Skip to content

Topic

WordPress Plugin Security

Vulnerabilities and patching in widely installed WordPress plugins, where a single plugin flaw exposes hundreds of thousands of sites.

Current stories

security4 publishers

Two loops, one blocklist bypass: Elementor Pro's upload field becomes unauthenticated RCE

CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence68
security3 publishers

One clicked link creates an attacker admin on Elementor 4.3.0 and 4.3.1

Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 55%
Investor
Investor 7%

Reality

Evidence72
Adoption60
Hype gap+10
Incentives30
Confidence74
security5 publishers

Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told

Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.

Perspective Coverage

5 publishers
Builder
Builder 32%
Operator
Operator 56%
Investor
Investor 12%

Reality

Evidence70
Adoption30
Hype gap+15
Incentives
Insufficient
Confidence68
security3 publishers

GiveWP issues accounts to unauthenticated attackers on sites where registration is off

Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.

Perspective Coverage

3 publishers
Builder
Builder 40%
Operator
Operator 52%
Investor
Investor 8%

Reality

Evidence68
Adoption45
Hype gap+15
Incentives30
Confidence70
security3 publishers

Wordfence blocked 100,000 exploit attempts against a WooCommerce plugin with 6,000 installs

CVE-2026-27540 lets an unauthenticated request add php to the plugin's own upload allowlist and drop a webshell. The fix shipped on February 20, and the first exploitation spike came 104 days later, on June 4.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence60
Adoption20
Hype gap+15
Incentives45
Confidence65