One actor is exploiting stored XSS flaws in two WordPress plugins, one installed on more than 500,000 sites, to plant backdoors and rogue administrator accounts. Patchstack says updating the plugins blocks further exploitation but will not clean a site that is already compromised.
Reality
- Evidence55
- Adoption30
- Hype gap+10
- Incentives35
- Confidence60
CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 62%
- Investor
- Investor 3%
Reality
- Evidence79
- Adoption42
- Hype gap+14
- Incentives67
- Confidence70
CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence68
Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 55%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption60
- Hype gap+10
- Incentives30
- Confidence74
Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.
Perspective Coverage
5 publishers
- Builder
- Builder 32%
- Operator
- Operator 56%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.
Perspective Coverage
3 publishers
- Builder
- Builder 40%
- Operator
- Operator 52%
- Investor
- Investor 8%
Reality
- Evidence68
- Adoption45
- Hype gap+15
- Incentives30
- Confidence70
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Wordfence blocked more than 250,000 attempts against Super Forms and 190,000 against Elementor Pro. The Super Forms campaign has been running since July 14, so unpatched sites need a look through their uploads directories.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence64
build1 publisherOne report Patchstack rated a CSRF flaw in Elementor 4.3.0 and 4.3.1 at CVSS 8.8, where one click by a logged-in admin creates an attacker's administrator account. It only affects sites with the experimental Editor Events feature on, and the fix is Elementor 4.3.2.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+35
- Incentives
- Insufficient
- Confidence60
Wordfence has blocked nearly 200,000 attempts against CVE-2026-32475 since August 19. Because the payload is a PHP file already sitting in the uploads tree, upgrading to 4.2.2 tells you nothing about whether you were hit.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 65%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption70
- Hype gap+15
- Incentives45
- Confidence70
CVE-2026-27540 lets an unauthenticated request add php to the plugin's own upload allowlist and drop a webshell. The fix shipped on February 20, and the first exploitation spike came 104 days later, on June 4.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption20
- Hype gap+15
- Incentives45
- Confidence65
Paulos Yibelo of pwn.ai reported the Core flaw on August 22 and WordPress fixed it in 7.1.1 last week. The full proof-of-concept is now public, and the chain needs no attacker account, only an administrator who opens a link.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
The flaw reaches code execution only where the active theme has a top-level directory starting with page- and a readable local .php file such as pearcmd.php sits on the server. Previdian has logged 68 attempts.
Reality
- Evidence66
- Adoption45
- Hype gap+12
- Incentives68
- Confidence60
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
build1 publisherOne report Patchstack logged 11,334 ecosystem vulnerabilities last year, and 46% had no developer fix when they went public. That turns a care plan built on clicking Update All into a plugin inventory problem.
Reality
- Evidence42
- Adoption52
- Hype gap+28
- Incentives62
- Confidence45
build1 publisherOne report CVE-2026-82222 lets an unauthenticated visitor register on any GiveWP site running 4.16.7.1 or earlier, park a serialized gadget in a profile field, and let donation processing deserialize it into OS command execution. The fix is 4.16.7.2.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence45
build1 publisherOne report The plugin honoured HMAC-SHA1 chosen by the attacker and used the IdP's public RSA key as the shared secret. Free is fixed at 5.4.5, Standard at 17.0.6, under the same slug.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives50
- Confidence48