← Back to News Iceland Security Dashboard Browse all tags
wordpress

Wordpress

core 4geo-mashup 3user-registration-and-membership-plugin 2database-backup-plugin 2boost-plugin 2booking-calendar-contact-form 2wechat-qr-login-plugin 1webmention-plugin 1user-registration-and-membership 1url-preview-plugin 1ultimate-product-catalog 1ultimate-form-builder-lite 1tennis-court-bookings 1temporary-login-plugin 1survey-and-poll 1social-warfare 1social-login-passkeys-magic-link-email-otp 1social warfare plugin 1snap creek duplicator plugin 1slimstat-analytics 1

CVEs tagged with this vendor (61)

CVE-2019-9978 🚨 Social Warfare Plugin
CVE-2019-9978 is a stored cross-site scripting (XSS) vulnerability in the Social Warfare and Social Warfare Pro plugins for WordPress versions prior to 3.5.3. T…
CVE-2020-11738 🚨 Snap Creek Duplicator Plugin
CVE-2020-11738 is a directory traversal vulnerability in the Snap Creek Duplicator plugin for WordPress (versions before 1.3.28) and Duplicator Pro (before 3.8.…
CVE-2020-25213 🚨 File Manager Plugin
CVE-2020-25213 is a critical remote code execution vulnerability in the WordPress File Manager plugin (wp-file-manager) prior to version 6.9, classified under C…
CVE-2026-60137 🚨 Core
CVE-2026-60137 is a SQL injection vulnerability in WordPress Core versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, caused by improper sa…
CVE-2026-63030 🚨 Core
CVE-2026-63030 is a critical vulnerability in WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 involving a REST API batch endpoint route confusion. …
CVE-2018-25436 CVSS 9.8
CVE-2018-25436 is a critical unrestricted file upload vulnerability in WordPress Plugin Baggage Freight Shipping Australia version 0.1.0, classified under CWE-4…
CVE-2019-25727 CVSS 9.8
CVE-2019-25727 is a critical path traversal vulnerability in WordPress Plugin ad manager version 1.0.11, classified under CWE-22. It allows unauthenticated atta…
CVE-2019-25738 CVSS 9.8
CVE-2019-25738 is a critical unauthenticated settings change vulnerability in WordPress Hybrid Composer 1.4.6, classified under CWE-306. It allows attackers to …
CVE-2023-54352 CVSS 9.8
CVE-2023-54352 is a critical remote code execution vulnerability in the WordPress Seotheme plugin, classified under CWE-306. It allows unauthenticated attackers…
CVE-2024-58348 CVSS 9.8
CVE-2024-58348 is a critical remote code execution vulnerability in WordPress Background Image Cropper version 1.2, classified under CWE-434. It allows unauthen…
CVE-2025-13618 CVSS 9.8
CVE-2025-13618 is a critical privilege escalation vulnerability in the Mentoring plugin for WordPress, affecting versions up to and including 1.2.8. The flaw st…
CVE-2026-1492 CVSS 9.8
CVE-2026-1492 is a critical vulnerability in the User Registration & Membership WordPress plugin affecting versions up to 5.1.2. It allows unauthenticated attac…
CVE-2026-15013 CVSS 9.8
CVE-2026-15013 is a critical authentication bypass vulnerability in the SAML Single Sign On – SSO Login plugin for WordPress, affecting versions up to 5.4.3. Th…
CVE-2026-7567 CVSS 9.8
CVE-2026-7567 is a critical authentication bypass vulnerability in the Temporary Login plugin for WordPress versions up to and including 1.0.0, classified under…
CVE-2026-7637 CVSS 9.8
CVE-2026-7637 is a critical PHP Object Injection vulnerability in the Boost WordPress plugin versions up to and including 2.0.3, caused by deserialization of un…
CVE-2026-13597 CVSS 9.1
CVE-2026-13597 is a critical authentication bypass vulnerability in the 微信二维码登陆 WordPress plugin version 1.3, caused by improper validation of WeChat webhook re…
CVE-2016-20075 CVSS 8.8
CVE-2016-20075 is a HIGH severity vulnerability (CVSS 8.8) in WordPress Ultimate Product Catalog version 3.8.6, classified under CWE-863. It allows authenticate…
CVE-2021-47979 CVSS 8.8
CVE-2021-47979 is a HIGH severity vulnerability (CVSS 8.8) in WordPress Plugin Backup and Restore version 1.0.3, classified under CWE-22 (Improper Limitation of…
CVE-2025-6784 CVSS 8.8
CVE-2025-6784 is a high-severity Remote Code Execution vulnerability in the Code Engine WordPress plugin versions up to 0.3.5. The flaw stems from insufficient …
CVE-2026-3220 CVSS 8.8
CVE-2026-3220 affects the Autoptimize, Clearfy Cache, and Speed Optimizer WordPress plugins prior to versions 3.1.15, 2.4.2, and 7.7.9 respectively. The vulnera…
CVE-2026-7641 CVSS 8.8
CVE-2026-7641 is a high-severity privilege escalation vulnerability in the Import and export users and customers WordPress plugin versions up to 2.0.8. The flaw…
CVE-2016-20068 CVSS 8.2
CVE-2016-20068 is a high severity (CVSS 8.2) unauthenticated blind SQL injection vulnerability in WordPress Booking Calendar Contact Form version 1.0.23. The fl…
CVE-2016-20069 CVSS 8.2
CVE-2016-20069 is a high severity (CVSS 8.2) unauthenticated blind SQL injection vulnerability in WordPress Booking Calendar Contact Form version 1.0.23. The fl…
CVE-2016-20071 CVSS 8.2
CVE-2016-20071 is a high-severity SQL injection vulnerability (CWE-89) affecting the 404 Redirection Manager plugin version 1.0 for WordPress. The flaw allows u…
CVE-2019-25745 CVSS 8.2
CVE-2019-25745 is a high-severity time-based blind SQL injection vulnerability in WordPress Plugin Google Review Slider version 6.1, classified under CWE-89. Th…
CVE-2021-47941 CVSS 8.2
CVE-2021-47941 is a high-severity SQL injection vulnerability (CVSS 8.2) in WordPress Plugin Survey & Poll version 1.5.7.3. Unauthenticated attackers can exploi…
CVE-2026-11961 CVSS 8.1
CVE-2026-11961 is a high-severity vulnerability in the User Registration & Membership WordPress plugin prior to version 5.2.3. The flaw stems from insufficient …
CVE-2026-11963 CVSS 8.1
CVE-2026-11963 is a high-severity authorization bypass vulnerability in the User Registration & Membership WordPress plugin prior to version 5.2.2. The flaw all…
CVE-2026-12083 CVSS 8.1
CVE-2026-12083 is a high-severity vulnerability in the Admin and Site Enhancements (ASE) and admin-site-enhancements-pro WordPress plugins prior to version 8.8.…
CVE-2026-12378 CVSS 8.1
CVE-2026-12378 affects the Appointment Booking Calendar Plugin and Scheduling Plugin for WordPress through version 1.1.28. The vulnerability is a deserializatio…
CVE-2026-12583 CVSS 8.1
CVE-2026-12583 is a high-severity deserialization vulnerability (CWE-502) in the Newsletters WordPress plugin versions prior to 4.15. It allows unauthenticated …
CVE-2026-13142 CVSS 8.1
CVE-2026-13142 is a high-severity vulnerability in the Social Login, Passkeys, Magic Link & Email OTP WordPress plugin versions prior to 1.4.1. The flaw stems f…
CVE-2026-4030 CVSS 8.1
CVE-2026-4030 is a HIGH severity vulnerability (CVSS 8.1) in the Database Backup for WordPress plugin affecting versions up to 2.5.2. It allows unauthenticated …
CVE-2026-5821 CVSS 8.1
The Image Optimizer plugin for WordPress versions up to and including 1.7.4 contains a path traversal vulnerability due to insufficient path validation in the I…
CVE-2026-12240 CVSS 8.0
CVE-2026-12240 is a high-severity vulnerability in the Export User Data plugin for WordPress versions up to 2.2.6, classified under CWE-502 (Deserialization of …
CVE-2016-20076 CVSS 7.5
CVE-2016-20076 affects WordPress Simple-Backup version 2.7.11, allowing unauthenticated attackers to exploit insufficient input validation via directory travers…
CVE-2016-20081 CVSS 7.5
CVE-2016-20081 is a path traversal vulnerability in WordPress Plugin HB Audio Gallery Lite 1.0.0 that allows unauthenticated attackers to download arbitrary fil…
CVE-2023-54346 CVSS 7.5
WordPress Plugin Backup Migration version 1.2.8 contains an information disclosure vulnerability (CWE-538) allowing unauthenticated attackers to download comple…
CVE-2023-54350 CVSS 7.5
CVE-2023-54350 is a high severity remote code execution vulnerability in the WordPress Augmented-Reality plugin, specifically within the elFinder connector. It …
CVE-2026-14235 CVSS 7.5
CVE-2026-14235 affects the Download Manager WordPress plugin versions prior to 3.3.62 due to a failure to bind temporary download tokens to the requesting sessi…
CVE-2026-4029 CVSS 7.5
CVE-2026-4029 is a high-severity vulnerability in the Database Backup for WordPress plugin affecting versions up to 2.5.2, allowing unauthenticated attackers to…
CVE-2026-4060 CVSS 7.5
CVE-2026-4060 is a high severity SQL injection vulnerability in the Geo Mashup WordPress plugin versions up to and including 1.13.18. The flaw allows unauthenti…
CVE-2026-4061 CVSS 7.5
CVE-2026-4061 is a high severity SQL injection vulnerability in the Geo Mashup WordPress plugin versions up to 1.13.18. The flaw allows unauthenticated attacker…
CVE-2026-4062 CVSS 7.5
CVE-2026-4062 is a high severity SQL injection vulnerability in the Geo Mashup WordPress plugin versions up to 1.13.18. The flaw allows unauthenticated attacker…
CVE-2026-4338 CVSS 7.5
CVE-2026-4338 affects the ActivityPub WordPress plugin versions prior to 8.0.2 due to improper filtering of posts. This vulnerability allows unauthenticated use…
CVE-2026-9010 CVSS 7.5
CVE-2026-9010 is a high severity SQL injection vulnerability in the Boost WordPress plugin versions up to and including 2.0.3. The flaw allows unauthenticated a…
CVE-2016-20084 CVSS 7.2
CVE-2016-20084 affects WordPress appointment-booking-calendar version 1.1.24, involving multiple privilege escalation vulnerabilities. The flaw allows unauthent…
CVE-2026-0686 CVSS 7.2
CVE-2026-0686 is a high severity Server-Side Request Forgery vulnerability in the Webmention plugin for WordPress, affecting versions up to 5.6.2. The flaw resi…
CVE-2026-12100 CVSS 7.2
CVE-2026-12100 is a Server-Side Request Forgery vulnerability in the URL Preview plugin for WordPress, affecting versions up to and including 1.0. The flaw exis…
CVE-2026-1238 CVSS 7.2
CVE-2026-1238 is a high severity stored cross-site scripting vulnerability in the SlimStat Analytics plugin for WordPress, affecting versions up to and includin…
CVE-2026-13430 CVSS 7.2
CVE-2026-13430 is a high severity vulnerability in the Post Export Import with Media plugin for WordPress, affecting versions up to 1.13.1. It allows authentica…
CVE-2026-1648 CVSS 7.2
CVE-2026-1648 is a high severity Server-Side Request Forgery vulnerability in the Performance Monitor plugin for WordPress, affecting versions up to 1.0.6. The …
CVE-2026-1771 CVSS 7.2
CVE-2026-1771 is a HIGH severity vulnerability (CVSS 7.2) in the MapSVG plugin for WordPress, affecting versions up to and including 8.14.0. It stems from CWE-2…
CVE-2026-4132 CVSS 7.2
CVE-2026-4132 is a high-severity (CVSS 7.2) vulnerability in the WordPress HTTP Headers plugin affecting versions up to 1.19.2. It allows authenticated administ…
CVE-2026-4267 CVSS 7.2
CVE-2026-4267 is a high-severity reflected cross-site scripting vulnerability in the Query Monitor WordPress plugin, affecting all versions up to and including …
CVE-2018-25346 CVSS 7.1
CVE-2018-25346 is a SQL injection vulnerability in WordPress Form Maker Plugin versions 1.12.24 and below, classified under CWE-89. The vulnerability allows aut…
CVE-2018-25347 CVSS 7.1
CVE-2018-25347 is a SQL injection vulnerability in WordPress Contact Form Maker Plugin version 1.12.20, classified under CWE-89. The flaw allows authenticated a…
CVE-2018-25352 CVSS 7.1
CVE-2018-25352 is a SQL injection vulnerability (CWE-89) in the WordPress Ultimate Form Builder Lite plugin versions 1.3.7 and below. Authenticated attackers ca…
CVE-2019-25746 CVSS 7.1
CVE-2019-25746 is an authenticated SQL injection vulnerability in WordPress Sliced Invoices version 3.8.2. Attackers can exploit this by injecting malicious SQL…
CVE-2026-1671 CVSS 6.5
CVE-2026-1671 affects the Activity Log for WordPress plugin, specifically versions up to and including 1.2.8, due to a missing capability check in the winter_ac…
CVE-2026-1044 CVSS 4.4
CVE-2026-1044 is a Medium severity Stored Cross-Site Scripting vulnerability in the Tennis Court Bookings WordPress plugin versions up to 1.2.7. It stems from i…

Articles tagged with Wordpress (30)

CRITICAL
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
Wordfence · 2026-07-29
CRITICAL
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
Wordfence · 2026-07-28
CRITICAL
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)
Reddit r/netsec · 2026-07-28
CRITICAL
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)
Wordfence · 2026-07-23
CRITICAL
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE
Reddit r/netsec · 2026-07-23
CRITICAL
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
Elastic Security Labs · 2026-07-22
HIGH
What happens if you visit a WordPress site hacked through wp2shell?
Malwarebytes Labs · 2026-07-21
CRITICAL
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
The Hacker News · 2026-07-21
CRITICAL
Attackers pummel critical WordPress vuln to create all sorts of mischief
The Register Security · 2026-07-20
CRITICAL
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
Wordfence · 2026-07-20
CRITICAL
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Dark Reading · 2026-07-20
CRITICAL
Researchers Build WordPress Exploit Using OpenAI's GPT
Infosecurity Magazine · 2026-07-20
CRITICAL
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
Tenable Research · 2026-07-20
CRITICAL
Patch now: WordPress REST API bug allows remote code execution
CSO Online · 2026-07-20
HIGH
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
Reddit r/netsec · 2026-07-20
CRITICAL
WP2Shell WordPress Vulnerabilities Exploited in the Wild
SecurityWeek · 2026-07-20
HIGH
Multiples vulnérabilités dans WordPress (20 juillet 2026)
CERT-FR (ANSSI) · 2026-07-20
HIGH
Multiples vulnérabilités dans WordPress (20 juillet 2026)
CERT-FR (ANSSI) · 2026-07-20
CRITICAL
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched.
Reddit r/netsec · 2026-07-19
CRITICAL
wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE
Reddit r/netsec · 2026-07-19
CRITICAL
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
Reddit r/netsec · 2026-07-18
CRITICAL
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
BleepingComputer · 2026-07-18
HIGH
NCSC-2026-0250 [1.00] [H/M] Kwetsbaarheden verholpen in WordPress door Automattic
NCSC Netherlands · 2026-07-18
CRITICAL
wp2shell: Pre Authentication RCE in WordPress Core
Reddit r/netsec · 2026-07-18
CRITICAL
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
Wordfence · 2026-07-17
CRITICAL
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
Rapid7 Research · 2026-07-17
CRITICAL
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
The Hacker News · 2026-07-17
HIGH
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
Cloudflare Blog · 2026-07-17
MEDIUM
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)
Wordfence · 2026-07-16
INFO
We built a vulnerability vending machine: AI tokens in, zero-days out
BleepingComputer · 2026-07-15