WordPress: 25 Plugin Vulnerabilities Disclosed Together, Ranging from SQLi to Critical Flaws
A batch of 25 WordPress plugin vulnerabilities, including critical flaws like arbitrary file upload and authentication bypass, were disclosed together on September 1, 2026.

Key findings
- 25 WordPress plugins affected by a single disclosure event on September 1, 2026.
- Vulnerabilities span SQL injection, XSS, arbitrary file upload, authentication bypass, and SSRF.
- Critical flaws in plugins like WPLP Cookie Consent and Support Genix pose severe risks.
- Many of the vulnerabilities are unauthenticated, increasing the attack surface.
- Prompt updates to patched plugin versions are crucial for site security.
On September 1, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with the earliest disclosure on August 31, 2026. This cluster of vulnerabilities, spanning multiple plugins and affecting a wide range of functionalities, presents a substantial risk to WordPress site administrators and users. The vulnerabilities include SQL injection, cross-site scripting (XSS), arbitrary file upload, authentication bypass, and server-side request forgery (SSRF), with severities ranging from medium to critical.
Several plugins were found to be vulnerable to SQL injection attacks. CVE-2026-77189 in the Charitable plugin, CVE-2026-77823 in LearnPress, CVE-2026-76006 in Photo Gallery by Ays, and CVE-2026-17589 in the Shopping Cart & eCommerce Store plugin all suffer from insufficient escaping of user-supplied parameters in SQL queries. The Persistent Login plugin (CVE-2026-18752) is also vulnerable via a cookie parameter.
Stored Cross-Site Scripting (XSS) vulnerabilities were identified in multiple plugins. The BetterDocs plugin (CVE-2026-75980) is vulnerable via a heading ID attribute, User Profile Builder (CVE-2026-75964 and CVE-2026-75965) is vulnerable via an email parameter and a date shortcode attribute respectively, Blocksy Companion (CVE-2026-18488) via a block attribute, Listdom (CVE-2026-19796) via a parameter in its directory functionality, Affiliate Super Assistent (CVE-2026-19573) via a shortcode, and Live Composer (CVE-2026-16787 and CVE-2026-13203) via shortcode attributes. Frontend Admin by DynamiApps (CVE-2026-12747) is also affected by stored XSS via a shortcode attribute. WordPress Social Login and Register (CVE-2026-82229) suffers from unauthenticated XSS.
Critical vulnerabilities include arbitrary file upload in WPLP Cookie Consent (CVE-2026-75865) and Master Addons for Elementor (CVE-2026-75921), arbitrary file deletion in Frontend Admin by DynamiApps (CVE-2026-19952), and an authentication bypass leading to administrator account takeover in Support Genix (CVE-2026-19806). The SiteGround Security plugin (CVE-2026-82228) also has an unauthenticated bypass vulnerability.
Other notable vulnerabilities include an unauthenticated shortcode execution flaw in MW WP Form (CVE-2026-78363), a caching issue in WP Fastest Cache (CVE-2026-74916), an authorization bypass in KiviCare (CVE-2026-13611) allowing disclosure of sensitive information, and an authorization bypass in Cozy Blocks (CVE-2026-19948). MapSVG (CVE-2026-82852) is affected by an unauthenticated Server Side Request Forgery (SSRF) vulnerability.
The majority of these vulnerabilities were patched in new versions released on or around the disclosure date. Users are strongly advised to update all affected plugins to their latest versions immediately to mitigate these risks. Specific version information for patches is available in the respective plugin changelogs and security advisories.
This extensive batch of vulnerabilities underscores the importance of diligent plugin management and timely updates within the WordPress ecosystem. Administrators should regularly audit their installed plugins, review their security configurations, and apply patches promptly to safeguard their websites against these widespread threats. The sheer volume and variety of vulnerabilities highlight the ongoing need for robust security practices in WordPress development and deployment.
Key Findings:
- 25 WordPress plugins were affected by a batch of vulnerabilities disclosed on September 1, 2026.
- Vulnerabilities include SQL injection, XSS, arbitrary file upload, authentication bypass, and SSRF.
- Critical flaws in plugins like WPLP Cookie Consent and Support Genix allow for file upload and account takeover.
- Many vulnerabilities are unauthenticated, posing a significant risk to all WordPress sites.
- Prompt updates to the latest plugin versions are essential for mitigation.
CVE IDs: CVE-2026-78363, CVE-2026-74916, CVE-2026-13611, CVE-2026-77189, CVE-2026-75980, CVE-2026-75964, CVE-2026-18488, CVE-2026-77823, CVE-2026-76006, CVE-2026-75965, CVE-2026-75921, CVE-2026-19952, CVE-2026-19948, CVE-2026-19806, CVE-2026-19796, CVE-2026-19573, CVE-2026-18752, CVE-2026-17589, CVE-2026-16787, CVE-2026-13203, CVE-2026-12747, CVE-2026-75865, CVE-2026-82852, CVE-2026-82229, CVE-2026-82228