VYPR
patchPublished Sep 26, 2026· 1 source

WordPress Plugins: 25 Vulnerabilities Disclosed, Including RCE and Stored XSS

Key findings • 25 WordPress plugins disclosed with vulnerabilities between Sept 25-26, 2026. • Flaws include RCE, Privilege Escalation, and multiple Stored XSS vulnerabilities. • Affected…

Key findings

  • 25 WordPress plugins disclosed with vulnerabilities between Sept 25-26, 2026.
  • Flaws include RCE, Privilege Escalation, and multiple Stored XSS vulnerabilities.
  • Affected plugins range from LMS and form builders to gallery and security plugins.
  • Critical issues like RCE in s2Member (CVE-2026-19804) and file deletion in Modula Gallery (CVE-2026-92713) require immediate attention.
  • Patches are available for most affected plugins; prompt updates are essential.

On September 25, 2026, a significant batch of 25 vulnerabilities was disclosed across various WordPress plugins, with a single CVE, CVE-2026-15273, disclosed on September 26th. This cluster of vulnerabilities, spanning a 20-hour window, highlights a broad range of security weaknesses affecting popular WordPress extensions. The disclosures include critical and high-severity flaws such as Remote Code Execution, Privilege Escalation, Stored Cross-Site Scripting (XSS), and arbitrary file deletion, posing substantial risks to WordPress site administrators and users.

Several plugins were found to be vulnerable to Stored Cross-Site Scripting (XSS), a common web vulnerability where attackers can inject malicious scripts into web pages viewed by other users. This batch includes multiple instances of Stored XSS affecting plugins like Automatic.css (CVE-2026-15273), Zero Spam for WordPress (CVE-2026-96752), Restaurant Menu and Food Ordering (CVE-2026-96568), User Profile Builder (CVE-2026-95866, CVE-2026-93656), Themify Builder (CVE-2026-95864), Repeater Fields for Elementor Forms (CVE-2026-94573), wpForo Forum (CVE-2026-93747), Fancy Product Designer (CVE-2026-84280), WP Maps (CVE-2026-13179), and GeoDirectory (CVE-2026-96766). These vulnerabilities often stem from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject scripts that execute when administrators interact with affected features.

Privilege Escalation vulnerabilities were also a prominent theme in this disclosure batch. The Knit Pay plugin (CVE-2026-89426) allows users to escalate their privileges by manipulating Gravity Forms entry fields to change their user role. Similarly, the Optima Express IDX plugin (CVE-2026-93901) contains a flaw in its AJAX action that can lead to privilege escalation, allowing unauthorized users to gain higher access levels.

Beyond XSS and privilege escalation, other critical vulnerabilities were identified. The s2Member plugin (CVE-2026-19804) is susceptible to Remote Code Execution (RCE) due to insufficient sanitization of the 'first_name' parameter, a severe flaw that could allow attackers to execute arbitrary code on the server. The Modula Image Gallery plugin faces two distinct issues: arbitrary file deletion (CVE-2026-92713) due to improper file path validation and unauthorized disclosure of private gallery contents (CVE-2026-89406) by improperly handling frontend requests. Additionally, the WP Maps plugin (CVE-2026-13456) suffers from Local File Inclusion, enabling authenticated attackers to read sensitive files on the server.

The batch also includes vulnerabilities related to security bypass and information disclosure. The MasterStudy LMS plugin (CVE-2026-88848) allows members to enroll in restricted paid courses without proper verification. The wpForo Forum plugin (CVE-2026-80514) has a rate-limiting bypass that could be exploited by spoofing IP headers, potentially exhausting site owner's AI credits. The SSL Zen plugin (CVE-2026-17602) is vulnerable to Directory Traversal, allowing authenticated administrators to read arbitrary files. Another instance of Reflected XSS was found in the SSL Zen plugin (CVE-2026-17577) via 'uri' and 'host' parameters. The Asset CleanUp plugin (CVE-2026-12037) is affected by Server-Side Request Forgery (SSRF), enabling authenticated administrators to make web requests to arbitrary locations.

The majority of these vulnerabilities were patched in specific plugin versions released around the disclosure date. For instance, MasterStudy LMS was fixed in version 3.7.50, wpForo Forum in 3.1.6, User Profile Builder in 4.0.2, Restaurant Menu and Food Ordering in 2.4.14, Themify Builder in 7.8.1, Repeater Fields for Elementor Forms in 2.2.7, Optima Express IDX in 8.7.5, Premium Packages in 7.2.1, Modula Image Gallery in 3.0.2 and 3.0.1 respectively, Knit Pay in 9.6.1.0, WPForms in 2.0.2, Fancy Product Designer in 6.5.2, s2Member in 260814, SSL Zen in 4.7.42, WP Maps in 4.9.8, Asset CleanUp in 1.4.0.5, and GeoDirectory in 2.8.183. Automatic.css and Zero Spam for WordPress were affected in all versions up to their respective disclosure points. Users are strongly advised to update these plugins to their patched versions to mitigate the risks associated with these numerous security flaws.

This extensive disclosure underscores the importance of regular security audits and timely patching for WordPress sites. The sheer volume and variety of vulnerabilities, from XSS to RCE, highlight the complex threat landscape faced by WordPress users. Staying vigilant and applying updates promptly remains the most effective defense against such widespread security issues.

CVE-2026-15273, CVE-2026-88848, CVE-2026-86837, CVE-2026-80514, CVE-2026-96752, CVE-2026-96568, CVE-2026-95866, CVE-2026-95864, CVE-2026-94573, CVE-2026-93901, CVE-2026-93747, CVE-2026-93656, CVE-2026-93654, CVE-2026-92713, CVE-2026-89426, CVE-2026-89406, CVE-2026-88996, CVE-2026-84280, CVE-2026-19804, CVE-2026-17602, CVE-2026-17577, CVE-2026-13456, CVE-2026-13179, CVE-2026-12037, CVE-2026-96766

Synthesized by Vypr AI