WordPress: 25 Plugin Vulnerabilities Disclosed Together, Ranging from Critical to Medium
A batch of 25 WordPress plugin vulnerabilities disclosed on September 23-24, 2026, spans critical flaws like SQL injection, privilege escalation, and XSS, affecting diverse site functionalities.

Key findings
- 25 WordPress plugins disclosed with vulnerabilities between Sep 23-24, 2026, ranging from Medium to Critical severity.
- Multiple plugins like Events Manager, WPeMatico, MasterStudy LMS, and Masteriyo LMS have multiple vulnerabilities each.
- Critical flaws include privilege escalation, SQL injection, authentication bypass, and stored XSS across various plugins.
- Patches are available for all affected plugins, with users urged to update immediately.
- Vulnerabilities impact core functionalities including user management, content, e-commerce, and LMS features.
On September 23-24, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple WordPress plugins, impacting a wide range of functionalities from user management and content creation to e-commerce and learning management systems. These vulnerabilities, disclosed within an 11-hour window, range in severity from Medium to Critical, with several allowing for privilege escalation, cross-site scripting (XSS), SQL injection, and authentication bypass. The sheer volume and diversity of these flaws underscore the ongoing security challenges faced by the extensive WordPress ecosystem.
Several plugins were affected by multiple vulnerabilities, indicating potential systemic issues within their development or update processes.
Events Manager Plugin Vulnerabilities: Two critical flaws were found in the Events Manager plugin before version 7.4.5. CVE-2026-93662 allows low-privileged users to access unpublished or pending event and venue content from other accounts, including sensitive address information. Additionally, CVE-2026-93661 enables authenticated users to hijack and reassign tickets from any event on the site to their own, regardless of ownership.
WPeMatico RSS Feed Fetcher Plugin Vulnerabilities: The WPeMatico RSS Feed Fetcher plugin, prior to version 2.8.26, suffers from two security weaknesses. CVE-2026-89005 and CVE-2026-89002 permit users with Contributor roles to inject malicious scripts, leading to Stored Cross-Site Scripting (XSS) attacks against higher-privileged users. Furthermore, CVE-2026-89004 allows users with Contributor access to view the configuration and run logs of campaigns created by other users, potentially exposing sensitive operational details.
MasterStudy LMS Plugin Vulnerabilities: The MasterStudy LMS WordPress plugin, in versions before 3.7.50, has three disclosed vulnerabilities. CVE-2026-88847 allows any authenticated user to falsely record lesson completions for courses they are not enrolled in. CVE-2026-88846 enables unauthenticated users to create accounts on sites where registration is enabled, bypassing security measures. Most critically, CVE-2026-88843 allows users with Contributor roles to execute arbitrary local PHP files on the server by manipulating display-style settings, posing a severe risk to server integrity. CVE-2026-88845 allows any authenticated user to trigger administrative maintenance actions, creating content attributed to their own account.
Masteriyo LMS Plugin Vulnerabilities: Two vulnerabilities were identified in the Masteriyo LMS plugin before version 3.4.2. CVE-2026-82850 allows any authenticated user to access correct answers for any quiz, regardless of course enrollment. CVE-2026-82849 permits authenticated users to view another user's learning activity by bypassing ownership checks on course progress records.
Other Notable Vulnerabilities: Several other plugins were affected by single, but significant, vulnerabilities:
- **CVE-2026-18467 (Critical):** Paytium: Mollie payment forms & donations plugin (up to 5.0.3) suffers from privilege escalation due to incomplete signature validation.
- **CVE-2026-86583 (High):** Import and export users and customers plugin (up to 2.4.17) has a privilege escalation flaw exploitable through its export/re-import workflow.
- **CVE-2026-19125 (High):** EthPress – Web3 Login plugin (up to 2.3.5) is vulnerable to authentication bypass due to a missing return statement in signature verification.
- **CVE-2026-95601 (Critical):** Product Filter by WBW (up to 3.1.7) contains an unauthenticated SQL injection vulnerability.
- **CVE-2026-80338 (Medium):** CMB2 plugin (before 2.13.0) allows users with Subscriber roles to create or corrupt arbitrary WordPress options via an AJAX action lacking capability checks, potentially taking the site offline.
- **CVE-2026-74991 (High):** WPForms plugin (before 2.0.2) allows unauthenticated users to trigger refunds and cancel subscriptions by manipulating Stripe payment objects.
- **CVE-2026-95604 (High):** Loops & Logic (<= 4.2.4) has an unauthenticated Broken Access Control vulnerability.
- **CVE-2026-95603 (High):** Reycob Product Import Export (<= 2.3.0) is vulnerable to shop manager PHP Object Injection.
- **CVE-2026-95600 (Medium):** TrustedLogin Connector (<= 2.0.3) exposes sensitive data due to unauthenticated data exposure.
- **CVE-2026-82195 (Medium):** 10Web Booster plugin (before 2.34.0) allows unauthenticated visitors to repeatedly delete the shared secret for cloud connection, preventing legitimate connections.
- **CVE-2026-80513 (Medium):** wpForo Forum plugin (before 3.1.6) allows authenticated users to inject PHP Objects via deserialization of user-supplied profile field values.
- **CVE-2026-95602 (Medium):** YITH WooCommerce Request A Quote (before 4.46.1) has an Authorization Bypass vulnerability.
- **CVE-2026-89002 (Medium):** WPeMatico RSS Feed Fetcher plugin (before 2.8.26) has Stored XSS.
- CVE-2026-10 (Medium): Post Grid plugin (before 7.9.5) allows Contributor roles to inject HTML, including iframes and style elements, site-wide.
The patches for these vulnerabilities are available in the following versions: Events Manager 7.4.5, WPeMatico RSS Feed Fetcher 2.8.26, MasterStudy LMS 3.7.50, Masteriyo LMS 3.4.2, Paytium: Mollie payment forms & donations 5.0.3, Import and export users and customers 2.4.17, EthPress – Web3 Login 2.3.5, W4 Post List 3.0.6, Loops & Logic 4.2.4, Reycob Product Import Export 2.3.0, YITH WooCommerce Request A Quote 4.46.1, Product Filter by WBW 3.1.7, TrustedLogin Connector 2.0.3, WPForms 2.0.2, 10Web Booster 2.34.0, wpForo Forum 3.1.6, CMB2 2.13.0, and Post Grid 7.9.5. Users are strongly advised to update these plugins to the patched versions to mitigate the risks associated with these widespread security flaws.
This extensive disclosure highlights the critical need for continuous security vigilance within the WordPress ecosystem. Developers and site administrators should prioritize updating plugins promptly following security advisories to protect against potential exploitation of these vulnerabilities. The clustering of these disclosures suggests a coordinated reporting effort, emphasizing the importance of staying informed about emerging threats.