Segurium Research
WordPress plugin advisories.
One record per finding. Filter by plugin, bug class, severity or year, or type a CVE. Every record links to the teardown that explains it, and every claim traces to a public source listed on the record.
Reading rather than looking something up? The teardown index runs the same findings as narrative posts.-
WP Go Maps 10.1.09 adds a bounds check on the midcbp REST parameter. In 10.1.08 and earlier, an out-of-range pointer made the Elias-Fano decode loop run past its buffer until PHP stopped the request.
-
The [hfe_template] shortcode in Ultimate Addons for Elementor used a status denylist, so scheduled, trashed and non-public posts could render to visitors who may not view them. Release 2.9.4 switches to an allowlist and drops the plugin's own SVG sanitiser.
-
A remote server could redirect a CSV import in 2.4.13 to a cloud metadata endpoint or a private service, and the plugin followed that redirect without checking the new host. Version 2.4.14 replaces download_url() with a checked fetch.
-
Depicter 4.8.1 rewrites the lead export query. Form field names from public submissions went straight into a raw MAX(IF()) SQL fragment, and sort parameters reached ORDER BY with no check. Update sites on 4.8.0 or earlier.
-
WP ERP before 1.17.8
critical 9.8The CRM's IMAP connector saved mail attachments without checking the extension or normalising the path, so a crafted email could drop a PHP file into wp-content/uploads. CVE-2026-18080, CVSS 9.8, fixed in 1.17.8.
-
Formidable Forms 6.34 adds a FrmHtmlSanitizer class that cleans href and src values before entry data reaches the screen. Releases up to 6.33.1 checked those URLs while they were still entity-encoded.
-
MalCare before 6.65
high 8.1Before 6.65, BlogVault, MalCare and WP Remote built the secret that binds a site to their remote management service with a weak random number generator, and leaked data derived from it to unauthenticated callers. CVE-2026-19718, CVSS 8.1.
-
Gutentor 4.0.6 adds capability checks to its own REST API. Version 4.0.5 and earlier returned non-public post content and the plain post_password value, and let callers filter posts by password. About 30,000 sites run the plugin.
-
WPvivid Backup 0.9.132 and earlier extracts backup archives without checking file paths. A crafted backup can write files outside the restore folder. Version 0.9.133 adds path containment checks and fixes SQL injection in the uploads cleaner.
No advisory matches those filters.