WordPress
Vulnerabilities across WordPress core and its plugin and theme ecosystem — the sprawling third-party attack surface that runs a large share of the public web, where a single popular plugin flaw can cascade into hundreds of thousands of compromised sites within days of disclosure.
WordPress WP_Query author__not_in SQL injection (wp2shell companion)
A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.
WordPress Core unauthenticated RCE (wp2shell)
A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
WordPress Snap Creek Duplicator Plugin File Download Vulnerability
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
WordPress File Manager Plugin Remote Code Execution Vulnerability
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

Elementor Pro Flaw Exploited to Backdoor WordPress Sites
Attackers are exploiting CVE-2026-32475, a critical file upload flaw in Elementor Pro, to deliver webshells to WordPress sites running version 4.2.1 or earlier.

Profile Builder Plugin Flaw Allows Unauth File Upload
Cozmoslabs Profile Builder for WordPress up to 3.16.1 lets unauthenticated attackers upload files via the avatar AJAX endpoint. Patch or mitigate now.

Avada WordPress Theme Patches Critical Zero-Click RCE
ThemeFusion patches a six-flaw chain in Avada and Fusion Builder that lets unauthenticated attackers execute arbitrary PHP code. CVSS 9.8 Critical.

miniOrange SAML WordPress Flaws Under Active Exploit
Two authentication bypass flaws in the miniOrange SAML 2.0 SSO plugin are being actively exploited for WordPress admin takeover. Update immediately.

Forminator WordPress Plugin RCE Flaw Hits 600K Sites
CVE-2026-15748 (CVSS 9.8) in Forminator Forms lets unauthenticated attackers upload PHP files and achieve remote code execution. Update immediately.

Critical Flaws in Pods, Link Library Hit WordPress Sites
Pods (CVSS 9.8) and Link Library (CVSS 9.1) expose WordPress sites to unauthenticated privilege escalation and arbitrary file deletion with RCE potential.

MaxUpload for WordPress: Unauthenticated File Upload
CVE-2026-15965: MaxUpload (≤1.4.0) lets unauthenticated attackers upload arbitrary files via a filename validation mismatch between chunk and final assembly. CVSS 8.8, no patch confirmed.

Patch Now: Critical Auth Bypass Hits WordPress Plugins
Two WordPress plugins patched this week carry CVSS 9.8 authentication bypass flaws. A third allows unauthenticated file deletion that hands attackers RCE.

WordPress 7.0.4 Patches High-Severity RCE Flaw
WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.

Three CVEs Chain to Admin Takeover in WordPress Login Plugin
Three CVEs in the Login & Register Forms WordPress plugin before 4.0.2 enable unauthenticated account takeover, including site admins. Update now.

Both wp2shell CVEs land on CISA KEV — federal clock runs
CISA added both wp2shell CVEs — CVE-2026-63030 RCE and CVE-2026-60137 SQLi — to KEV on July 21. BOD 26-04 clock runs; SQLi is now framed as chainable.

wp2shell mass scanning confirmed — patch triage tonight
Four vendors — KEVIntel, watchTowr, Wiz, Cloudflare — now confirm mass scanning of the wp2shell RCE. CMSmap webshells and backdoor admin accounts observed.

wp2shell: first signs of exploitation; CVE-2026-60137 lands
watchTowr reports first signs of in-the-wild exploitation of the WordPress Core wp2shell RCE. The pending companion CVE-2026-60137 SQLi has landed, and exact patched versions are 6.9.5 and 7.0.2.

WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public
A critical unauthenticated remote code execution flaw in WordPress Core got a CVE, a GitHub advisory, and a working public PoC on July 17, 2026.