Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: wordpress (29 articles)Clear

Elementor WordPress plugin flaw lets one link create a rogue administrator account

Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.

Check
Update the Elementor plugin to 4.3.2 across all WordPress sites, then audit administrator accounts for unexpected additions created via the flaw.
Affected
Sites running Elementor 4.3.0 or 4.3.1 let an unauthenticated attacker trick a logged-in admin into creating a rogue administrator account by clicking a link.
Fix
Apply Elementor 4.3.2, remove unrecognized admin accounts, and warn administrators against opening untrusted links while signed in to WordPress.

Attackers exploit unauthenticated WordPress code execution flaw within hours of its disclosure

Threat actors began exploiting a critical WordPress flaw, CVE-2026-87902, rated 9.2, within hours of its public disclosure. The bug lets an unauthenticated attacker make get_page_template() include a chosen readable local .php file outside the active theme directories, which can lead to remote code execution when server and theme preconditions are met. Exploitation requires the active child or parent theme to contain a top-level directory whose name starts with page-, and a readable local .php target such as pearcmd.php. Previdian reported honeypot exploitation attempts from a New Jersey IP that include /usr/local/lib/php/pearcmd.php, write a file to /tmp, then pull a PHP upload script from GitHub to plant a web shell.

Check
Update WordPress to the patched release now, then check whether active themes contain page- prefixed directories and review web logs for pearcmd.php requests.
Affected
WordPress sites meeting the theme and server preconditions let an unauthenticated attacker chain local file inclusion into remote code execution, already seen in the wild.
Fix
Apply the WordPress patch, harden PHP to disable pearcmd.php inclusion, and block the observed exploit indicators at the web tier.

WordPress flaw forces theme installs and can chain to server code execution

WordPress shipped 7.1.1 on September 17 to fix a flaw that pwn.ai calls Click2Shell, where a crafted link opened by a logged-in administrator installs a theme from the official directory with no click. Two parts of WordPress read the link differently, so attacker-added characters steer the admin browser into clicking Install, and the logged-in session supplies the permission and security token. Alone it only installs a real, switched-off theme, but the researchers chained it with a second flaw in the Mobile Repair Zone theme, whose handler fetched and ran remote code during a Customizer preview, reaching server code execution. No in-the-wild abuse is reported.

Check
Update all WordPress sites to 7.1.1 immediately, then audit installed themes for unexpected additions and remove any that administrators did not intend.
Affected
Sites where an administrator opens a crafted link can silently install an attacker-chosen theme, which can chain with a vulnerable theme to code execution.
Fix
Apply 7.1.1, remove unused themes, and warn administrators against opening untrusted links while authenticated to the WordPress dashboard.

WordPress backup plugin flaw lets attackers hijack sites through a poisoned import

A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.

Check
Update All-in-One WP Migration and Backup to 7.110 or later across all WordPress sites, and review sites for suspicious trackback comments, unexpected admin accounts, and unfamiliar files.
Affected
WordPress sites running All-in-One WP Migration and Backup through 7.109 (CVE-2026-19949); an unauthenticated attacker can plant SQL injection that leaks the plugin's secret key, enabling a malicious archive import and site takeover.
Fix
Patch the plugin, scan for web shells and unexpected files, audit administrator accounts, rotate WordPress secrets, disable trackbacks if not needed, and put a web application firewall in front of the site.

Critical WordPress plugin and theme flaws let unauthenticated attackers seize sites

Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.

Check
Inventory your WordPress sites for the WPMU DEV Dashboard, Avada, Pods, and TranslatePress components, and update each to its patched version now, prioritizing internet-facing and multi-author sites.
Affected
Sites running vulnerable versions of WPMU DEV Dashboard, Avada, Pods, or TranslatePress (CVE-2026-76581, CVE-2026-18431, CVE-2026-19598, CVE-2026-19632); unauthenticated attackers can gain admin access, reset passwords, or execute code.
Fix
Patch every affected plugin and theme, audit for unexpected admin accounts, changed passwords, and new PHP files, front sites with a web application firewall, and rotate credentials on any exposed site.

Critical GiveWP WordPress flaw lets unauthenticated attackers run server commands

A critical flaw in GiveWP, a WordPress donation and fundraising plugin installed on more than 100,000 sites, lets an unauthenticated attacker run commands on the hosting server. Tracked as CVE-2026-82222, it chains three weaknesses: an unsafe PHP deserialization helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that turns that into system command execution. Although exploitation normally needs an account, an exposed registration action lets an attacker create one even when registration is disabled, making it effectively unauthenticated. It affects versions up to 4.16.7.1 and is fixed in 4.16.7.2, which blocks serialized data during donation processing.

Check
Update the GiveWP plugin to 4.16.7.2 across all WordPress sites now, and check for unexpected accounts, files, or processes on servers running the donation plugin.
Affected
WordPress sites running GiveWP up to 4.16.7.1 (CVE-2026-82222); an attacker can chain PHP object injection into system command execution, and a registration bypass makes exploitation effectively unauthenticated even with signups disabled.
Fix
Patch the plugin, put a web application firewall in front of the site, scan for web shells and unauthorized files, and review hosting accounts and logs on donation-enabled sites.

Attackers chain two miniOrange WordPress SSO flaws to forge admin logins

Attackers are exploiting two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, chaining them to forge login responses and sign in as an administrator. The first flaw, CVE-2026-61979, lets the plugin accept an attacker-chosen signature algorithm, so the identity provider's public key can be abused as a shared secret to forge a valid signature; the second, CVE-2026-15981, makes the plugin treat a signature-verification error as success. Both were fixed in July, but the vendor only alerted free-edition users, leaving paid editions unpatched. Security firm Patchstack traced an attack in mid-August where the two were chained to steal an administrator session cookie.

Check
Update the miniOrange SAML Single Sign On plugin on all WordPress sites, including paid editions that were not alerted, and audit for unexpected administrator accounts and sessions.
Affected
WordPress sites using the miniOrange SAML 2.0 Single Sign On plugin (CVE-2026-61979, CVE-2026-15981); chaining the two lets an unauthenticated attacker forge a SAML response and obtain an administrator session.
Fix
Patch or remove the plugin, rotate WordPress salts and admin passwords to invalidate stolen sessions, check for rogue admins, and put a web application firewall in front of login endpoints.

Critical Elementor Pro flaw lets unauthenticated visitors upload PHP and run code

Researchers disclosed a critical flaw in Elementor Pro, the widely used WordPress page builder, that lets an unauthenticated visitor upload a PHP file through a public form and run code on the server. Tracked as CVE-2026-32475 and scored 9.0, it is a desynchronization bug in the Forms module's file-upload field: the code that validates an upload and the code that saves it disagree about how to handle an empty file entry. By sending a crafted upload with an empty first part followed by a PHP payload, an attacker slips the file past validation into a public directory. It affects versions up to 4.2.1 and is fixed in 4.2.2.

Check
Update Elementor Pro to 4.2.2 across all WordPress sites, and because updating does not remove files already uploaded, inspect the Elementor forms upload directory for unexpected PHP files.
Affected
WordPress sites running Elementor Pro up to 4.2.1 with a published form containing a file-upload field (CVE-2026-32475); an unauthenticated visitor can upload a PHP file and execute code as the web server.
Fix
Patch to 4.2.2, scan for web shells and unexpected files in upload directories, put a web application firewall in front of the site, and restrict public upload forms until confirmed clean.

Unauthenticated Forminator flaw lets attackers upload PHP and take over WordPress sites

A critical flaw in Forminator Forms, a WordPress plugin with more than 600,000 installations, lets unauthenticated attackers upload executable PHP files and take over a site. Tracked as CVE-2026-15748 and scored 9.8, the bug chains weaknesses in the plugin's upload handling: an attacker smuggles a forged record through a Select field that declares itself a file upload, then slips a PHP file past a blocklist that only checks exact extensions. Exploitation requires a form with both a file upload field and a select field, and it affects all versions up to 1.56.1. Because it needs no authentication, automated scanners can hunt for vulnerable sites at scale.

Check
Update the Forminator plugin to a version newer than 1.56.1 across all WordPress sites, and check for unexpected PHP files in upload directories and unfamiliar administrator activity.
Affected
WordPress sites running Forminator 1.56.1 or earlier with a form containing both a file upload and a select field (CVE-2026-15748); an unauthenticated attacker can upload PHP and fully compromise the site.
Fix
Patch the plugin, put a web application firewall in front of the site, scan for web shells and unauthorized files, and remove or reconfigure vulnerable forms until the update is applied.

Poisoned banner feed turns BdThemes WordPress plugins into rogue-admin factories

Researchers at Wordfence found that attackers compromised the upstream infrastructure of BdThemes, a popular WordPress plugin vendor, and poisoned a remote JSON feed that its plugins fetch to show promotional banners in the admin dashboard. Because the malicious code lives in that feed rather than in the plugin source, no plugin update was needed and nothing changed on disk. The injected script runs in every logged-in administrator's browser, creates hidden rogue admin accounts through the site's own interface, and installs a fake plugin containing a web shell for persistence. Seven plugins including Element Pack and Prime Slider were affected, and the flaw sat unnoticed for about five months.

Check
If you run BdThemes plugins such as Element Pack or Prime Slider, check for unexpected administrator accounts and unfamiliar plugins, and look for a web shell file named emer-run dot php.
Affected
WordPress sites running affected BdThemes plugins; a poisoned vendor feed ran code in administrators' browsers to create hidden admin accounts and install a web shell, without any plugin update or on-disk change.
Fix
Update the plugins once cleaned versions ship, remove rogue admins and web shells, rotate administrator credentials, and treat remote content that plugins load into the dashboard as an attack surface to monitor.