WordPress: 24 Plugin Flaws Including Critical Backdoors and Account Takeovers Disclosed Together
A batch of 24 WordPress plugin vulnerabilities, including critical flaws like account takeover and malicious backdoors, were disclosed on August 13-14, 2026, demanding urgent user action.

Key findings
- 24 WordPress plugin vulnerabilities disclosed in a single batch between Aug 13-14, 2026.
- Critical flaws include account takeover (CVE-2026-12949) and malicious code backdoors (CVE-2026-73533, CVE-2026-73532).
- High-severity issues encompass stored XSS, SSRF, and SQL injection across multiple plugins.
- Affected plugins span e-commerce, forms, user registration, and theme add-ons.
- Immediate updates are critical for all affected WordPress plugins and themes.
On August 13-14, 2026, a significant batch of 24 vulnerabilities was disclosed across various WordPress plugins, with several critical and high-severity flaws impacting core functionalities like user roles, order management, and data integrity. This cluster of vulnerabilities, disclosed over an 18-hour period, highlights ongoing security challenges within the extensive WordPress plugin ecosystem. The disclosures include critical vulnerabilities such as account takeovers, embedded malicious code, and severe SQL injection flaws, alongside numerous high and medium-severity issues like stored cross-site scripting (XSS) and broken access control.
Several plugins were found to have critical vulnerabilities. CVE-2026-73533 and CVE-2026-73532, affecting Ninja Tables Pro and Fluent Forms Pro respectively, were introduced via tampered plugin builds served through a decommissioned update server, establishing backdoor REST API endpoints. CVE-2026-12949, a critical vulnerability in Wishlist Member, allows for account takeover due to insufficient verification of data authenticity.
High-severity vulnerabilities were also prevalent. CVE-2026-19794 and CVE-2026-18109, affecting WP-Stats and W3 Total Cache, respectively, are stored XSS vulnerabilities. CVE-2026-66704 in Gutenverse Companion presents an unauthenticated SSRF risk, while CVE-2026-66700 (Smart Online Order for Clover) and CVE-2026-66698 (SureDash) are unauthenticated XSS flaws. Additionally, CVE-2026-16810 (Bit Form) and CVE-2026-15205 (Paymob for WooCommerce) involve SQL injection, and CVE-2026-73346 in MailChimp For WooCommerce allows for administrator SQL injection. CVE-2026-18039 (Essential Addons for Elementor) allows unauthenticated attackers to register accounts with administrator privileges. CVE-2026-28154 in snstheme themes allows for reflected XSS.
Medium-severity issues include SQL injection vulnerabilities in affiliate-toolkit (CVE-2026-12743) and time-based SQL injection in Bit Form (CVE-2026-16810). Broken access control vulnerabilities were found in User Registration (CVE-2026-73403), InstaWP Connect (CVE-2026-73401), Revolut Gateway for WooCommerce (CVE-2026-73353), and GiveWP (CVE-2026-73349). Cross-site scripting vulnerabilities were identified in Astro Booking Engine (CVE-2025-10308), Embed Google Photos album (CVE-2026-14290), GiveWP (CVE-2026-73357), WP Data Access (CVE-2026-73344), and Featured Image from URL (CVE-2026-73340). CVE-2026-16739 in Epeken All Kurir for Woocommerce allows unauthenticated attackers to mark arbitrary orders as confirmed.
The affected plugins and themes include WP-Stats, Essential Addons for Elementor, Bit Form, Epeken All Kurir for Woocommerce, Paymob for WooCommerce, Embed Google Photos album, Wishlist Member, affiliate-toolkit, Astro Booking Engine, W3 Total Cache, Ninja Tables Pro, Fluent Forms Pro, snstheme Samex, snstheme M.Anh, User Registration, InstaWP Connect, GiveWP, Revolut Gateway for WooCommerce, MailChimp For WooCommerce, WP Data Access, Featured Image from URL, Gutenverse Companion, Smart Online Order for Clover, and SureDash. Users are strongly advised to update these plugins and themes to their patched versions immediately to mitigate the risks associated with these vulnerabilities.
The disclosure of these vulnerabilities highlights the importance of diligent security practices for WordPress users and developers alike. Regularly updating plugins, themes, and the WordPress core is crucial for maintaining a secure website. For developers, thorough input sanitization, output escaping, and proper nonce validation are essential to prevent common attack vectors like XSS and SQL injection. The presence of tampered plugin builds in this batch also underscores the need for vigilance in sourcing plugins from trusted repositories and being aware of potential supply chain attacks.
The batch of vulnerabilities disclosed between August 13-14, 2026, presents a clear and present danger to WordPress users. The critical nature of several flaws, including account takeovers and backdoors, necessitates immediate action. Users must prioritize updating the affected plugins and themes to their latest versions. The variety of vulnerabilities, from SQL injection and XSS to broken access control and SSRF, demonstrates the diverse threat landscape within the WordPress ecosystem. Staying informed about security advisories and applying patches promptly are the most effective defenses against these threats.
The following plugins and themes are affected by the disclosed vulnerabilities: WP-Stats, Essential Addons for Elementor, Bit Form, Epeken All Kurir for Woocommerce, Paymob for WooCommerce, Embed Google Photos album, Wishlist Member, affiliate-toolkit, Astro Booking Engine, W3 Total Cache, Ninja Tables Pro, Fluent Forms Pro, snstheme Samex, snstheme M.Anh, User Registration, InstaWP Connect, GiveWP, Revolut Gateway for WooCommerce, MailChimp For WooCommerce, WP Data Access, Featured Image from URL, Gutenverse Companion, Smart Online Order for Clover, and SureDash.
It is imperative for all WordPress site administrators to review their installed plugins and themes against this list and apply updates as soon as possible. The window for exploitation of such vulnerabilities is often short, and proactive patching is the best defense.
CVE-2026-19794, CVE-2026-18039, CVE-2026-16810, CVE-2026-16739, CVE-2026-15205, CVE-2026-14290, CVE-2026-12949, CVE-2026-12743, CVE-2025-10308, CVE-2026-18109, CVE-2026-73533, CVE-2026-73532, CVE-2026-28154, CVE-2026-73403, CVE-2026-73401, CVE-2026-73357, CVE-2026-73353, CVE-2026-73349, CVE-2026-73346, CVE-2026-73344, CVE-2026-73340, CVE-2026-66704, CVE-2026-66700, CVE-2026-66698. CVE-2026-73188 was rejected.