WordPress Plugins: 25 Vulnerabilities Disclosed, Including Critical Unauthenticated Flaws
A batch of 25 WordPress plugin vulnerabilities, including critical unauthenticated SQLi, RCE, and privilege escalation flaws, were disclosed on August 19, 2026.

Key findings
- 25 WordPress plugin vulnerabilities disclosed on August 19, 2026, spanning Critical to Medium severity.
- Multiple critical vulnerabilities include unauthenticated SQL Injection, Privilege Escalation, PHP Object Injection, and RCE.
- Many flaws allow unauthenticated access, posing a significant risk to WordPress sites.
- Affected plugins range from e-commerce and booking to SEO and user tracking tools.
- Urgent updates are required for all affected plugins to patch these security holes.
On August 19, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with disclosure times spanning a six-hour window. These vulnerabilities range in severity from Medium to Critical, with many allowing for unauthenticated attacks. The sheer volume and severity of these flaws highlight a widespread security concern within the WordPress plugin ecosystem.
Several critical vulnerabilities were identified, including SQL Injection, Privilege Escalation, and PHP Object Injection. Specifically, Total Donations versions up to 2.0.5 are affected by unauthenticated SQL Injection (CVE-2026-73391) and Privilege Escalation (CVE-2026-73390), both rated Critical. Kalles Addons up to version 1.0.6 suffer from unauthenticated PHP Object Injection (CVE-2026-73389), also a Critical severity flaw. Nikstore Core up to 1.5 has an unauthenticated SQL Injection vulnerability (CVE-2026-73388), and Flexible Subscriptions up to 1.8.1 contains a customer PHP Object Injection flaw (CVE-2026-73364), both rated Critical. Additionally, JetEngine up to 3.8.14 has a Critical unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2026-66613). TrueBooker up to 1.2.6 is affected by an unauthenticated Privilege Escalation vulnerability (CVE-2026-73347).
Other notable vulnerabilities include unauthenticated Broken Access Control flaws in Stitch Express (CVE-2026-73394) and Outranking Plugin Options (CVE-2026-73385), both rated High. Sensitive Data Exposure vulnerabilities were found in Track Geolocation Of Users Using Contact Form 7 (CVE-2026-73386) and Pay with Contact Form 7 (CVE-2026-73384), both High severity. Local File Inclusion affects Resido up to 1.5 (CVE-2026-73387).
Cross-Site Scripting (XSS) vulnerabilities were prevalent, with High severity flaws found in SimplyRETS Real Estate IDX (CVE-2026-73354), Global Gallery (CVE-2026-73184), BBQ Pro (CVE-2026-73182), Newsletter (CVE-2026-66596), and Contest Gallery (CVE-2026-61986). TranslatePress – Translate Multilingual sites with AI Translation plugin is vulnerable to Stored XSS (CVE-2026-75981), and WP Statistics plugin is vulnerable to Stored XSS via the 'utm_campaign' parameter (CVE-2026-15780), both rated High. EWWW Image Optimizer (CVE-2026-15446) has a Medium severity Stored XSS vulnerability.
SQL Injection vulnerabilities also appeared in Maps Marker Pro (CVE-2026-73183) and NGG Smart Image Search (CVE-2026-73185), both Critical. Community by PeepSo (CVE-2026-66668) and YITH WooCommerce Membership Premium (CVE-2026-32552) have High severity Subscriber SQL Injection flaws. Taxi Booking Manager for WooCommerce versions prior to 2.0.8 have a Medium severity Broken Access Control vulnerability (CVE-2026-73363).
The majority of these vulnerabilities appear to be unauthenticated, meaning attackers can exploit them without needing any user credentials. The affected versions vary across plugins, with many issues present in older versions. Users are strongly advised to update their plugins to the patched versions as soon as possible to mitigate these risks.
This coordinated disclosure event underscores the importance of diligent security practices for WordPress users, including regular plugin updates and security audits. The wide range of vulnerabilities and affected plugins suggests a need for increased scrutiny of plugin security by both developers and users.
The affected plugins and their respective versions are as follows: Stitch Express <= 1.9.0, Total Donations <= 2.0.5, Kalles Addons <= 1.0.6, Nikstore Core <= 1.5, Resido <= 1.5, Track Geolocation Of Users Using Contact Form 7 <= 3.0.2, Outranking Plugin Options <= 1.1.3, Pay with Contact Form 7 <= 1.0.4, Flexible Subscriptions <= 1.8.1, Taxi Booking Manager for WooCommerce < 2.0.8, SimplyRETS Real Estate IDX <= 3.2.8, TrueBooker <= 1.2.6, NGG Smart Image Search < 4.0.0, Global Gallery <= 11.1.2, Maps Marker Pro <= 4.32, BBQ Pro <= 3.9, JetEngine <= 3.8.14, Newsletter <= 9.3.3, Contest Gallery <= 30.0.5, Community by PeepSo <= 9.0.5.2, YITH WooCommerce Membership Premium <= 2.33.0, TranslatePress – Translate Multilingual sites with AI Translation plugin <= 3.2.5, WP Statistics plugin <= 14.16.8, and EWWW Image Optimizer <= 8.7.3. Patches for these vulnerabilities have been released by the respective plugin developers.