Archive
WordPress vulnerability archive
The flaws worth knowing about, with the versions affected, what each one allowed, and a link to the original research. We keep this updated as new ones are disclosed.
- Entries
- 29
- Known exploited
- 10
- Highest severity
- 10.0
- Covering from
- January 2025
September 2026
- Sep 22WordPress coreCVSS 9.2
WordPress core 7.1.2
A crafted URL could make WordPress open files it shouldn't, and run code on some hosts. No login needed.
- Flaw:
- Unauthenticated path traversal (local file inclusion)
- Vulnerable:
- 4.7 – 7.1.1
- Fixed in:
- 7.1.2
- CVE:
- CVE-2026-87902
- Sep 18Server softwareCVSS 9.8
libheif (server image library)
A crafted iPhone photo could run code on servers that process HEIC uploads. Not fixed by updating WordPress.
- Flaw:
- Heap buffer overflow
- Vulnerable:
- 1.18.0 – 1.23.2
- Fixed in:
- 1.23.3
- Sep 17WordPress core
WordPress core 7.1.1
One chain let an attacker take over a site if a logged-in admin clicked a crafted link.
- Flaw:
- 11 security fixes, including stored XSS and a theme-install chain
- Fixed in:
- 7.1.1
- CVE:
- CVE-2026-93485
- Sep 17PluginCVSS 8.8100,000+ installs
Tutor LMS
A student-level account could run code on the server. Open registration made it reachable by anyone.
- Flaw:
- PHP object injection
- Vulnerable:
- <= 4.0.7
- Fixed in:
- 4.0.8
- CVE:
- CVE-2026-78175
- Sep 14PluginCVSS 9.8600,000+ installs
The Events Calendar
A comment on an event page, with no login, could run code on the server or reset the admin password.
- Flaw:
- Unauthenticated PHP object injection and password-reset chain
- Vulnerable:
- <= 6.17.4
- Fixed in:
- 6.17.4.1
- CVE:
- CVE-2026-78006 / CVE-2026-78159
August 2026
- Aug 29PluginCVSS 9.8
WPMU DEV Dashboard
Attackers could get in without valid credentials.
- Flaw:
- Authentication bypass
- Vulnerable:
- <= 5.0.1
- CVE:
- CVE-2026-76581
- Aug 29ThemeCVSS 9.8
Avada theme (with Fusion Builder)
Writing files to the server opens the door to running code on it.
- Flaw:
- Arbitrary file write
- Vulnerable:
- <= 7.16 (Fusion Builder <= 3.16)
- CVE:
- CVE-2026-18431
- Aug 29PluginCVSS 9.8
TranslatePress
Affected sites using secondary languages with automatic string saving enabled.
- Flaw:
- Sensitive data exposure
- Vulnerable:
- <= 3.3.1
- CVE:
- CVE-2026-19632
- Aug 29PluginCVSS 9.8100,000+ installs
Pods – Custom Content Types and Fields
An unauthenticated attacker could become an administrator or reset the owner's password.
- Flaw:
- Privilege escalation
- Vulnerable:
- <= 3.3.9
- CVE:
- CVE-2026-19598
- Aug 27PluginCVSS 10.0
GiveWP
Maximum severity. No login needed, and a default donation setup was enough.
- Flaw:
- PHP object injection
- Vulnerable:
- <= 4.16.7.1
- Fixed in:
- 4.16.7.2
- CVE:
- CVE-2026-82222
- Aug 22PluginCVSS 9.880,000+ installs
Mailgun for WordPress
Let an attacker create a mail-routing rule forwarding incoming mail, including password resets, to themselves.
- Flaw:
- Unauthenticated server-side request forgery (SSRF) via path traversal
- Vulnerable:
- <= 2.2.0
- Fixed in:
- 2.2.1
- CVE:
- CVE-2026-78003
- Aug 14Plugin5,000,000+ installs
All-in-One WP Migration and Backup
Could expose the plugin's secret key, a route to full takeover. Millions of sites stayed unpatched for weeks.
- Flaw:
- Second-order SQL injection
- Vulnerable:
- <= 7.109
- Fixed in:
- 7.110
- CVE:
- CVE-2026-19949
June 2026
- Jun 6PluginExploited in the wild100,000+ installs
Gravity SMTP
Attackers pulled API keys and OAuth tokens. Wordfence blocked over 17 million attempts.
- Flaw:
- Sensitive data exposure
- CVE:
- CVE-2026-4020
May 2026
- May 18PluginExploited in the wild500,000+ installs
Kirki Customizer Framework
Attackers redirected password resets to themselves and took over admin accounts.
- Flaw:
- Privilege escalation via password reset
- Vulnerable:
- 6.0.0 – 6.0.6
- Fixed in:
- 6.0.7
- CVE:
- CVE-2026-8206
April 2026
- Apr 13PluginCVSS 9.8Exploited in the wild
Everest Forms Pro
Unauthenticated attackers injected and ran PHP. Tens of thousands of attempts were blocked.
- Flaw:
- Remote code execution
- Vulnerable:
- <= 1.9.12
- CVE:
- CVE-2026-3300
March 2026
- Mar 20PluginCVSS 9.1
Photo Engine (wplr-sync)
Any file could be uploaded, including a backdoor that could then be run.
- Flaw:
- Arbitrary file upload
- Vulnerable:
- <= 6.4.9
- CVE:
- CVE-2026-32524
January 2026
- Jan 28PluginCVSS 9.8900,000+ installs
WPvivid Backup & Migration
No login needed. Uploading a file was enough to take the whole site.
- Flaw:
- Arbitrary file upload
- Vulnerable:
- <= 0.9.123
- Fixed in:
- 0.9.124
- CVE:
- CVE-2026-1357
December 2025
- Dec 5PluginExploited in the wild100,000+ installs
Advanced Custom Fields: Extended
Unauthenticated attackers could run code on the server.
- Flaw:
- Remote code execution
- CVE:
- CVE-2025-13486
November 2025
- Nov 1PluginExploited in the wild
Post SMTP
Attackers began hitting this the day after disclosure and took over accounts and sites.
- Flaw:
- Account takeover
- CVE:
- CVE-2025-11833
- Nov 1Plugin100,000+ installs
AI Engine
An exposed token handed unauthenticated attackers full administrative access.
- Flaw:
- Exposed authentication token
- CVE:
- CVE-2025-11749
October 2025
- Oct 30PluginExploited in the wild
King Addons for Elementor
Attackers signed up as administrators. Over 48,000 attempts were blocked.
- Flaw:
- Privilege escalation at registration
- Fixed in:
- 51.1.35
- CVE:
- CVE-2025-8489
August 2025
- Aug 12PluginCVSS 9.8Exploited in the wild70,000+ installs
Database for Contact Form 7
Attackers scanned the internet for vulnerable sites and ran code on the ones they found.
- Flaw:
- PHP object injection
- Vulnerable:
- <= 1.4.3
- CVE:
- CVE-2025-7384
- Aug 1PluginExploited in the wild
Service Finder Bookings
A manipulated cookie logged attackers in as any user, including the administrator. Exploited the day after the patch.
- Flaw:
- Authentication bypass
- Vulnerable:
- <= 6.0
- CVE:
- CVE-2025-5947
July 2025
- Jul 14ThemeCVSS 9.8Exploited in the wild
Alone (charity theme)
Attackers uploaded web shells disguised as plugins. Exploitation started two days before public disclosure.
- Flaw:
- Arbitrary file upload
- Vulnerable:
- <= 7.8.3
- CVE:
- CVE-2025-5394
June 2025
- Jun 30PluginCVSS 8.8600,000+ installs
Forminator Forms
Deleting wp-config.php can hand an attacker the whole site. No login required.
- Flaw:
- Arbitrary file deletion
- Vulnerable:
- <= 1.44.2
- Fixed in:
- 1.44.3
- CVE:
- CVE-2025-6463
- Jun 7ThemeCVSS 9.8Exploited in the wild22,000+ installs
Motors theme
The theme didn't check who was changing a password, so attackers changed the administrator's. Mass exploitation followed.
- Flaw:
- Privilege escalation via password reset
- Vulnerable:
- <= 5.6.67
- Fixed in:
- 5.6.68
- CVE:
- CVE-2025-4322
May 2025
- May 1PluginCVSS 9.8
OttoKit (formerly SureTriggers)
Unauthenticated attackers could escalate to administrator on sites where the plugin was installed but never configured.
- Flaw:
- Privilege escalation
- Vulnerable:
- <= 1.0.82
- Fixed in:
- 1.0.83
- CVE:
- CVE-2025-27007
January 2025
- Jan 29PluginCVSS 8.890,000+ installs
Jupiter X Core
A contributor-level account could upload a crafted SVG and run code on the server.
- Flaw:
- SVG upload to remote code execution
- Fixed in:
- 4.8.8
- CVE:
- CVE-2025-0366
- Jan 14PluginCVSS 8.51,000,000+ installs
W3 Total Cache
Any subscriber-level account could make the server fetch internal data, including cloud metadata.
- Flaw:
- Server-side request forgery
- Vulnerable:
- <= 2.8.1
- Fixed in:
- 2.8.2
- CVE:
- CVE-2024-12365
Compiled from public advisories by Wordfence, Patchstack, WordPress.org, and security press. Severity scores are the ones assigned by the reporting researchers. Spotted something wrong or missing? Tell us and we'll fix it.
Running an old version of something on this list?
We'll tell you whether it was just a close call or whether something got in. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)