WordPress Plugins: 25 Vulnerabilities Disclosed, Including Critical Auth Bypass and Code Execution Flaws
A batch of 25 WordPress plugin vulnerabilities disclosed on August 22-23, 2026, includes critical flaws enabling site takeovers and arbitrary code execution.

Key findings
- 25 WordPress plugins disclosed with vulnerabilities between August 22-23, 2026.
- Multiple critical flaws allow unauthenticated attackers to gain administrator privileges.
- PHP Object Injection and SSRF vulnerabilities present in several plugins.
- Forminator Forms plugin has critical flaws enabling network-wide code execution and admin role assignment.
- Affected plugins range from form builders to social login and PDF invoice generators.
- Immediate updates to all affected plugins are crucial for website security.
On August 22-23, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, impacting a wide range of functionalities from form building to user authentication and content management. These vulnerabilities, disclosed over a two-day period, highlight persistent security weaknesses in the WordPress ecosystem, with several allowing for privilege escalation and site takeover. The disclosures were made by multiple researchers and security firms, indicating a broad and ongoing effort to uncover flaws in popular WordPress extensions.
Several plugins were found to suffer from broken access control or missing capability checks, allowing lower-privileged users to perform administrative actions. CVE-2026-77116, affecting Brave Popup Builder, allowed any logged-in user to access restricted popup content. Similarly, CVE-2026-77003 (Content Mask) and CVE-2026-14853 (WooCommerce Bookings) enabled contributors and subscribers to publish posts or create draft bookable products, respectively, without proper authorization.
A particularly dangerous class of vulnerabilities involved PHP Object Injection, with CVE-2026-0551 (PPWP – Password Protect Pages) and CVE-2026-4703 (WS Form LITE) allowing authenticated and unauthenticated attackers, respectively, to inject malicious code through deserialization flaws. CVE-2026-19221, affecting Forminator Forms, presented a critical risk on multisite networks, enabling a site administrator to execute arbitrary code across the entire network.
Authentication bypass vulnerabilities were also prevalent. CVE-2026-13598 (RestrictMate), CVE-2026-77002 (SmilePass Selfie Login), CVE-2026-77001 (Social Login & Sharing buttons By SoClever), CVE-2026-77000 (WP Social Media Login), and CVE-2026-76793 (Firebase Authentication) all allowed unauthenticated attackers to gain administrator privileges by exploiting flaws in login and authentication handlers. CVE-2026-19222 (Forminator Forms) also allowed form builders to assign administrator roles to any visitor.
Other notable vulnerabilities include a Directory Traversal flaw in WebToffee WooCommerce PDF Invoices (CVE-2026-18027), Stored Cross-Site Scripting (XSS) in MC4WP: Mailchimp for WordPress (CVE-2026-4561) and Image Photo Gallery Final Tiles Grid (CVE-2026-4559), and arbitrary shortcode execution in kk Star Ratings (CVE-2026-3424). The Security Hardener plugin (CVE-2026-16149) suffered from Missing Authorization, and the Post Duplicator plugin had multiple authorization bypass and unauthorized data modification issues (CVE-2026-4244, CVE-2026-4245).
The affected plugins include Brave Popup Builder (versions through 0.8.5), Content Mask (before 1.8.5.5), WooCommerce Bookings (before 3.9.0), RestrictMate (before 1.3.0), WebToffee WooCommerce PDF Invoices (through 4.9.8), Security Hardener (through 2.4.4), PPWP – Password Protect Pages (through 1.9.18), WS Form LITE (through 1.10.80), GreenShift (through 12.8.9), MC4WP: Mailchimp for WordPress (through 4.12.0), Image Photo Gallery Final Tiles Grid (through 3.6.12), Advanced Product Fields for WooCommerce (through 1.6.21), Post Duplicator (through 3.0.11), The kk Star Ratings (through 5.4.10.3), Mailgun for WordPress (up to 2.2.0), SmilePass Selfie Login (through 1.0.2), Social Login & Sharing buttons By SoClever (through 1.2.0), WP Social Media Login (through 1.0.6), Firebase Authentication (before 1.7.1), Slider Hero with Video Background, Animation (before 9.1.3), Forminator Forms (before 1.57.0.7 and 1.57.0.5), and Tutor LMS (before 4.0.6). Users are strongly advised to update these plugins to their patched versions immediately to mitigate the risks associated with these critical security flaws.
This extensive disclosure underscores the importance of regular security audits and prompt patching for all WordPress installations. The sheer number and severity of these vulnerabilities, particularly those leading to full site takeover, emphasize the need for vigilance within the WordPress community. Users should prioritize updating the affected plugins to their latest versions, as provided by the respective developers, to safeguard their websites against these threats.
The batch of vulnerabilities disclosed between August 22-23, 2026, highlights critical security gaps in numerous WordPress plugins. The most severe issues include multiple instances of authentication bypass and PHP object injection, enabling full site takeovers.
The vulnerabilities span a wide range of plugin functionalities, including form builders, user registration, social login, and content management.
Several plugins allowed unauthenticated attackers to gain administrator privileges, posing a severe risk to website security.
PHP Object Injection flaws in plugins like PPWP and WS Form LITE could lead to arbitrary code execution.
The disclosure includes critical vulnerabilities in Forminator Forms, with one allowing network-wide code execution on multisite installations.
Users are urged to update affected plugins to their latest versions to patch these security holes. CVE-2026-77116, CVE-2026-77115, CVE-2026-77003, CVE-2026-14853, CVE-2026-13598, CVE-2026-18027, CVE-2026-16149, CVE-2026-0551, CVE-2026-4703, CVE-2026-5093, CVE-2026-4561, CVE-2026-4559, CVE-2026-2996, CVE-2026-4244, CVE-2026-4245, CVE-2026-3424, CVE-2026-78003, CVE-2026-77002, CVE-2026-77001, CVE-2026-77000, CVE-2026-76793, CVE-2026-76789, CVE-2026-19222, CVE-2026-19221, CVE-2026-19093