VYPR
advisoryPublished Oct 3, 2026· Updated Oct 4, 2026· 1 source

WordPress Plugins: 25 Vulnerabilities Disclosed in Single Batch, Including Critical Flaws

Key findings • 25 WordPress plugins disclosed with vulnerabilities on October 3, 2026, including critical and high severity flaws. • Vulnerabilities span authorization bypass, XSS, SQL inject…

Key findings

  • 25 WordPress plugins disclosed with vulnerabilities on October 3, 2026, including critical and high severity flaws.
  • Vulnerabilities span authorization bypass, XSS, SQL injection, arbitrary file operations, and shortcode execution.
  • Affected plugins include Ultimate Member, Beaver Builder, WPCafe, and many others, with various fixed versions.
  • Critical flaws like arbitrary file deletion (CVE-2026-87115) and shortcode execution (CVE-2026-92084) pose significant risks.
  • Users must update all affected plugins promptly to mitigate these widespread security issues.

On October 3, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with a notable cluster of high and critical severity flaws impacting core functionalities. These vulnerabilities, disclosed within a 10-hour window, span across multiple plugin types, including authorization bypass, cross-site scripting (XSS), SQL injection, and arbitrary file operations, posing a considerable risk to WordPress site security. The sheer volume and diversity of these issues underscore the ongoing need for diligent security practices within the WordPress ecosystem.

Several plugins were found to have authorization bypass vulnerabilities, allowing privilege escalation or unauthorized access to functionalities. CVE-2026-96451 in Ultimate Member (versions up to 2.13.1) and CVE-2026-94505 in Nelio Content (versions up to 4.5.0) allow authenticated attackers to escalate privileges. Additionally, CVE-2026-11601 in WPCafe (versions up to 3.0.19) and CVE-2026-97343 in Burst Statistics (versions up to 3.7.1) also suffer from authorization flaws, with the latter potentially leading to account persistence.

Cross-site scripting (XSS) vulnerabilities were prevalent, with multiple plugins affected by stored and reflected XSS. CVE-2026-103342 in Unlimited Elements for Elementor and CVE-2026-92767 in Twenty20 Image Before-After (versions up to 2.0.5) are examples of reflected and stored XSS, respectively. CVE-2026-97660 in WPC Product Options for WooCommerce and CVE-2026-93889 in Mail logging – WP Mail Catcher also contain stored XSS flaws. Reflected XSS was also identified in CVE-2026-93896 (WPFront Notification Bar, up to 3.5.1), CVE-2026-92974 (Photo Gallery by 10Web, up to 1.8.46), and CVE-2026-104313 (WPC Estimated Delivery Date for WooCommerce, up to 4.0.1). CVE-2026-97344 in Wp Social Login and Register Social Counter (up to 3.2.1) and CVE-2026-103421 in WPMobile.App (up to 11.84) also present stored XSS risks. CVE-2026-97341 in Visitor Traffic Real Time Statistics (up to 8.16) is a DOM-based XSS vulnerability.

Critical and high severity vulnerabilities also include arbitrary shortcode execution and SQL injection flaws. CVE-2026-92084 and CVE-2026-100157 in The Beaver Builder Page Builder (up to 2.11.0.5) and The WP Ultimate Review (up to 2.4.3) respectively, allow arbitrary shortcode execution. SQL injection vulnerabilities were found in CVE-2026-96267 (WP Visitor Statistics, up to 8.7) and CVE-2026-15795 (Smart Manager, up to 8.97.0). Furthermore, CVE-2026-13065 in Kirki (up to 6.3.1) involves improper validation of input, and CVE-2026-87115 in VikAppointments Services Booking Calendar (up to 1.2.21) allows arbitrary file deletion. CVE-2026-75028 in WPCafe (up to 3.0.18) is susceptible to Local File Inclusion.

The batch also includes medium severity vulnerabilities such as CVE-2026-103065 in Kirki (up to 6.3.1) for improper validation of input, CVE-2026-15795 in Responsive Plus (up to 3.5.3) for stored XSS, and CVE-2026-193519 in The WP Ultimate Review (up to 2.4.3) for arbitrary shortcode execution. CVE-2026-97344 in Wp Social Login and Register Social Counter (up to 3.2.1) has stored XSS, and CVE-2026-103421 in WPMobile.App (up to 11.84) also has stored XSS. CVE-2026-97341 in Visitor Traffic Real Time Statistics (up to 8.16) has DOM-based XSS. CVE-2026-97337 in Simple Membership (up to 4.8.3) allows unauthorized data modification and information disclosure. Finally, CVE-2026-96962 (Pie Register, before 3.8.4.14) is a low severity vulnerability allowing unauthenticated users to access user registration data via invitation codes.

The affected plugins have various fixed versions, with many patched in releases immediately following the disclosed vulnerabilities. Users are strongly advised to update all instances of the listed plugins to their latest available versions to mitigate these security risks. Regular security audits and prompt patching are crucial for maintaining the integrity and security of WordPress websites.

This coordinated disclosure highlights the persistent threats within the WordPress plugin ecosystem. The wide range of vulnerabilities, from critical remote code execution to lower-severity information disclosure, necessitates a proactive security posture from all WordPress site administrators. Staying informed about disclosed vulnerabilities and applying patches promptly remains the most effective defense against these ongoing threats.

Synthesized by Vypr AI