VYPR
Vypr IntelligenceAI-generatedSep 4, 2026· 25 CVEs

WordPress Plugins: 25 Vulnerabilities Disclosed in Batch, Ranging from Critical to Medium Severity

A batch of 25 WordPress plugin vulnerabilities, disclosed on September 3-4, 2026, ranges from critical privilege escalation to medium-severity XSS and access control flaws.

Key findings

  • 25 WordPress plugin vulnerabilities disclosed between Sep 3-4, 2026, spanning critical to medium severity.
  • Flaws include privilege escalation, XSS, broken access control, and file deletion, affecting popular plugins like WPFunnels and LearnPress.
  • Critical vulnerabilities in ACPT, Quick Event Manager, and WC Ukraine Shipping allow unauthenticated compromise.
  • Multiple plugins patched, users urged to update immediately to secure their sites.
  • The batch highlights ongoing security risks within the WordPress plugin ecosystem.

On September 3rd and 4th, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, highlighting a widespread security concern for the platform's extensive ecosystem. These vulnerabilities, spanning critical, high, and medium severity ratings, were disclosed within a 14-hour window, indicating a coordinated or closely timed discovery and reporting cycle. The disclosures include issues such as privilege escalation, cross-site scripting (XSS), broken access control, and insecure direct object references (IDOR), affecting popular plugins like WPFunnels, LearnPress, and Quick Event Manager. The sheer volume and variety of these vulnerabilities underscore the persistent need for diligent security practices among WordPress site administrators and developers.

Several plugins were found to have critical or high-severity flaws that could lead to significant compromise. The ACPT (Premium) plugin, in versions up to 2.0.66, suffers from a critical privilege escalation vulnerability (CVE-2026-15354) due to missing authorization in its submit() function, allowing unauthenticated users to manipulate the target user ID before user updates. Similarly, Quick Event Manager, in versions up to 9.17, has a high-severity unauthenticated XSS vulnerability (CVE-2026-84848) and a high-severity broken access control vulnerability (CVE-2026-84847). WC Ukraine Shipping, up to version 1.22.3, has a high-severity Subscriber IDOR vulnerability (CVE-2026-84836). These specific vulnerabilities pose immediate threats due to their unauthenticated nature and potential for severe impact.

Other notable vulnerabilities include a file deletion flaw in the Frontend Admin plugin (CVE-2026-81347), where unauthenticated attackers could delete critical files like index.php and .htaccess, potentially rendering sites inoperable. The WPFunnels plugin is implicated in multiple vulnerabilities, including unauthorized email sending (CVE-2026-79632), exposure of sensitive log data (CVE-2026-79631), and product discount manipulation during checkout (CVE-2026-79630). Furthermore, the Pods plugin (CVE-2026-74853) has a vulnerability allowing users with the author role to read arbitrary files, and the Hummingbird Performance plugin (CVE-2026-19224) has a critical flaw enabling site administrators to execute arbitrary code across an entire multisite network.

The batch also includes several medium-severity issues. LearnPress plugin versions before 4.4.6 are affected by a stored XSS vulnerability (CVE-2026-82024) and a broken object-level authorization flaw (CVE-2026-82023), both exploitable by authenticated instructors. Plugins like Ultimate Maps by Supsystic (CVE-2026-85309), SureForms (CVE-2026-85308), MountDev AI MCP Connector for WordPress (CVE-2026-85306), and Unlimited Elements for Elementor (CVE-2026-85304) suffer from missing authorization vulnerabilities. SEOPress (CVE-2026-85305) has an SSRF vulnerability, while Booking and Rental Manager (CVE-2026-85303) and WPKoi Templates for Elementor (CVE-2026-85302) have stored and DOM-based XSS vulnerabilities, respectively. Pre-Orders for WooCommerce (CVE-2026-84849) has an unauthenticated bypass vulnerability.

The affected versions for many of these plugins have been patched. For instance, Frontend Admin is fixed in version 3.29.13, Ninja Forms in 3.15.2, and WPFunnels in 3.13.0. Pods is patched in 3.3.9.2, and Hummingbird Performance in 3.21.2. Content Views is fixed in 4.5.1.2, and Classified Listing in 6.1.1. ACPT (Premium) is patched in version 2.0.67. LearnPress is updated to 4.4.6. For plugins where specific version numbers for fixes are not detailed in the initial reports, users are advised to update to the latest available versions. Administrators should consult the respective plugin changelogs and vendor advisories for detailed information on patches and affected versions.

This coordinated disclosure event serves as a stark reminder of the security challenges inherent in the WordPress ecosystem, where a single vulnerability in a popular plugin can have widespread implications. Users are strongly encouraged to audit their installed plugins, apply updates promptly, and maintain regular backups. The continuous stream of vulnerabilities across various plugins necessitates a proactive security posture, including the use of security plugins and regular security scans, to mitigate risks associated with unpatched or vulnerable components. Staying informed about security advisories and acting swiftly on patching is crucial for maintaining the integrity and security of WordPress websites.

The vulnerabilities disclosed include:

Users are urged to update affected plugins immediately to mitigate these security risks. The affected plugins and their fixed versions include Frontend Admin (3.29.13), Ninja Forms (3.15.2), WPFunnels (3.13.0), Pods (3.3.9.2), Hummingbird Performance (3.21.2), Content Views (4.5.1.2), Classified Listing (6.1.1), ACPT (Premium) (2.0.67), LearnPress (4.4.6), Ultimate Maps by Supsystic (1.5.4), SureForms (2.12.6), KP Agent Ready (1.2.08), MountDev AI MCP Connector for WordPress (1.6.6), SEOPress (10.2), Unlimited Elements for Elementor (2.0.18), Booking and Rental Manager (2.7.8), WPKoi Templates for Elementor (3.7.3), Pre-Orders for WooCommerce (2.4), Quick Event Manager (9.18), and WC Ukraine Shipping (1.23). For plugins where specific updated versions are not listed, users should refer to the vendor's official release notes.

AI-written article. Grounded in 25 CVE records listed below.