1.0.4 and earlier can accept an arbitrary upload through a hidden File Upload field on a public form. Update to 3.1.1 or later and inspect upload…
Tutor LMS <= 4.0.7 - Subscriber+ PHP Object Injection to RCE (CVE-2026-78175)
CVE-2026-78175 allows subscriber-level attackers to reach PHP Object Injection and remote code execution in Tutor LMS 4.0.7 and earlier. Update to 4.0.8 or later.
WordPress Core <= 7.1 - 11 Security Fixes Including Stored XSS and Click2Shell
WordPress 7.1.1 fixes 11 security issues, including CVE-2026-93485 stored XSS and the Click2Shell crafted-URL chain. Update WordPress Core immediately.