Home WordPress Security Alerts

Critical vulnerabilities in WordPress core and popular plugins get exploited fast — often within hours of disclosure. This page tracks the ones that matter, with a plain-English breakdown of what’s affected, how to check if you’re at risk, and how to update safely without losing your site in the process.

⚠️ Before you update anything

Emergency updates carry their own risk — plugin conflicts, broken sites, or discovering the compromise happened before you patched. Always take a full backup first. See how Nota Backup & Restore makes that a 2-minute step →

Latest Alerts

JULY 2026

wp2shell: Critical WordPress Core RCE Chain

CVE-2026-63030 & CVE-2026-60137 — an unauthenticated remote code execution chain in WordPress core, actively exploited and on CISA’s KEV list. Affects core 6.9.0–6.9.4 and 7.0.0–7.0.1.

Read the alert →

JULY 2026

miniOrange OAuth SSO: Critical Authentication Bypass

CVE-2026-57807 (CVSS 9.8) — an unauthenticated auth bypass via the plugin’s password recovery flow. No official patch yet.

Read the alert →

JUNE 2026

Support Board: Unauthenticated Privilege Escalation

CVSS 9.8 — lets an attacker with no login create or take over an admin account. Fixed in version 3.8.9.

Read the alert →

JUNE 2026

WP Activity Log: PHP Object Injection

CVSS 8.1, 300,000+ active installs — can chain into more serious attacks. Fixed in version 5.6.4.

Read the alert →

JULY 2026

WP Ultimate CSV Importer: Maximum-Severity RCE

CVSS 10.0 — the highest possible rating. Especially dangerous on sites where it was installed once for a migration and forgotten.

Read the alert →

JULY 2026

miniOrange Social Login and Register: Privilege Escalation

CVSS 9.8 — a separate miniOrange product from the OAuth SSO bug above. Check your full plugin list if you use any miniOrange product.

Read the alert →

JULY 2026

Kirki: Unauthenticated Admin Account Takeover

CVE-2026-8206 (CVSS 9.8) — a flawed password reset endpoint lets attackers hijack admin accounts. ~150,000 sites exposed among 500,000+ installs. Fixed in 6.0.7.

Read the alert →

AUGUST 2026

Elementor Pro: Unauthenticated File Upload RCE

CVE-2026-32475 (CVSS 9.0) — an unauthenticated attacker can upload PHP files via the Forms module and run code. Millions of sites use Elementor Pro. Fixed in 4.2.2.

Read the alert →

JULY 2026

Forminator Forms: Unauthenticated File Upload RCE

CVE-2026-15748 (CVSS 9.8) — 600,000+ sites exposed to unauthenticated PHP file upload leading to full RCE. Fixed in 1.56.2.

Read the alert →

JULY 2026

User Profile Builder: Auth Bypass to Admin Takeover

CVE-2026-15826 (CVSS 9.8) — a type-juggling bug lets a failed registration be treated as admin account ID 1. Affects 40,000+ sites.

Read the alert →

AUGUST 2026

ARVE: Hardcoded Token Backdoor

CVE-2026-18072 (CVSS 9.8) — a fixed authentication token in the plugin’s own code grants full admin access via a single request.

Read the alert →

AUGUST 2026

Everest Forms: Unauthenticated File Upload

CVE-2026-19598 (CVSS 9.8) — 100,000+ sites exposed to file upload leading to full site takeover. Fixed in 3.0.9.5.

Read the alert →

AUGUST 2026

miniOrange SAML SSO: Third Flaw This Season

CVE-2026-61979 / CVE-2026-15981 (CVSS 9.8) — forged SAML assertions let attackers log in as any user, including admins. Third critical miniOrange bug this season.

Read the alert →

SEPTEMBER 2026

GiveWP: Maximum-Severity RCE (CVSS 10.0)

CVE-2026-82222 — a perfect 10.0 score. PHP object injection lets attackers run commands on any site with a published donation form. 100,000+ installs.

Read the alert →

AUGUST 2026

Avada Theme: Zero-Click RCE Chain

CVE-2026-18431 (CVSS 9.8) — a six-step chain in one of WordPress’s best-selling themes lets attackers run code with no login and no clicks needed.

Read the alert →

AUGUST 2026

WPMU DEV Dashboard: Hub SSO Bypass

CVE-2026-76581 (CVSS 9.8) — sites with Hub SSO enabled and mapped to an admin can be taken over without authentication. Common in agency site management.

Read the alert →

SEPTEMBER 2026

All-in-One WP Migration: 4 Vulnerabilities This Season

Including an unauthenticated SQL injection via archive restore leading to potential RCE. Update to 7.110+ to cover all four.

Read the alert →

Why We Track This

Half of high-impact WordPress vulnerabilities are exploited within 24 hours of disclosure, and the most targeted ones within just 5. Waiting for your host’s newsletter or a random tweet isn’t a strategy. We watch the same sources security researchers do and translate the technical write-ups into: is my site affected, and what do I do right now.

Make emergency updates a non-event

Nota Backup & Restore keeps automatic, off-site backups and lets you recover even when wp-admin is down. Start your 14-day free trial — no credit card required.