I went for coffee and came back with 6 vulnerabilities in WordPress plugins
Related Vulnerabilities
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-5809: The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and HIGH
- CVE-2026-5207: The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all v MEDIUM
- CVE-2026-4979: The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for W MEDIUM
- CVE-2026-5226: The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
Related Coverage
Threat Actors