Critical vulnerabilities in WordPress core and popular plugins get exploited fast — often within hours of disclosure. This page tracks the ones that matter, with a plain-English breakdown of what’s affected, how to check if you’re at risk, and how to update safely without losing your site in the process.
⚠️ Before you update anything
Emergency updates carry their own risk — plugin conflicts, broken sites, or discovering the compromise happened before you patched. Always take a full backup first. See how Nota Backup & Restore makes that a 2-minute step →
Latest Alerts
JULY 2026
wp2shell: Critical WordPress Core RCE Chain
CVE-2026-63030 & CVE-2026-60137 — an unauthenticated remote code execution chain in WordPress core, actively exploited and on CISA’s KEV list. Affects core 6.9.0–6.9.4 and 7.0.0–7.0.1.
JULY 2026
miniOrange OAuth SSO: Critical Authentication Bypass
CVE-2026-57807 (CVSS 9.8) — an unauthenticated auth bypass via the plugin’s password recovery flow. No official patch yet.
JUNE 2026
Support Board: Unauthenticated Privilege Escalation
CVSS 9.8 — lets an attacker with no login create or take over an admin account. Fixed in version 3.8.9.
JUNE 2026
WP Activity Log: PHP Object Injection
CVSS 8.1, 300,000+ active installs — can chain into more serious attacks. Fixed in version 5.6.4.
JULY 2026
WP Ultimate CSV Importer: Maximum-Severity RCE
CVSS 10.0 — the highest possible rating. Especially dangerous on sites where it was installed once for a migration and forgotten.
JULY 2026
miniOrange Social Login and Register: Privilege Escalation
CVSS 9.8 — a separate miniOrange product from the OAuth SSO bug above. Check your full plugin list if you use any miniOrange product.
JULY 2026
Kirki: Unauthenticated Admin Account Takeover
CVE-2026-8206 (CVSS 9.8) — a flawed password reset endpoint lets attackers hijack admin accounts. ~150,000 sites exposed among 500,000+ installs. Fixed in 6.0.7.
AUGUST 2026
Elementor Pro: Unauthenticated File Upload RCE
CVE-2026-32475 (CVSS 9.0) — an unauthenticated attacker can upload PHP files via the Forms module and run code. Millions of sites use Elementor Pro. Fixed in 4.2.2.
JULY 2026
Forminator Forms: Unauthenticated File Upload RCE
CVE-2026-15748 (CVSS 9.8) — 600,000+ sites exposed to unauthenticated PHP file upload leading to full RCE. Fixed in 1.56.2.
JULY 2026
User Profile Builder: Auth Bypass to Admin Takeover
CVE-2026-15826 (CVSS 9.8) — a type-juggling bug lets a failed registration be treated as admin account ID 1. Affects 40,000+ sites.
AUGUST 2026
ARVE: Hardcoded Token Backdoor
CVE-2026-18072 (CVSS 9.8) — a fixed authentication token in the plugin’s own code grants full admin access via a single request.
AUGUST 2026
Everest Forms: Unauthenticated File Upload
CVE-2026-19598 (CVSS 9.8) — 100,000+ sites exposed to file upload leading to full site takeover. Fixed in 3.0.9.5.
AUGUST 2026
miniOrange SAML SSO: Third Flaw This Season
CVE-2026-61979 / CVE-2026-15981 (CVSS 9.8) — forged SAML assertions let attackers log in as any user, including admins. Third critical miniOrange bug this season.
SEPTEMBER 2026
GiveWP: Maximum-Severity RCE (CVSS 10.0)
CVE-2026-82222 — a perfect 10.0 score. PHP object injection lets attackers run commands on any site with a published donation form. 100,000+ installs.
AUGUST 2026
Avada Theme: Zero-Click RCE Chain
CVE-2026-18431 (CVSS 9.8) — a six-step chain in one of WordPress’s best-selling themes lets attackers run code with no login and no clicks needed.
AUGUST 2026
WPMU DEV Dashboard: Hub SSO Bypass
CVE-2026-76581 (CVSS 9.8) — sites with Hub SSO enabled and mapped to an admin can be taken over without authentication. Common in agency site management.
SEPTEMBER 2026
All-in-One WP Migration: 4 Vulnerabilities This Season
Including an unauthenticated SQL injection via archive restore leading to potential RCE. Update to 7.110+ to cover all four.
Why We Track This
Half of high-impact WordPress vulnerabilities are exploited within 24 hours of disclosure, and the most targeted ones within just 5. Waiting for your host’s newsletter or a random tweet isn’t a strategy. We watch the same sources security researchers do and translate the technical write-ups into: is my site affected, and what do I do right now.
Make emergency updates a non-event
Nota Backup & Restore keeps automatic, off-site backups and lets you recover even when wp-admin is down. Start your 14-day free trial — no credit card required.
