Critical vulnerabilities in WordPress core and popular plugins get exploited fast — often within hours of disclosure. This page tracks the ones that matter, with a plain-English breakdown of what’s affected, how to check if you’re at risk, and how to update safely without losing your site in the process.
⚠️ Before you update anything
Emergency updates carry their own risk — plugin conflicts, broken sites, or discovering the compromise happened before you patched. Always take a full backup first. See how Nota Backup & Restore makes that a 2-minute step →
Latest Alerts
JULY 2026
wp2shell: Critical WordPress Core RCE Chain
CVE-2026-63030 & CVE-2026-60137 — an unauthenticated remote code execution chain in WordPress core, actively exploited and on CISA’s KEV list. Affects core 6.9.0–6.9.4 and 7.0.0–7.0.1.
JULY 2026
miniOrange OAuth SSO: Critical Authentication Bypass
CVE-2026-57807 (CVSS 9.8) — an unauthenticated auth bypass via the plugin’s password recovery flow. No official patch yet.
JUNE 2026
Support Board: Unauthenticated Privilege Escalation
CVSS 9.8 — lets an attacker with no login create or take over an admin account. Fixed in version 3.8.9.
JUNE 2026
WP Activity Log: PHP Object Injection
CVSS 8.1, 300,000+ active installs — can chain into more serious attacks. Fixed in version 5.6.4.
JULY 2026
WP Ultimate CSV Importer: Maximum-Severity RCE
CVSS 10.0 — the highest possible rating. Especially dangerous on sites where it was installed once for a migration and forgotten.
JULY 2026
miniOrange Social Login and Register: Privilege Escalation
CVSS 9.8 — a separate miniOrange product from the OAuth SSO bug above. Check your full plugin list if you use any miniOrange product.
JULY 2026
Kirki: Unauthenticated Admin Account Takeover
CVE-2026-8206 (CVSS 9.8) — a flawed password reset endpoint lets attackers hijack admin accounts. ~150,000 sites exposed among 500,000+ installs. Fixed in 6.0.7.
Why We Track This
Half of high-impact WordPress vulnerabilities are exploited within 24 hours of disclosure, and the most targeted ones within just 5. Waiting for your host’s newsletter or a random tweet isn’t a strategy. We watch the same sources security researchers do and translate the technical write-ups into: is my site affected, and what do I do right now.
Make emergency updates a non-event
Nota Backup & Restore keeps automatic, off-site backups and lets you recover even when wp-admin is down. Start your 14-day free trial — no credit card required.
