VYPR
advisoryPublished Aug 30, 2026· 1 source

WordPress Plugins: 25 Vulnerabilities Disclosed, Including Critical Auth Bypass and RCE Flaws

Key findings • 25 WordPress plugins disclosed with vulnerabilities between August 29-30, 2026. • Multiple critical vulnerabilities include authentication bypass, RCE, and privilege escalation…

Key findings

  • 25 WordPress plugins disclosed with vulnerabilities between August 29-30, 2026.
  • Multiple critical vulnerabilities include authentication bypass, RCE, and privilege escalation.
  • Stored XSS flaws affect plugins like Groundhogg and Customer Reviews for WooCommerce.
  • High-severity issues impact SAML SSO, appointment booking, and user profile builder plugins.
  • Patches are available for most affected plugins; immediate updates are recommended.

On August 29-30, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with a notable cluster of critical and high-severity flaws impacting essential functionalities like authentication, code execution, and data handling. These disclosures highlight ongoing security challenges within the extensive WordPress plugin ecosystem, underscoring the need for diligent patching and security auditing by site administrators.

Several plugins were found to have critical vulnerabilities. CVE-2026-15980, affecting MyHome Core up to version 4.4.5, allows for authentication bypass through improper token validation and missing authorization checks in its AJAX handlers. Similarly, CVE-2026-14494 in Sigma Forms Pro (up to 1.4.5) enables remote code execution by dynamically granting unfiltered upload capabilities and bypassing MIME type validation during form submissions. Custom User Registration Fields for WooCommerce (up to 2.2.3) suffers from a privilege escalation flaw (CVE-2026-15369) where unauthenticated users can manipulate user roles via the WooCommerce Store API. The 爱采集数据采集和发布插件 (up to 1.0.0) has a critical vulnerability (CVE-2026-77012) allowing unauthenticated attackers to read arbitrary files and potentially execute code due to a missing per-install secret and inadequate URL validation.

High-severity issues were also prevalent. The SAML Single Sign On – SSO Login plugin (up to 5.4.6) has an authentication bypass vulnerability (CVE-2026-75807) related to the handling of X.509 certificates. The Appointment Booking Calendar Plugin and Scheduling Plugin (before 1.6.3) contains a flaw (CVE-2026-76586) where unauthenticated users can confirm paid appointments for a fraction of the price by not properly verifying the amount paid against the server-side price. User Profile Builder (before 4.0.1) has a high-severity vulnerability (CVE-2026-76548) that improperly restricts its front-end file upload feature, allowing unauthenticated visitors to access and modify media library items and unpublished content. The HEL Online Classroom plugin (through 1.0.3) has multiple vulnerabilities, including CVE-2026-77007, a high-severity flaw allowing unauthenticated users to retrieve stored settings, including a shared secret for API requests to a BigBlueButton server.

A number of plugins were affected by stored cross-site scripting (XSS) vulnerabilities, typically allowing unauthenticated users to inject malicious scripts. These include Groundhogg — CRM, Newsletters, and Marketing Automation (before 4.5.13, CVE-2026-81660), MW WP Form (before 5.1.6, CVE-2026-78364), Customer Reviews for WooCommerce (before 5.118.0, CVE-2026-76585), and SOGO Add Script to Individual Pages Header Footer (through 3.9, CVE-2026-14835). Additionally, CVE-2026-14307 in the geotargetingwp plugin (before 3.5.6.2) allows unauthenticated attackers to inject scripts via crafted requests that are reflected in AJAX responses.

Other notable vulnerabilities include an arbitrary code execution flaw in the Really Simple Security plugin (before 9.8.0, CVE-2026-81766) due to insufficient checks before installing plugins from user-supplied URLs, and a file write vulnerability in WPvivid — Backup, Migration & Staging (before 0.9.133, CVE-2026-19722) allowing administrators to write arbitrary files during backup restoration. The MasterStudy LMS plugin is affected by multiple issues: CVE-2026-81342 (medium) allows unauthenticated redirection, CVE-2026-81200 (low) permits instructors to view other users' order details, and CVE-2026-81026 (medium) allows unauthenticated users to complete orders by manipulating payment notifications. SQL injection was found in WP Ultimate CSV Importer (before 9.0, CVE-2026-80488), and a medium-severity vulnerability in Stripe Payment Forms by WP Full Pay (before 8.5.5, CVE-2026-80311) allows users to cancel other customers' subscriptions. Rank Math SEO (before 1.0.277, CVE-2026-77786) allowed editors to change administrator-level settings, and Booking for Appointments and Events Calendar (before 2.4.9, CVE-2026-77704) allowed customers to change appointment statuses. The HEL Online Classroom plugin also has medium-severity flaws (CVE-2026-77010 and CVE-2026-77008) related to unauthorized access to meeting links and settings manipulation.

The majority of these vulnerabilities were patched by their respective developers, with affected versions and patch details provided in the CVE descriptions. WordPress site administrators are strongly advised to review the specific plugins they are using and update them to the latest available versions to mitigate these risks. The sheer volume and severity of this batch underscore the critical importance of timely updates and proactive security management within the WordPress ecosystem.

The disclosures occurred between August 29 and August 30, 2026.

CVE-2026-81766, CVE-2026-81660, CVE-2026-78364, CVE-2026-76585, CVE-2026-19722, CVE-2026-14835, CVE-2026-14307, CVE-2026-15980, CVE-2026-15369, CVE-2026-75807, CVE-2026-14494, CVE-2026-81346, CVE-2026-81342, CVE-2026-81200, CVE-2026-81026, CVE-2026-80488, CVE-2026-80311, CVE-2026-77786, CVE-2026-77704, CVE-2026-77012, CVE-2026-77010, CVE-2026-77008, CVE-2026-77007, CVE-2026-76586, CVE-2026-76548

Synthesized by Vypr AI