Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

WordPress

Vulnerabilities across WordPress core and its plugin and theme ecosystem — the sprawling third-party attack surface that runs a large share of the public web, where a single popular plugin flaw can cascade into hundreds of thousands of compromised sites within days of disclosure.

5 CVEs15 articlesRSS
CVEs
CVE-2026-60137
[ MEDIUM ]CVSS 5.9EPSS 78.3%kev

WordPress WP_Query author__not_in SQL injection (wp2shell companion)

A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.

WordPress / WordPress Core (6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1)
CVE-2026-63030
[ CRITICAL ]CVSS 9.8EPSS 97.3%kev

WordPress Core unauthenticated RCE (wp2shell)

A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.

WordPress / WordPress Core (6.9 and 7.0 branches per The Hacker News)
CVE-2019-9978
[ MEDIUM ]CVSS 6.1EPSS 72.9%kev

WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

WordPress / Social Warfare Plugin
CVE-2020-11738
[ HIGH ]CVSS 7.5EPSS 97.8%kev

WordPress Snap Creek Duplicator Plugin File Download Vulnerability

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

WordPress / Snap Creek Duplicator Plugin
CVE-2020-25213
[ CRITICAL ]CVSS 10.0EPSS 97.3%kev

WordPress File Manager Plugin Remote Code Execution Vulnerability

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

WordPress / File Manager Plugin
Articles
~/articles/2026-09-04-all-in-one-wp-migration-cve-2026-19949-sql-injection
All-in-One WP Migration Flaw Hits 3M WordPress Sites
wordpress

All-in-One WP Migration Flaw Hits 3M WordPress Sites

Unauthenticated SQL injection in All-in-One WP Migration and Backup plugin (versions through 7.109) enables data theft and conditional RCE. Update immediately.

read →
~/articles/2026-09-04-elementor-pro-cve-2026-32475-wordpress-webshell
Elementor Pro Flaw Exploited to Backdoor WordPress Sites
wordpress

Elementor Pro Flaw Exploited to Backdoor WordPress Sites

Attackers are exploiting CVE-2026-32475, a critical file upload flaw in Elementor Pro, to deliver webshells to WordPress sites running version 4.2.1 or earlier.

read →
~/articles/2026-08-31-profile-builder-unauth-file-upload-cve-2026-82607
Profile Builder Plugin Flaw Allows Unauth File Upload
wordpress

Profile Builder Plugin Flaw Allows Unauth File Upload

Cozmoslabs Profile Builder for WordPress up to 3.16.1 lets unauthenticated attackers upload files via the avatar AJAX endpoint. Patch or mitigate now.

read →
~/articles/2026-08-27-avada-wordpress-zero-click-rce-cve-2026-18431
Avada WordPress Theme Patches Critical Zero-Click RCE
wordpress

Avada WordPress Theme Patches Critical Zero-Click RCE

ThemeFusion patches a six-flaw chain in Avada and Fusion Builder that lets unauthenticated attackers execute arbitrary PHP code. CVSS 9.8 Critical.

read →
~/articles/2026-08-25-miniorange-saml-wordpress-auth-bypass-exploited
miniOrange SAML WordPress Flaws Under Active Exploit
wordpress

miniOrange SAML WordPress Flaws Under Active Exploit

Two authentication bypass flaws in the miniOrange SAML 2.0 SSO plugin are being actively exploited for WordPress admin takeover. Update immediately.

read →
~/articles/2026-08-18-forminator-wordpress-cve-2026-15748-rce
Forminator WordPress Plugin RCE Flaw Hits 600K Sites
wordpress

Forminator WordPress Plugin RCE Flaw Hits 600K Sites

CVE-2026-15748 (CVSS 9.8) in Forminator Forms lets unauthenticated attackers upload PHP files and achieve remote code execution. Update immediately.

read →
~/articles/2026-08-16-wordpress-pods-link-library-critical-vulns
Critical Flaws in Pods, Link Library Hit WordPress Sites
wordpress

Critical Flaws in Pods, Link Library Hit WordPress Sites

Pods (CVSS 9.8) and Link Library (CVSS 9.1) expose WordPress sites to unauthenticated privilege escalation and arbitrary file deletion with RCE potential.

read →
~/articles/2026-08-15-maxupload-cve-2026-15965-file-upload
MaxUpload for WordPress: Unauthenticated File Upload
wordpress

MaxUpload for WordPress: Unauthenticated File Upload

CVE-2026-15965: MaxUpload (≤1.4.0) lets unauthenticated attackers upload arbitrary files via a filename validation mismatch between chunk and final assembly. CVSS 8.8, no patch confirmed.

read →
~/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98
Patch Now: Critical Auth Bypass Hits WordPress Plugins
wordpress

Patch Now: Critical Auth Bypass Hits WordPress Plugins

Two WordPress plugins patched this week carry CVSS 9.8 authentication bypass flaws. A third allows unauthenticated file deletion that hands attackers RCE.

read →
~/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript
WordPress 7.0.4 Patches High-Severity RCE Flaw
wordpress

WordPress 7.0.4 Patches High-Severity RCE Flaw

WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.

read →
~/articles/2026-08-10-wp-login-register-cve-2026-18468-18469-18470
Three CVEs Chain to Admin Takeover in WordPress Login Plugin
wordpress

Three CVEs Chain to Admin Takeover in WordPress Login Plugin

Three CVEs in the Login & Register Forms WordPress plugin before 4.0.2 enable unauthenticated account takeover, including site admins. Update now.

read →
~/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock
Both wp2shell CVEs land on CISA KEV — federal clock runs
wordpress

Both wp2shell CVEs land on CISA KEV — federal clock runs

CISA added both wp2shell CVEs — CVE-2026-63030 RCE and CVE-2026-60137 SQLi — to KEV on July 21. BOD 26-04 clock runs; SQLi is now framed as chainable.

read →
~/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage
wp2shell mass scanning confirmed — patch triage tonight
wordpress

wp2shell mass scanning confirmed — patch triage tonight

Four vendors — KEVIntel, watchTowr, Wiz, Cloudflare — now confirm mass scanning of the wp2shell RCE. CMSmap webshells and backdoor admin accounts observed.

read →
~/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched
wp2shell: first signs of exploitation; CVE-2026-60137 lands
wordpress

wp2shell: first signs of exploitation; CVE-2026-60137 lands

watchTowr reports first signs of in-the-wild exploitation of the WordPress Core wp2shell RCE. The pending companion CVE-2026-60137 SQLi has landed, and exact patched versions are 6.9.5 and 7.0.2.

read →
~/articles/2026-07-18-wordpress-core-cve-2026-63030-wp2shell-rce-poc-public
WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public
wordpress

WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public

A critical unauthenticated remote code execution flaw in WordPress Core got a CVE, a GitHub advisory, and a working public PoC on July 17, 2026.

read →