Skip to content

company

Patchstack

Patchstack is a WordPress security company that runs a vulnerability disclosure and bug bounty program for plugins and themes.

Known aliases

  • PatchStack
  • Patchstack Bug Bounty Program

Relationships

No evidence-backed relationships are recorded.

Current stories

security7 publishersConfirmed

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
security4 publishersConfirmed

Two loops, one blocklist bypass: Elementor Pro's upload field becomes unauthenticated RCE

CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence68
security3 publishersConfirmed

One clicked link creates an attacker admin on Elementor 4.3.0 and 4.3.1

Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 55%
Investor
Investor 7%

Reality

Evidence72
Adoption60
Hype gap+10
Incentives30
Confidence74
security5 publishersConfirmed

Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told

Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.

Perspective Coverage

5 publishers
Builder
Builder 32%
Operator
Operator 56%
Investor
Investor 12%

Reality

Evidence70
Adoption30
Hype gap+15
Incentives
Insufficient
Confidence68
security3 publishersConfirmed

GiveWP issues accounts to unauthenticated attackers on sites where registration is off

Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.

Perspective Coverage

3 publishers
Builder
Builder 40%
Operator
Operator 52%
Investor
Investor 8%

Reality

Evidence68
Adoption45
Hype gap+15
Incentives30
Confidence70
build1 publisherOne report

A URL substring match lets Elementor's Editor Events skip WordPress's REST nonce

Patchstack rated a CSRF flaw in Elementor 4.3.0 and 4.3.1 at CVSS 8.8, where one click by a logged-in admin creates an attacker's administrator account. It only affects sites with the experimental Editor Events feature on, and the fix is Elementor 4.3.2.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap+35
Incentives
Insufficient
Confidence60
security3 publishersConfirmed

Attackers started dropping webshells through Elementor Pro forms on patch day

Wordfence has blocked nearly 200,000 attempts against CVE-2026-32475 since August 19. Because the payload is a PHP file already sitting in the uploads tree, upgrading to 4.2.2 tells you nothing about whether you were hit.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 65%
Investor
Investor 7%

Reality

Evidence72
Adoption70
Hype gap+15
Incentives45
Confidence70
security3 publishersConfirmed

Wordfence blocked 100,000 exploit attempts against a WooCommerce plugin with 6,000 installs

CVE-2026-27540 lets an unauthenticated request add php to the plugin's own upload allowlist and drop a webshell. The fix shipped on February 20, and the first exploitation spike came 104 days later, on June 4.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence60
Adoption20
Hype gap+15
Incentives45
Confidence65