CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence68
Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 55%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption60
- Hype gap+10
- Incentives30
- Confidence74
Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.
Perspective Coverage
5 publishers
- Builder
- Builder 32%
- Operator
- Operator 56%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.
Perspective Coverage
3 publishers
- Builder
- Builder 40%
- Operator
- Operator 52%
- Investor
- Investor 8%
Reality
- Evidence68
- Adoption45
- Hype gap+15
- Incentives30
- Confidence70
Wordfence blocked more than 250,000 attempts against Super Forms and 190,000 against Elementor Pro. The Super Forms campaign has been running since July 14, so unpatched sites need a look through their uploads directories.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence64
Patchstack rated a CSRF flaw in Elementor 4.3.0 and 4.3.1 at CVSS 8.8, where one click by a logged-in admin creates an attacker's administrator account. It only affects sites with the experimental Editor Events feature on, and the fix is Elementor 4.3.2.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+35
- Incentives
- Insufficient
- Confidence60
CVE-2026-27540 lets an unauthenticated request add php to the plugin's own upload allowlist and drop a webshell. The fix shipped on February 20, and the first exploitation spike came 104 days later, on June 4.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption20
- Hype gap+15
- Incentives45
- Confidence65
StellarWP split the fix across two releases, so a WordPress site updated on August 25 stayed open to CVE-2026-78006 until 6.17.4.1 shipped on September 10. Version data puts about 240,000 installs behind both bugs.
Reality
- Evidence62
- Adoption60
- Hype gap+20
- Incentives40
- Confidence60
Wordfence's Argus team found two CVSS-9.8 chains in The Events Calendar. An anonymous comment plus a moderation-hash preview URL reaches OS command execution, and version 6.17.4 closes only one of them.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence62
The developer pulled 2.35 and published 2.36, but the distribution server was still compromised, so some 2.36 downloads carried the same code and about 1,500 sites need a restore from backups taken before September 14.
Reality
- Evidence45
- Adoption55
- Hype gap+18
- Incentives45
- Confidence50
CVE-2026-27540 lets an unauthenticated POST save a PHP file, and 2.0.3.2 closes that write. Whether a file that already landed can run is a separate question, decided by how the server treats the upload directory.
Reality
- Evidence60
- Adoption38
- Hype gap+10
- Incentives45
- Confidence55
The bypass needs three separate conditions to line up before it reaches command execution. Wordfence's blocked-attempt telemetry tells you nothing about whether they lined up on your site.
Reality
- Evidence58
- Adoption35
- Hype gap+15
- Incentives55
- Confidence55
CVE-2026-19949 sits in the read path, so text planted through trackbacks becomes a live query the moment an administrator exports or restores a backup. The query it runs hands over the key that guards the import endpoint.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+24
- Incentives34
- Confidence44
CVE-2026-82222 lets an unauthenticated visitor register on any GiveWP site running 4.16.7.1 or earlier, park a serialized gadget in a profile field, and let donation processing deserialize it into OS command execution. The fix is 4.16.7.2.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence45
The plugin honoured HMAC-SHA1 chosen by the attacker and used the IdP's public RSA key as the shared secret. Free is fixed at 5.4.5, Standard at 17.0.6, under the same slug.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives50
- Confidence48
A researcher found the plugin's directory route answers anyone, returning contact details members had set to hide. The fix is in code, so patch past 1.0.0 or turn it off.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+24
- Incentives68
- Confidence42
CVE-2026-15748 lets an unauthenticated attacker hide upload settings inside a Select field, so any site below 1.56.1 with a Select and a File Upload field is one request from a PHP file.
Reality
- Evidence60
- Adoption40
- Hype gap+18
- Incentives
- Insufficient
- Confidence52