WordPress: 25 Plugin Vulnerabilities Disclosed Together, Including Critical Flaws
A batch of 25 WordPress plugin vulnerabilities, including critical flaws like arbitrary file uploads and authentication bypass, were disclosed on September 26-27, 2026.

Key findings
- 25 WordPress plugin vulnerabilities disclosed together between Sept 26-27, 2026, ranging from Medium to Critical severity.
- Critical flaws include arbitrary file uploads (CVE-2026-82901) and authentication bypass (CVE-2026-85984).
- Multiple plugins affected by stored XSS, privilege escalation, and SSRF vulnerabilities.
- Affected plugins include PowerPress, Optima Express IDX, WPeMatico, Download Manager, and others.
- Patches are available; immediate updates are recommended for all affected plugins.
On September 26-27, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, impacting a wide range of functionalities from content management to user authentication. These vulnerabilities, ranging in severity from Low to Critical, were reported within a 23-hour window, highlighting a concentrated disclosure event that demands immediate attention from WordPress site administrators. The disclosures include critical flaws such as arbitrary file uploads and authentication bypass, alongside numerous stored cross-site scripting (XSS) and privilege escalation vulnerabilities.
Several plugins were affected by stored XSS vulnerabilities, where insufficient sanitization or escaping of user-supplied data allowed attackers to inject malicious scripts. The PowerPress Podcasting plugin (CVE-2026-97319), Optima Express IDX plugin (CVE-2026-96899), WP YouTube Lyte plugin (CVE-2026-96895), and WPeMatico RSS Feed Fetcher plugin (CVE-2026-89006) are among those with stored XSS flaws, primarily affecting users with contributor roles or above. EmbedPress (CVE-2026-85002) and Optimole (CVE-2026-96531) also had similar issues, impacting higher privileged users viewing posts.
Critical vulnerabilities were also present, including arbitrary file uploads in the Ultra Addons for Contact Form 7 plugin (CVE-2026-82901), allowing unauthenticated attackers to upload malicious files. The miniOrange OTP Login plugin (CVE-2026-85984) suffered from an authentication bypass vulnerability, while the Groups – Memberships and Access Control plugin (CVE-2026-77203) had a privilege escalation flaw. The Malcure Malware Shield plugin (CVE-2026-96896) allowed subsite administrators to write and delete arbitrary files on a multisite network's shared filesystem.
Other notable vulnerabilities include privilege escalation in the Online Scheduling and Appointment Booking System plugin (CVE-2026-86841), which also had a separate low-severity flaw allowing authenticated staff to view, modify, and delete other staff's appointment and payment records (CVE-2026-86839). The Testimonials Widget plugin was affected by two vulnerabilities: one allowing unauthenticated users to fetch internal services (CVE-2026-96533), and another enabling unauthenticated users to modify or create arbitrary posts (CVE-2026-96532). The Download Manager plugin (CVE-2026-86609) and Ad Inserter plugin (CVE-2026-81655) had high-severity stored XSS vulnerabilities affecting administrators and logged-in users, respectively.
The batch also included vulnerabilities related to information disclosure and unauthorized access. The NextScripts: Social Networks Auto-Poster plugin (CVE-2026-97227) allowed users with posting features to export social account credentials. The Optima Express IDX plugin (CVE-2026-96897) allowed unauthenticated attackers to create fixed author-role accounts and rotate application passwords. Verge3D Publishing and E-Commerce plugin (CVE-2026-92995) allowed unauthenticated users to download digital goods files without authorization. Mailchimp for WooCommerce (CVE-2026-92436) allowed unauthenticated attackers to confirm customer details by knowing their email address. WebFacing™ plugin (CVE-2026-84069) allowed unauthenticated users to perform Local File Inclusion. UpdraftPlus (CVE-2026-82841) had a routine that output stored remote storage settings into admin pages without capability checks.
The WPeMatico RSS Feed Fetcher plugin was affected by multiple issues, including stored XSS (CVE-2026-89006), and server-side request forgery (SSRF) vulnerabilities allowing users to fetch internal-only hosts (CVE-2026-89003, CVE-2026-89000). It also allowed contributor-level users to publish posts live and attribute them to any registered user (CVE-2026-89001).
Most of these vulnerabilities have been addressed in plugin updates released around the disclosure date. Administrators are strongly advised to update all affected plugins to their latest versions immediately to mitigate these risks. The sheer volume and variety of these vulnerabilities underscore the importance of diligent plugin management and regular security audits for WordPress websites.
The affected plugins and their patched versions include: PowerPress Podcasting (before 11.17.2), NextScripts: Social Networks Auto-Poster (before 4.4.8), Optima Express IDX (before 8.7.6), Malcure Malware Shield (before 19.9.7), WP YouTube Lyte (before 1.7.31), Verge3D Publishing and E-Commerce (through 4.13.0), Mailchimp for WooCommerce (before 6.3), WPeMatico RSS Feed Fetcher (before 2.8.27), Online Scheduling and Appointment Booking System (before 28.3), Download Manager (before 7.5.6), EmbedPress (before 4.6.7), WebFacing™ (before 5.4), UpdraftPlus: WP Backup & Migration Plugin (before 1.26.8 and 2.26.8.26), Ad Inserter (before 2.8.19), Ultra Addons for Contact Form 7 (up to 3.5.50), miniOrange OTP Login (up to 5.5.5), Groups – Memberships and Access Control (up to 4.6.0), Testimonials Widget (through 4.0.4), Optimole (before 4.2.13).
This concentrated disclosure event serves as a critical reminder for WordPress users to maintain up-to-date plugins and themes, and to regularly review their security posture to protect against a wide array of potential threats. The timely patching of these vulnerabilities is essential to prevent exploitation and maintain the integrity of WordPress websites.