WordPress: 25 Plugin Vulnerabilities Disclosed Together, Including Critical Flaws
A coordinated disclosure on August 20-21, 2026, revealed 25 vulnerabilities across various WordPress plugins, ranging in severity from Low to Critical.

Key findings
- 25 WordPress plugin vulnerabilities disclosed in a single batch on August 20-21, 2026.
- Vulnerabilities include Critical SQL Injection, Authentication Bypass, and Arbitrary Code Execution.
- Multiple plugins affected by Broken Access Control, CSRF, and XSS flaws.
- Affected plugins range from e-commerce solutions to form builders and utility tools.
- Patches are available for most affected plugins, with versions specified for fixes.
On August 20-21, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with a tight disclosure window of just 23 hours. This coordinated release highlights a persistent challenge for WordPress site administrators: the need for diligent patching and updates to mitigate a wide range of security risks. The vulnerabilities span multiple severity levels, from Low to Critical, affecting plugins such as ProfilePress, Limit Login Attempts Reloaded, Passster, Charitable, myCred, Dokan, and InfiniteWP Client, among others.
Several plugins were found to have issues related to improper access control and authorization. CVE-2026-15046, a CSRF vulnerability in the LitExtension plugin, allows attackers to overwrite an authentication token. Similarly, CVE-2026-15150 and CVE-2026-16575 in myCred and Dokan respectively, allow unauthenticated attackers to credit arbitrary amounts or disclose sensitive vendor commission details. CVE-2026-74011, a Blind SQL Injection vulnerability in InfiniteWP Client, and CVE-2026-16959, an SQL injection in Media Library Assistant, pose significant risks to data integrity.
Cross-Site Scripting (XSS) and code execution vulnerabilities were also prominent. CVE-2026-19848 in ProfilePress allows unauthenticated attackers to store and execute shortcodes, potentially disclosing user email addresses. CVE-2026-18781 and CVE-2026-14325 in the Drag and Drop Multiple File Upload for Contact Form 7 plugin enable arbitrary code execution and XSS, respectively. CVE-2026-18409, a Stored XSS in WPForms Pro, allows for the injection of arbitrary web scripts.
Authentication bypass and privilege escalation were other key themes. CVE-2026-77264, a Critical vulnerability in Automation Web Platform – Notifications and OTP for WooCommerce, allows for authentication bypass by returning a secret magic login token. CVE-2026-75796 in AI Engine allows administrators on a Multisite sub-site to take over any account on the network. CVE-2026-18356 in Limit Login Attempts Reloaded allows authenticated bypass of login restrictions.
The batch also included vulnerabilities related to payment processing and order manipulation. CVE-2026-16650 in Charitable allows unauthenticated attackers to forge webhook notifications to mark donations as paid. CVE-2026-13076 in Eventin allows contributors to trigger blind server-side requests. CVE-2026-16962 in Tamara Checkout allows unauthenticated attackers to cancel or fail arbitrary orders.
The affected plugins and their patched versions include ProfilePress (before 4.17.1), Limit Login Attempts Reloaded (before 3.3.5), Passster (before 4.3.9), Charitable (before 1.8.12), myCred (before 3.2.5 for CVE-2026-15150, and before 3.2.8 for CVE-2026-28163), LitExtension (through 1.2.5), Eventin (before 4.1.21), Automation Web Platform – Notifications and OTP for WooCommerce (up to 4.8.6), AI Engine (before 3.6.1), Duplicate Post (before 1.5.6), Drag and Drop Multiple File Upload for Contact Form 7 (before 1.3.9.9), Tamara Checkout (through 1.9.9.20), Media Library Assistant (before 3.40), Dokan (before 5.0.14 for CVE-2026-16577, CVE-2026-16576, CVE-2026-15675), Link Whisper Free (before 0.9.7), NewPath WildApricotPress Add-on (through 1.0.0), Welcart e-Commerce (before 2.12.1), WPForms Pro (up to 2.0.0.2), InfiniteWP Client (through 1.13.9), and Easy Elementor Addons (through 2.3.7).
This coordinated disclosure of 25 vulnerabilities underscores the critical importance of maintaining up-to-date WordPress installations. Administrators should prioritize patching these plugins to prevent potential exploitation, which could range from data breaches and account takeovers to complete site compromise. Continuous monitoring and prompt application of security updates are essential for safeguarding WordPress websites against such a broad spectrum of threats.
Vypr Intelligence reported on this batch of vulnerabilities on August 20, 2026, highlighting the critical SQL Injection, Arbitrary File Upload, RCE, and PHP Object Injection flaws, as well as Broken Access Control and XSS issues.
The vulnerabilities disclosed include:
- CVE-2026-19848: ProfilePress - Shortcode injection leading to disclosure of user email.
- CVE-2026-18356: Limit Login Attempts Reloaded - Case-insensitive username check allowing bypass.
- CVE-2026-17559: Passster - Improper REST API endpoint matching.
- CVE-2026-16650: Charitable - Unverified Square payment webhook events.
- CVE-2026-15150: myCred - Mismatched payment gateway receiver.
- CVE-2026-15046: LitExtension - CSRF to overwrite connector authentication token.
- CVE-2026-13176: Eventin - Blind SSRF via unvalidated webhook URL.
- CVE-2026-77264: Automation Web Platform – Notifications and OTP for WooCommerce - Authentication bypass via magic login token.
- CVE-2026-75796: AI Engine - Privilege escalation on Multisite networks.
- CVE-2026-19435: Duplicate Post - Unauthorized access to post content and metadata.
- CVE-2026-19085: Duplicate Post - Unauthorized republishing of password-protected posts.
- CVE-2026-18781: Drag and Drop Multiple File Upload for Contact Form 7 - Arbitrary code execution via file name validation bypass.
- CVE-2026-16962: Tamara Checkout - Order status manipulation via unverified return URLs.
- CVE-2026-16959: Media Library Assistant - SQL injection via search parameter.
- CVE-2026-16577: Dokan - Arbitrary credit to vendor reverse-withdrawal ledger.
- CVE-2026-16576: Dokan - Insufficient capability check on admin REST API routes.
- CVE-2026-16575: Dokan - Disclosure of vendor commission details.
- CVE-2026-14601: Link Whisper Free - SQL injection via sanitized parameter.
- CVE-2026-14325: Drag and Drop Multiple File Upload for Contact Form 7 - XSS via HTML tag name injection.
- CVE-2026-13736: NewPath WildApricotPress Add-on - Disclosure of member contact information.
- CVE-2025-15671: Welcart e-Commerce - Session fixation for account takeover.
- CVE-2026-18409: WPForms Pro - Stored XSS in field values.
- CVE-2026-74011: InfiniteWP Client - Blind SQL Injection.
- CVE-2026-28164: Easy Elementor Addons - Cross-Site Request Forgery.
- CVE-2026-28163: myCred New User Approve - Exploiting incorrect access control.