WordPress Plugins: 25 Vulnerabilities Including Critical SQLi and Object Injection Disclosed Together
A batch of 25 WordPress plugin vulnerabilities, including critical and high-severity flaws like SQL Injection and Object Injection, were disclosed on October 7-8, 2026.

Key findings
- 25 WordPress plugins disclosed with vulnerabilities between Oct 7-8, 2026, including critical and high-severity flaws.
- Key vulnerabilities include PHP Object Injection, SQL Injection, and multiple XSS flaws across various plugins.
- Critical flaws found in The Events Calendar (CVE-2026-95606) and WP Data Access (CVE-2026-95605).
- Multiple high-severity SQL Injection vulnerabilities affect plugins like 10Web Slider and WP Post Author.
- Users urged to update all affected plugins immediately to patch these vulnerabilities.
On October 7-8, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with several critical and high-severity flaws identified. This coordinated disclosure event highlights ongoing security challenges within the extensive WordPress plugin ecosystem. The vulnerabilities span multiple categories, including PHP Object Injection, SQL Injection, Cross-Site Scripting (XSS), and Missing Authorization, impacting a wide range of plugin functionalities.
Several plugins were affected by critical or high-severity vulnerabilities. The Uncanny Automator plugin (versions up to 7.6.1.1) is vulnerable to PHP Object Injection (CVE-2026-82627, High, 7.5), allowing authenticated attackers to execute arbitrary code. Similarly, The Events Calendar (versions up to 6.17.4) suffers from a critical PHP Object Injection flaw (CVE-2026-95606, Critical, 9.8), and WP Data Access (versions up to 5.5.82) has a critical Blind SQL Injection vulnerability (CVE-2026-95605, Critical, 9.3).
A notable cluster of high-severity SQL Injection vulnerabilities (CVSSv3 7.6) were disclosed on October 7th, affecting multiple plugins including 10Web Slider (CVE-2026-42710), AF themes WP Post Author (CVE-2026-42708), Pix por Piggly (CVE-2026-42714), Post title marquee scroll (CVE-2026-42713), and affiliate-toolkit (CVE-2026-42716). These flaws, if exploited, could allow attackers to manipulate or extract sensitive data from databases.
Cross-Site Scripting (XSS) vulnerabilities were also prevalent, with multiple plugins affected by stored and reflected XSS. Medium-severity XSS flaws were found in Aurora Heatmap (CVE-2026-94154), Disable and Remove Google Fonts (CVE-2026-95595), Everest Forms (CVE-2026-94670), Media LIbrary Assistant (CVE-2026-97294), WP Media Rocket Lazy Load (CVE-2026-105884), BdThemes Prime Slider (CVE-2026-105875), BdThemes Element Pack (CVE-2026-105873, CVE-2026-105871), Happy Addons for Elementor (CVE-2026-104393), and Quiz And Survey Master (CVE-2026-104391). Additionally, Unlimited Elements for Elementor (versions up to 2.0.19) has both a high-severity Stored XSS (CVE-2026-94662) and a high-severity Object Injection vulnerability (CVE-2026-95534).
Missing Authorization vulnerabilities, allowing exploitation of incorrectly configured access control, were identified in WPMU DEV Forminator (CVE-2026-96335, High, 7.5), sc Internet Vivoo WP Rentals (CVE-2026-27434, Medium, 5.3), and WP Chill Modula Image Gallery (CVE-2026-105876, Medium, 5.3).
The majority of these vulnerabilities were patched by their respective developers. Users are strongly advised to update all affected plugins to their latest versions to mitigate these risks. Specific version information for patches is available in the detailed advisories for each plugin.
This batch of disclosures underscores the critical need for continuous security vigilance within the WordPress ecosystem. Users should prioritize updating plugins, especially those with high or critical severity ratings, to protect their sites from potential compromise. The sheer volume and variety of vulnerabilities highlight the importance of regular security audits and prompt patching.