Tag

#WordPress

blogCRITICAL 9.3

Understanding and Defending Against Unauthenticated SQL Injection in GamiPress

This educational analysis covers CVE-2026-59538, an unauthenticated SQL injection vulnerability in GamiPress versions up to 7.9.7. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies to protect against this critical threat.

1 source
newsCRITICAL 9.3

CVE-2026-59533: Unauthenticated SQL Injection in Relevanssi Light Plugin

A critical vulnerability (CVE-2026-59533, CVSS 9.3) was discovered in the Relevanssi Light plugin (versions <= 1.2.2) for WordPress, allowing unauthenticated SQL injection. This vulnerability is not currently being exploited, but it poses a significant risk to WordPress sites using the affected plugin versions. Immediate action is required to update to a patched version.

1 source
articleCRITICAL 9.3

Critical Unauthenticated SQL Injection Vulnerability in MapSVG Plugin

A critical SQL injection vulnerability (CVE-2026-59527) has been discovered in the MapSVG plugin, affecting versions up to 8.14.0. This unauthenticated vulnerability has a CVSS score of 9.3, indicating a high severity threat. Successful exploitation could lead to unauthorized access to sensitive data. Immediate patching to version 8.14.1 or later is strongly recommended.

1 source
newsCRITICAL 9.1

Critical Vulnerability in 微信二维码登陆 WordPress Plugin Allows Unauthenticated Login

A critical vulnerability (CVE-2026-13597, CVSS 9.1) in the 微信二维码登陆 WordPress plugin (version 1.3 and earlier) allows unauthenticated attackers to forge login events, read login codes, and log in as any user, including administrators, without a password. Immediate action is required to prevent exploitation.

1 source
newsCRITICAL 9.8

Critical Code Injection Vulnerability in Customer Support Ticket System & Helpdesk Plugin for WordPress (CVE-2026-15011)

A critical vulnerability (CVE-2026-15011, CVSS score: 9.8) exists in the Customer Support Ticket System & Helpdesk plugin for WordPress, allowing unauthenticated attackers to inject arbitrary PHP code. This vulnerability affects all versions up to and including 6.0.5. Immediate action is required to prevent potential site disruption and data exposure.

1 source
articleCRITICAL 9.8

Critical Vulnerability in GoDAM WordPress Plugin Allows Arbitrary File Uploads and Potential RCE

The GoDAM – Organize WordPress Media Library & File Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to and including 1.12.2. This critical vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to upload arbitrary files on the affected site's server, potentially leading to remote code execution. Immediate patching is recommended.

1 source
articleCRITICAL 9.3

CVE-2026-65048: Critical Unauthenticated Stored XSS in Ninja Forms WordPress Plugin

A critical vulnerability (CVE-2026-65048, CVSS 9.3) exists in the Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9, allowing unauthenticated stored cross-site scripting (XSS) attacks via the Repeatable Fieldset feature. An attacker can submit a crafted form with malicious script payloads, which execute in an administrator's browser when viewing submissions, enabling session-cookie theft, creation of administrator accounts, and arbitrary modification of site content. Immediate patching is recommended.

1 source
newsCRITICAL 9.8

CVE-2026-13439: Unauthenticated Privilege Escalation in Easy Form Builder by WhiteStudio WordPress Plugin

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to unauthenticated privilege escalation to administrator in versions up to 4.0.11. This vulnerability allows unauthenticated attackers to reset the password of any WordPress user, including administrators, and gain full administrator access. A CVSS score of 9.8 indicates critical severity.

1 source
blogMEDIUM 6.5

Understanding and Defending Against CVE-2026-12973: Unauthorized Disclosure and Modification of WooCommerce Order Status

CVE-2026-12973 is a vulnerability in the PayPlus Payment Gateway WordPress plugin that allows unauthenticated users to disclose secret order keys and modify order statuses. This vulnerability has a CVSS score of 6.5 and is considered medium severity. It is not currently being actively exploited in the wild.

1 source
newsMEDIUM 6.5

CVE-2026-12898: Unauthenticated Log File Creation/Append Vulnerability in All-in-One WP Migration and Backup Plugin

A vulnerability in the All-in-One WP Migration and Backup WordPress plugin before version 7.106 allows unauthenticated attackers to create or append log files in arbitrary locations. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Affected versions are prior to 7.106.

1 source
articleHIGH 7.1

CVE-2026-9833: Unauthenticated XSS in Tag Groups WordPress Plugin

The CVE-2026-9833 vulnerability is a high-severity (CVSS 7.1) unauthenticated stored cross-site scripting (XSS) flaw in the Tag Groups WordPress plugin prior to version 2.2.0. An attacker can exploit this vulnerability by crafting a link that, when followed by a logged-in user with 'edit_pages' capability (Editor or higher), allows the execution of arbitrary JavaScript in the user's browser. This could lead to unauthorized actions within the WordPress dashboard. Immediate action is recommended to upgrade to version 2.2.0 or later.

1 source
articleHIGH 8.1

Critical Vulnerability in User Registration & Membership WordPress Plugin Allows Unauthorized Role Elevation

A high-severity vulnerability (CVE-2026-11963, CVSS 8.1) exists in the User Registration & Membership WordPress plugin prior to version 5.2.2. This flaw allows any authenticated user, including subscribers, to change another user's WordPress role and membership tier without proper authorization. The vulnerability has not been actively exploited but poses a significant risk due to its ease of exploitation and potential impact.

1 source
blogHIGH 8.1

Understanding and Defending Against CVE-2026-7655: Privilege Escalation in SureCart Plugin

CVE-2026-7655 is a privilege escalation vulnerability in the SureCart plugin for WordPress, allowing unauthenticated attackers to takeover accounts by manipulating user details via webhook events. This vulnerability has a CVSS score of 8.1 and affects versions up to 4.2.3 of the plugin. Understanding the root cause and attack vector is crucial for defenders to implement effective mitigations.

1 source
articleCRITICAL 9.8

CVE-2026-14245: Critical Authentication Bypass in miniOrange OTP Login, Verification and SMS Notifications Plugin

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover. This vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to take control of an arbitrary Administrator account. The plugin's flawed implementation of the password reset process enables attackers to obtain a freshly generated password-reset URL for an Administrator account. Immediate patching is recommended.

1 source
articleCRITICAL 9.8

CVE-2026-58480: Critical Unauthenticated Arbitrary File Upload Vulnerability in Blocksy Companion Pro Plugin

A critical vulnerability (CVE-2026-58480, CVSS 9.8) exists in the Blocksy Companion Pro plugin for WordPress before version 2.1.47. This unauthenticated arbitrary file upload vulnerability allows attackers to upload executable files, bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Successful exploitation leads to remote code execution. Immediate patching is recommended.

1 source
articleHIGH 8.8

CVE-2026-14495: Critical Authentication Bypass in DoLogin Security Plugin for WordPress

The DoLogin Security plugin for WordPress is vulnerable to authentication bypass due to insufficient randomness in all versions up to and including 4.3. This vulnerability allows unauthenticated attackers to brute-force a limited seed space and reconstruct active passwordless login tokens, enabling them to authenticate as any targeted user, including administrators, without a password. The vulnerability has a CVSS score of 8.8 and requires a valid, unexpired passwordless login link to exist for the target account. Immediate patching is recommended.

1 source
newsHIGH 8.6

CVE-2026-11590: WP Support Plus Responsive Ticket System SQL Injection Vulnerability

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 is vulnerable to SQL injection attacks. An unauthenticated attacker can exploit this vulnerability to perform malicious SQL queries. The vulnerability has a CVSS score of 8.6, indicating high severity.

1 source
newsMEDIUM 6.5

CVE-2026-3462: Frisbii Pay Plugin for WordPress Vulnerability

The Frisbii Pay plugin for WordPress has a vulnerability (CVE-2026-3462) that allows authenticated attackers with Subscriber-level access to modify data by uploading arbitrary CSV files. This vulnerability has a CVSS score of 6.5 and affects all versions up to 1.8.9. To mitigate, update the plugin to a patched version.

1 source
articleMEDIUM 6.5

CVE-2026-13333: SQL Injection Vulnerability in Groundhogg Plugin for WordPress

The Groundhogg plugin for WordPress is vulnerable to a generic SQL injection attack via the 'query[select]' parameter in versions up to and including 4.5.5. This vulnerability allows authenticated attackers with Sales Representative-level access and above to append additional SQL queries to extract sensitive information from the database. The CVSS score for this vulnerability is 6.5, indicating a medium severity. Organizations using the affected versions of the Groundhogg plugin should apply the necessary patches immediately to prevent potential exploitation.

1 source
newsCRITICAL 9.3

CVE-2026-54825: Unauthenticated SQL Injection in wpDataTables Plugin

A critical vulnerability (CVE-2026-54825, CVSS score 9.3) was discovered in the wpDataTables plugin (versions <= 7.4) for WordPress, allowing unauthenticated SQL injection attacks. This vulnerability is not currently being exploited, but it poses a significant risk to WordPress sites using affected versions. Immediate action is required to update to a patched version.

1 source
articleCRITICAL 9.3

Critical Unauthenticated SQL Injection Vulnerability in JetBooking Plugin

A critical SQL injection vulnerability (CVE-2026-54820) has been discovered in the JetBooking plugin, affecting versions up to 4.0.4.1. This unauthenticated vulnerability has a CVSS score of 9.3, indicating a high severity threat. Successful exploitation could lead to unauthorized access to sensitive data. Immediate patching to version 4.0.4.2 or later is strongly recommended.

1 source
blogHIGH 8.5

Understanding and Defending Against CVE-2026-56049: Contributor Remote Code Execution in Post Snippets

CVE-2026-56049 is a high-severity vulnerability in the Post Snippets WordPress plugin, allowing contributors to execute remote code. This vulnerability has a CVSS score of 8.5 and affects versions up to 4.0.19. Understanding the root cause, attack surface, and exploitation mechanics is crucial for defenders to protect their WordPress installations.

1 source
newsHIGH 8.5

CVE-2026-54838: SQL Injection Vulnerability in WC Vendors Marketplace

A SQL injection vulnerability exists in WC Vendors Marketplace plugin versions up to 2.6.8, allowing attackers to inject malicious SQL code. This vulnerability has a CVSS score of 8.5 and is considered high severity. Affected users should update to version 2.6.9 or later.

1 source
blogCRITICAL 9.8

Understanding and Defending Against CVE-2019-25763: Authentication Bypass in WordPress Ultimate Addons for Beaver Builder

CVE-2019-25763 is a critical authentication bypass vulnerability in WordPress Ultimate Addons for Beaver Builder 1.2.4.1. Attackers can exploit this flaw to gain unauthorized access by manipulating the social media login form functionality. This vulnerability has a CVSS score of 9.8, indicating a high severity threat. Understanding the root cause, attack vector, and defensive strategies is crucial for security practitioners to protect their deployments.

1 source
blogMEDIUM 5.3

Understanding Insufficient Verification of Data Authenticity: The CVE-2026-7792 Vulnerability

The WPForms plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity, allowing unauthenticated attackers to forge PayPal webhook events and modify subscription payment records. This vulnerability has a severity score of 5.3 and affects versions up to and including 1.10.0.1. Understanding this vulnerability can help users take necessary precautions to protect their websites.

1 source
newsMEDIUM 5.3

WordPress Breeze Plugin Vulnerability Exposes Sensitive Information

The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2.

1 source