WordPress: 25 Plugin and Theme Vulnerabilities Disclosed in Single Batch
Key findings • 25 vulnerabilities disclosed in WordPress plugins and themes on August 25, 2026. • Vulnerabilities include XSS, privilege escalation, SQLi, file upload, and auth bypass. • …

Key findings
- 25 vulnerabilities disclosed in WordPress plugins and themes on August 25, 2026.
- Vulnerabilities include XSS, privilege escalation, SQLi, file upload, and auth bypass.
- Critical severity flaw in Jawn theme allows unauthenticated admin access.
- MasterStudy LMS and CM Map Locations plugins affected by file manipulation issues.
- Patches are available; users urged to update affected plugins and themes immediately.
On August 25, 2026, a significant batch of 25 vulnerabilities affecting various WordPress plugins and themes was disclosed. This coordinated disclosure event highlights ongoing security challenges within the extensive WordPress ecosystem. The vulnerabilities span multiple categories, including cross-site scripting (XSS), privilege escalation, SQL injection, arbitrary file upload, and authorization bypass, with severities ranging from medium to critical.
Several plugins were found to have Stored Cross-Site Scripting (XSS) vulnerabilities due to insufficient input sanitization and output escaping. These include TranslatePress (CVE-2026-18512), Forminator Forms (CVE-2026-18323), MetForm (CVE-2026-18100), tagDiv Composer (CVE-2026-12561), FundEngine (CVE-2026-76063), Gutenverse (CVE-2026-19943), Cozy Blocks (CVE-2026-75019), and PPWP (CVE-2025-9878). These flaws could allow authenticated attackers to inject malicious scripts into websites, which are then rendered by other users.
High-severity vulnerabilities were also prominent. The CM Map Locations plugin (CVE-2026-16601) suffers from limited arbitrary file upload due to inadequate file type validation. The Mane theme (CVE-2026-78478) has a Local File Inclusion vulnerability, enabling unauthenticated attackers to include and execute arbitrary files on the server. A critical privilege escalation vulnerability was found in the Jawn theme (CVE-2026-78477), allowing unauthenticated attackers to gain administrator privileges. Additionally, InfusedWoo Pro (CVE-2026-19892) has a privilege escalation flaw via account takeover due to a missing capability check. MasterStudy LMS (CVE-2026-78284) has an unauthenticated arbitrary file deletion vulnerability.
Other notable vulnerabilities include SQL Injection flaws in WP Project Manager Pro (CVE-2026-78470) and Events Manager (CVE-2026-15023), which could allow authenticated attackers to manipulate database queries. Several plugins, such as Fluent Support Pro (CVE-2026-78467), Fluent Boards Pro (CVE-2026-78466), FundEngine (CVE-2026-75930), LearnPress (CVE-2026-75982), BetterLinks (CVE-2026-19801), and WP Courses LMS (CVE-2026-10630), are affected by authorization bypass or insecure direct object reference (IDOR) issues, enabling authenticated users to perform unauthorized actions. Events Manager also has a Local File Inclusion vulnerability (CVE-2026-14280) and an authorization bypass (CVE-2026-10627). Forminator Forms also has a DOM-based reflected XSS vulnerability (CVE-2026-18328). Events Manager also has a reflected XSS vulnerability (CVE-2026-17089).
The majority of these vulnerabilities were patched in updates released on or around August 25, 2026. Users are strongly advised to update the affected plugins and themes to their latest versions to mitigate these risks.
This batch of disclosures underscores the importance of regular security audits and timely patching for WordPress sites. The sheer number and variety of vulnerabilities highlight the complex security landscape of the WordPress ecosystem, where a single disclosure event can impact numerous components. website administrators should remain vigilant and apply updates promptly.