Introduction All-in-One WP Migration and Backup, one of the most widely used migration and backup plugins for WordPress, has had four separate vulnera...
WPMU DEV Dashboard: Hub SSO Authentication Bypass to Admin Takeover (CVE-2026-76581)
Introduction The WPMU DEV Dashboard plugin had a critical authentication bypass vulnerability disclosed as CVE-2026-76581 (CVSS 9.8). On sites with Hu...
Avada Theme: Zero-Click Remote Code Execution Chain (CVE-2026-18431)
Introduction Avada, one of the best-selling WordPress themes, and its companion Fusion Builder plugin had a critical vulnerability disclosed as CVE-20...
GiveWP: Maximum-Severity Remote Code Execution (CVSS 10.0, CVE-2026-82222)
Introduction GiveWP, a donation and fundraising plugin with more than 100,000 active installations, had a vulnerability disclosed with a maximum CVSS ...
miniOrange SAML SSO: Critical Authentication Bypass, Third miniOrange Flaw This Season (CVE-2026-61979 / CVE-2026-15981)
Introduction Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin, tracked as CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8), l...
ARVE Plugin: Hardcoded Token Backdoor Grants Full Admin Access (CVE-2026-18072)
Introduction Advanced Responsive Video Embedder (ARVE), a popular video embedding plugin, had a critical vulnerability disclosed as CVE-2026-18072 (CV...
Everest Forms: Unauthenticated File Upload Flaw (CVE-2026-19598)
Introduction Everest Forms, installed on more than 100,000 WordPress sites, had a critical vulnerability disclosed as CVE-2026-19598 (CVSS 9.8) that l...
Elementor Pro: Unauthenticated File Upload RCE (CVE-2026-32475)
Introduction Elementor Pro, running on millions of WordPress sites, had a critical vulnerability disclosed as CVE-2026-32475 (CVSS 9.0) in its Forms m...
User Profile Builder: Authentication Bypass to Admin Takeover (CVE-2026-15826)
Introduction User Profile Builder, a plugin for custom registration and profile forms, had a critical authentication bypass vulnerability disclosed as...
Forminator Forms: Unauthenticated File Upload RCE (CVE-2026-15748)
Introduction Forminator Forms, installed on more than 600,000 WordPress sites, had a critical arbitrary file upload vulnerability disclosed and rated ...
