VYPR
AI Brief2026-08-08· generated Aug 8, 2026

WordPress Plugins Hit by Critical RCE and Backdoor Flaws

Critical vulnerabilities plague WordPress plugins with RCE and backdoor capabilities, alongside compromised update servers and flaws in Qflksheep, OpenReception, and Apache CXF.

A wave of critical vulnerabilities has been disclosed across multiple WordPress plugins, with several allowing unauthenticated attackers to achieve remote code execution or arbitrary file uploads. Notably, the Premium SEO plugin (CVE-2026-14812) and Spider Analyser (CVE-2026-65553) are among those with RCE capabilities. Additionally, the official MonsterInsights Pro update distribution channel was compromised, injecting malicious code into plugin versions 10.2.2 and 10.2.0 (CVE-2026-11976). Multiple other plugins are affected by unauthenticated PHP object injection flaws, including AI ANN (CVE-2026-65581), Agora (CVE-2026-65578), Advice (CVE-2026-65577), Accalia (CVE-2026-65575), Abelle (CVE-2026-65573), A.Williams (CVE-2026-65572), WPBruiser (CVE-2026-65556), and Export User Data (CVE-2026-65552). The Betheme theme (CVE-2026-65548) and AIWU plugin (CVE-2026-65507) also suffer from critical RCE and privilege escalation, respectively. As Wordfence reported, these issues pose a significant risk to WordPress sites.

Critical vulnerabilities have been identified in Qflksheep products, including an SQL injection in FineAdmin V1.0 (CVE-2026-67689) and an unrestricted file upload in ICS-Park Smart Park Management System v2.0 (CVE-2026-67688), both of which can lead to arbitrary code execution.

OpenReception's appointment booking software has two critical vulnerabilities. The first (CVE-2026-48086) allows a TENANT_ADMIN to promote themselves to a platform-wide GLOBAL_ADMIN, while the second (CVE-2026-48085) enables unauthenticated users to create an admin account. Both issues are fixed in later versions.

A flaw in Apache CXF's DefaultEncryptingCodeDataProvider (CVE-2026-68079) allows for unlimited redemption of captured authorization codes due to an improper implementation of the removeCodeGrant functionality, violating RFC requirements.

Synthesized by Vypr AI
WordPress Plugins Hit by Critical RCE and Backdoor Flaws · VYPR