buildOne report1 publisher Super Forms CVE-2026-17609 (CVSS 9.1) lets unauthenticated visitors recursively delete server directories when file cleanup is enabled. Versions through 6.3.316 are affected, and 6.3.317 fixes it, a dev.to analysis says.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Unauthenticated attackers can drop PHP onto WordPress sites running Forminator 1.56.1 or earlier. The install base is 600,000; the exposed subset depends on how the forms were built.
Reality
- Evidence72
- Adoption45
- Hype gap+30
- Incentives
- Insufficient
- Confidence68
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Wordfence blocked more than 250,000 attempts against Super Forms and 190,000 against Elementor Pro. The Super Forms campaign has been running since July 14, so unpatched sites need a look through their uploads directories.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence64
Wordfence has blocked nearly 200,000 attempts against CVE-2026-32475 since August 19. Because the payload is a PHP file already sitting in the uploads tree, upgrading to 4.2.2 tells you nothing about whether you were hit.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 65%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption70
- Hype gap+15
- Incentives45
- Confidence70
CVE-2026-27540 lets an unauthenticated request add php to the plugin's own upload allowlist and drop a webshell. The fix shipped on February 20, and the first exploitation spike came 104 days later, on June 4.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption20
- Hype gap+15
- Incentives45
- Confidence65
StellarWP split the fix across two releases, so a WordPress site updated on August 25 stayed open to CVE-2026-78006 until 6.17.4.1 shipped on September 10. Version data puts about 240,000 installs behind both bugs.
Reality
- Evidence62
- Adoption60
- Hype gap+20
- Incentives40
- Confidence60
buildOne report1 publisher Wordfence's Argus team found two CVSS-9.8 chains in The Events Calendar. An anonymous comment plus a moderation-hash preview URL reaches OS command execution, and version 6.17.4 closes only one of them.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence62
buildOne report1 publisher CVE-2026-27540 lets an unauthenticated POST save a PHP file, and 2.0.3.2 closes that write. Whether a file that already landed can run is a separate question, decided by how the server treats the upload directory.
Reality
- Evidence60
- Adoption38
- Hype gap+10
- Incentives45
- Confidence55
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
Every plugin and theme release now sits in a six-hour cooldown while AI models and Jetpack Scan grade the changes, and a high enough risk score halts distribution before any human looks at it. WordPress says the check already caught a backdoor.
Reality
- Evidence45
- Adoption68
- Hype gap+18
- Incentives62
- Confidence55
The WordPress.org update API will refuse any plugin release its own scoring calls high risk. The decision moves off a team member's inbox and onto a threshold the announcement does not publish.
Reality
- Evidence55
- Adoption68
- Hype gap+15
- Incentives60
- Confidence58
buildOne report1 publisher The bypass needs three separate conditions to line up before it reaches command execution. Wordfence's blocked-attempt telemetry tells you nothing about whether they lined up on your site.
Reality
- Evidence58
- Adoption35
- Hype gap+15
- Incentives55
- Confidence55
buildOne report1 publisher CVE-2026-19949 sits in the read path, so text planted through trackbacks becomes a live query the moment an administrator exports or restores a backup. The query it runs hands over the key that guards the import endpoint.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+24
- Incentives34
- Confidence44
Wordfence says CVE-2026-18431 lets an unauthenticated attacker run PHP on sites running both a vulnerable Avada theme and Fusion Builder. Updating either component breaks the chain.
Reality
- Evidence52
- Adoption28
- Hype gap+18
- Incentives66
- Confidence54