Skip to content
WP Hack FixEst. 2005

Archive

WordPress vulnerability archive

The flaws worth knowing about, with the versions affected, what each one allowed, and a link to the original research. We keep this updated as new ones are disclosed.

Entries
29
Known exploited
10
Highest severity
10.0
Covering from
January 2025

September 2026

  • Sep 22WordPress coreCVSS 9.2

    WordPress core 7.1.2

    A crafted URL could make WordPress open files it shouldn't, and run code on some hosts. No login needed.

    Flaw:
    Unauthenticated path traversal (local file inclusion)
    Vulnerable:
    4.7 – 7.1.1
    Fixed in:
    7.1.2
    CVE:
    CVE-2026-87902

    Read our write-up Original research(opens in a new tab)

  • Sep 18Server softwareCVSS 9.8

    libheif (server image library)

    A crafted iPhone photo could run code on servers that process HEIC uploads. Not fixed by updating WordPress.

    Flaw:
    Heap buffer overflow
    Vulnerable:
    1.18.0 – 1.23.2
    Fixed in:
    1.23.3

    Read our write-up Original research(opens in a new tab)

  • Sep 17WordPress core

    WordPress core 7.1.1

    One chain let an attacker take over a site if a logged-in admin clicked a crafted link.

    Flaw:
    11 security fixes, including stored XSS and a theme-install chain
    Fixed in:
    7.1.1
    CVE:
    CVE-2026-93485

    Read our write-up Original research(opens in a new tab)

  • Sep 17PluginCVSS 8.8100,000+ installs

    Tutor LMS

    A student-level account could run code on the server. Open registration made it reachable by anyone.

    Flaw:
    PHP object injection
    Vulnerable:
    <= 4.0.7
    Fixed in:
    4.0.8
    CVE:
    CVE-2026-78175

    Read our write-up Original research(opens in a new tab)

  • Sep 14PluginCVSS 9.8600,000+ installs

    The Events Calendar

    A comment on an event page, with no login, could run code on the server or reset the admin password.

    Flaw:
    Unauthenticated PHP object injection and password-reset chain
    Vulnerable:
    <= 6.17.4
    Fixed in:
    6.17.4.1
    CVE:
    CVE-2026-78006 / CVE-2026-78159

    Read our write-up Original research(opens in a new tab)

August 2026

  • Aug 29PluginCVSS 9.8

    WPMU DEV Dashboard

    Attackers could get in without valid credentials.

    Flaw:
    Authentication bypass
    Vulnerable:
    <= 5.0.1
    CVE:
    CVE-2026-76581

    Original research(opens in a new tab)

  • Aug 29ThemeCVSS 9.8

    Avada theme (with Fusion Builder)

    Writing files to the server opens the door to running code on it.

    Flaw:
    Arbitrary file write
    Vulnerable:
    <= 7.16 (Fusion Builder <= 3.16)
    CVE:
    CVE-2026-18431

    Original research(opens in a new tab)

  • Aug 29PluginCVSS 9.8

    TranslatePress

    Affected sites using secondary languages with automatic string saving enabled.

    Flaw:
    Sensitive data exposure
    Vulnerable:
    <= 3.3.1
    CVE:
    CVE-2026-19632

    Original research(opens in a new tab)

  • Aug 29PluginCVSS 9.8100,000+ installs

    Pods – Custom Content Types and Fields

    An unauthenticated attacker could become an administrator or reset the owner's password.

    Flaw:
    Privilege escalation
    Vulnerable:
    <= 3.3.9
    CVE:
    CVE-2026-19598

    Original research(opens in a new tab)

  • Aug 27PluginCVSS 10.0

    GiveWP

    Maximum severity. No login needed, and a default donation setup was enough.

    Flaw:
    PHP object injection
    Vulnerable:
    <= 4.16.7.1
    Fixed in:
    4.16.7.2
    CVE:
    CVE-2026-82222

    Read our write-up Original research(opens in a new tab)

  • Aug 22PluginCVSS 9.880,000+ installs

    Mailgun for WordPress

    Let an attacker create a mail-routing rule forwarding incoming mail, including password resets, to themselves.

    Flaw:
    Unauthenticated server-side request forgery (SSRF) via path traversal
    Vulnerable:
    <= 2.2.0
    Fixed in:
    2.2.1
    CVE:
    CVE-2026-78003

    Read our write-up Original research(opens in a new tab)

  • Aug 14Plugin5,000,000+ installs

    All-in-One WP Migration and Backup

    Could expose the plugin's secret key, a route to full takeover. Millions of sites stayed unpatched for weeks.

    Flaw:
    Second-order SQL injection
    Vulnerable:
    <= 7.109
    Fixed in:
    7.110
    CVE:
    CVE-2026-19949

    Original research(opens in a new tab)

June 2026

  • Jun 6PluginExploited in the wild100,000+ installs

    Gravity SMTP

    Attackers pulled API keys and OAuth tokens. Wordfence blocked over 17 million attempts.

    Flaw:
    Sensitive data exposure
    CVE:
    CVE-2026-4020

    Original research(opens in a new tab)

May 2026

  • May 18PluginExploited in the wild500,000+ installs

    Kirki Customizer Framework

    Attackers redirected password resets to themselves and took over admin accounts.

    Flaw:
    Privilege escalation via password reset
    Vulnerable:
    6.0.0 – 6.0.6
    Fixed in:
    6.0.7
    CVE:
    CVE-2026-8206

    Original research(opens in a new tab)

April 2026

  • Apr 13PluginCVSS 9.8Exploited in the wild

    Everest Forms Pro

    Unauthenticated attackers injected and ran PHP. Tens of thousands of attempts were blocked.

    Flaw:
    Remote code execution
    Vulnerable:
    <= 1.9.12
    CVE:
    CVE-2026-3300

    Original research(opens in a new tab)

March 2026

  • Mar 20PluginCVSS 9.1

    Photo Engine (wplr-sync)

    Any file could be uploaded, including a backdoor that could then be run.

    Flaw:
    Arbitrary file upload
    Vulnerable:
    <= 6.4.9
    CVE:
    CVE-2026-32524

    Original research(opens in a new tab)

January 2026

  • Jan 28PluginCVSS 9.8900,000+ installs

    WPvivid Backup & Migration

    No login needed. Uploading a file was enough to take the whole site.

    Flaw:
    Arbitrary file upload
    Vulnerable:
    <= 0.9.123
    Fixed in:
    0.9.124
    CVE:
    CVE-2026-1357

    Original research(opens in a new tab)

December 2025

  • Dec 5PluginExploited in the wild100,000+ installs

    Advanced Custom Fields: Extended

    Unauthenticated attackers could run code on the server.

    Flaw:
    Remote code execution
    CVE:
    CVE-2025-13486

    Original research(opens in a new tab)

November 2025

  • Nov 1PluginExploited in the wild

    Post SMTP

    Attackers began hitting this the day after disclosure and took over accounts and sites.

    Flaw:
    Account takeover
    CVE:
    CVE-2025-11833

    Original research(opens in a new tab)

  • Nov 1Plugin100,000+ installs

    AI Engine

    An exposed token handed unauthenticated attackers full administrative access.

    Flaw:
    Exposed authentication token
    CVE:
    CVE-2025-11749

    Original research(opens in a new tab)

October 2025

  • Oct 30PluginExploited in the wild

    King Addons for Elementor

    Attackers signed up as administrators. Over 48,000 attempts were blocked.

    Flaw:
    Privilege escalation at registration
    Fixed in:
    51.1.35
    CVE:
    CVE-2025-8489

    Original research(opens in a new tab)

August 2025

  • Aug 12PluginCVSS 9.8Exploited in the wild70,000+ installs

    Database for Contact Form 7

    Attackers scanned the internet for vulnerable sites and ran code on the ones they found.

    Flaw:
    PHP object injection
    Vulnerable:
    <= 1.4.3
    CVE:
    CVE-2025-7384

    Original research(opens in a new tab)

  • Aug 1PluginExploited in the wild

    Service Finder Bookings

    A manipulated cookie logged attackers in as any user, including the administrator. Exploited the day after the patch.

    Flaw:
    Authentication bypass
    Vulnerable:
    <= 6.0
    CVE:
    CVE-2025-5947

    Original research(opens in a new tab)

July 2025

  • Jul 14ThemeCVSS 9.8Exploited in the wild

    Alone (charity theme)

    Attackers uploaded web shells disguised as plugins. Exploitation started two days before public disclosure.

    Flaw:
    Arbitrary file upload
    Vulnerable:
    <= 7.8.3
    CVE:
    CVE-2025-5394

    Original research(opens in a new tab)

June 2025

  • Jun 30PluginCVSS 8.8600,000+ installs

    Forminator Forms

    Deleting wp-config.php can hand an attacker the whole site. No login required.

    Flaw:
    Arbitrary file deletion
    Vulnerable:
    <= 1.44.2
    Fixed in:
    1.44.3
    CVE:
    CVE-2025-6463

    Original research(opens in a new tab)

  • Jun 7ThemeCVSS 9.8Exploited in the wild22,000+ installs

    Motors theme

    The theme didn't check who was changing a password, so attackers changed the administrator's. Mass exploitation followed.

    Flaw:
    Privilege escalation via password reset
    Vulnerable:
    <= 5.6.67
    Fixed in:
    5.6.68
    CVE:
    CVE-2025-4322

    Original research(opens in a new tab)

May 2025

  • May 1PluginCVSS 9.8

    OttoKit (formerly SureTriggers)

    Unauthenticated attackers could escalate to administrator on sites where the plugin was installed but never configured.

    Flaw:
    Privilege escalation
    Vulnerable:
    <= 1.0.82
    Fixed in:
    1.0.83
    CVE:
    CVE-2025-27007

    Original research(opens in a new tab)

January 2025

  • Jan 29PluginCVSS 8.890,000+ installs

    Jupiter X Core

    A contributor-level account could upload a crafted SVG and run code on the server.

    Flaw:
    SVG upload to remote code execution
    Fixed in:
    4.8.8
    CVE:
    CVE-2025-0366

    Original research(opens in a new tab)

  • Jan 14PluginCVSS 8.51,000,000+ installs

    W3 Total Cache

    Any subscriber-level account could make the server fetch internal data, including cloud metadata.

    Flaw:
    Server-side request forgery
    Vulnerable:
    <= 2.8.1
    Fixed in:
    2.8.2
    CVE:
    CVE-2024-12365

    Original research(opens in a new tab)

Compiled from public advisories by Wordfence, Patchstack, WordPress.org, and security press. Severity scores are the ones assigned by the reporting researchers. Spotted something wrong or missing? Tell us and we'll fix it.

Running an old version of something on this list?

We'll tell you whether it was just a close call or whether something got in. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)