WPDeeply
Download free plugin

Security Research

Historical and current WordPress vulnerability disclosures.

38
Guides
Ultimate Member 2.6.7 – 2.12.1 – Unauthenticated Privilege Escalation via Profile Form Role Field WPScan published a new high-severity Ultimate Member vulnerability on August 26, 2026. Versions 2.6.7 through 2.12.1 are affected by unauthenticated privilege escalation through the profile form role field.… Plugin Security 27 Aug 2026, 3 min TranslatePress <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure CVE-2026-19632 is a critical TranslatePress vulnerability that can expose administrator password reset links from secondary-language dictionary tables. Update to 3.3.2 or newer immediately; WordPress.org currently lists 3.3.4. Plugin Security 26 Aug 2026, 3 min Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution CVE-2026-18431 is a critical unauthenticated RCE chain affecting Avada Plugin Security 26 Aug 2026, 3 min Events Manager <= 7.4.0.1 - Multiple Vulnerabilities Disclosed in WordPress Plugin Four Events Manager vulnerabilities were published on August 24, 2026, including Contributor+ SQL injection, unauthenticated information disclosure, reflected XSS, and administrator-level local file inclusion. Update to 7.4.1 or… Plugin Security 25 Aug 2026, 3 min PPWP Password Protect Pages <= 1.9.18 - Contributor+ PHP Object Injection CVE-2026-0551 affects PPWP Password Protect Pages up to 1.9.18. Contributor-level users can inject a PHP object through post_protection_roles; real-world impact depends on whether another plugin or theme exposes… Plugin Security 23 Aug 2026, 3 min Security Hardener <= 2.4.4 - Subscriber+ Privilege Escalation via REST Users Permission Callback CVE-2026-16149 is a high-severity Security Hardener flaw where user-enumeration protection can overwrite WordPress REST user endpoint capability checks, allowing Subscriber-level users to perform privileged user actions. Update to… Hardening 23 Aug 2026, 3 min Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router CVE-2026-19598 is a critical Pods authorization bypass that can let unauthenticated attackers reach administrator methods, overwrite user passwords, or obtain administrator privileges. Update to 3.3.9.1 or a backported… Plugin Security 22 Aug 2026, 3 min miniOrange SAML Single Sign On – Unauthenticated Authentication Bypass Across Seven Editions Two miniOrange SAML Single Sign On flaws can let unauthenticated attackers sign in as existing WordPress users, including administrators. Paid editions need manual version checks because the normal… Plugin Security 22 Aug 2026, 3 min WordPress Security Testing (2026 Update) Short answer: you can’t verify a WordPress security vendor’s claims by reading their marketing page — you verify them by checking what’s actually testable: their CVE disclosure history,… Security Research 9 Aug 2026, 14 min WordPress Importer — Arbitrary Post Creation The official WordPress Importer accepts a structured file and creates content from it. WPDeeply’s 2021 disclosure examined what happens when the file is not trustworthy. Security Research 11 Mar 2021, 3 min