Stored XSS in ManageWP Worker
ManageWP Worker versions prior to 4.9.32 contain a stored XSS vulnerability in the brand customisation feature, allowing an attacker with ManageWP account access to inject JavaScript into the WordPress admin dashboard.
29 June 2026
Read moreAuthentication Bypass in Customer Reviews for WooCommerce
CVE-2026-4664: a flaw in Customer Reviews for WooCommerce lets unauthenticated attackers post fake Verified reviews via the plugin's REST API.
28 June 2026
Read morePrivilege Escalation in User Registration & Membership
Versions of User Registration & Membership up to 5.1.2 let unauthenticated attackers create administrator accounts via an unguarded AJAX endpoint.
27 June 2026
Read moreRemote Code Execution in Everest Forms
CVE-2026-3300 is a critical unauthenticated RCE in Everest Forms ≤1.9.12 — the Calculation Addon passes user input directly to eval(), giving attackers full server access.
26 June 2026
Read moreUltimate Member – Reflected XSS in Member Directory
The Ultimate Member plugin's Members List page has a sorting feature that accepts user input via GET parameters. The plugin fails to properly escape this input when displaying it back in the HTML, creating a reflected XSS vulnerability.
24 June 2026
Read moreBooking Manipulation in WP Travel Engine
CVE-2026-49078: WP Travel Engine ≤6.7.10 lets unauthenticated attackers create fraudulent bookings and access customer data via AJAX endpoints with non-fatal nonce validation.
22 June 2026
Read moreRemote Code Execution in RD Station Plugin
CVE-2026-49774: RD Station Plugin ≤5.6.0 lets contributor-level users execute arbitrary PHP by injecting a path traversal sequence into the OAuth refresh token, which is used unsanitised in a log file path.
21 June 2026
Read moreStored XSS in All-in-One WP Security & Firewall
CVE-2026-8438: All-in-One WP Security & Firewall ≤5.4.7 allows unauthenticated attackers to inject persistent JavaScript via unsanitised input, executing in visitors' browsers across the site.
21 June 2026
Read moreInformation Disclosure in Advanced Custom Fields
CVE-2026-4812: ACF 6.7.0 and earlier let unauthenticated attackers leak internal post, user, and relationship data by manipulating AJAX query parameters.
16 June 2026
Read moreAuthentication Bypass in UpdraftPlus
UpdraftPlus is one of the most popular WordPress backup plugins, with over 3 million active installations. In versions before 1.26.5, it contained a critical authentication bypass vulnerability that allowed unauthenticated attackers to restore arbitrary backups to a site.
13 June 2026
Read moreArbitrary File Read & SQL Injection in Avada Builder
Avada (Fusion) Builder version 3.15.1 has two vulnerabilities: Arbitrary file read (e.g. leak wp-config.php) and unauthenticated SQL injection.
17 May 2026
Read moreWP Mail Gateway – Missing Authorisation on Email Settings
The WP Mail Gateway plugin has a critical authorisation flaw in version 1.8 and earlier. Any authenticated user, including a Subscriber with no special permissions, can modify your site's email gateway settings. This means redirecting all outgoing mail to an attacker's server, intercepting password resets, and escalating to administrator access.
15 May 2026
Read more