Home/Security Research

Security Research

CVE advisories from responsible disclosure of WordPress plugin vulnerabilities. All findings were reported to the relevant vendor or disclosure program prior to publication.

CVE ID↓
Plugin↕
Vulnerability Title↕
Severity↕
Disclosed↕
CVE-2026-85678AI Builder
Authenticated (Contributor+) Stored XSS in AI Builder

Insufficient sanitization of custom JavaScript saved against posts allows Contributor-level users to inject arbitrary web scripts inside inline script tags. Patched in 2.7.8.

MEDIUM 6.4Sep 2026
CVE-2026-84021Bold Page Builder
Authenticated (Contributor+) Stored XSS in Bold Page Builder

Missing URL validation on shortcodes and button/headline link parameters allows Contributor-level users to store malicious JavaScript links. Patched in 5.9.8.

MEDIUM 6.8Aug 2026
CVE-2026-57661WPComplete
Broken Access Control in WPComplete

Missing authorization checks and nonce validation on a sensitive function allows Subscriber-level users to perform privileged actions including manipulating course completion records for arbitrary users. Patched in 2.9.5.6.

MEDIUM 5.4Jun 2026
CVE-2026-15049Depicter
Authenticated (Editor+) Arbitrary File Upload in Depicter

Improper file validation during ZIP slider/template import allows Editor-level users to upload arbitrary executable PHP files leading to Remote Code Execution (RCE). Patched in 4.8.0.

HIGH 7.2Jul 2026
CVE-2026-15048GeekyBot
Unauthenticated Sensitive Information Exposure in GeekyBot

Missing authorization check on AJAX action allows unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps. Patched in 1.2.8.

MEDIUM 5.3Jul 2026
CVE-2026-14822Event Tickets
Unauthenticated PayPal Order Status Manipulation in Event Tickets

Missing authorization on REST endpoint allows unauthenticated attackers to forge status transitions on PayPal ticket orders without valid payment. Patched in 5.29.0.1.

MEDIUM 5.3Jul 2026
CVE-2026-14821Quiz and Survey Master
Missing Authorization in Quiz and Survey Master

Missing capability checks on output template deletion allow Contributor-level users or higher to delete arbitrary output templates in Quiz and Survey Master < 11.1.5. Patched in version 11.1.5.

LOW 2.7May 2026
CVE-2026-14322Timetics
Unauthenticated Booking Auto-Approval in Timetics

Missing payment method verification and status enforcement allows unauthenticated users to create fully-approved bookings for priced appointments without payment. Patched in 1.0.57.

MEDIUM 5.3Jul 2026
CVE-2026-10749Post Duplicator
PHP Object Injection in Post Duplicator

Unsanitized input passed to PHP's unserialize() via the customMetaData parameter allows Contributor-level users to inject arbitrary PHP objects, potentially leading to RCE when a gadget chain is present. Patched in 3.0.15.

HIGH 7.2Jun 2026
Showing 9 of 9 disclosuresPowered by TanStack Table v8

Vendor Recognitions & Changelog Credits

Additional security disclosures and contributions recognized in official plugin changelogs and release notes.

MapPress Maps 2.97.2Changelog Credit2026

Security Assistance Recognition in MapPress Google Maps for WordPress

Discovered and reported security issues in MapPress Maps. The plugin author published official changelog appreciation in version 2.97.2:"Thanks to https://shovon.bd for security assistance in 2.97"

WP Store Locator 2.3.1Patch Release2026

Stored XSS (CVSS 8.1) Coordinated Patch Release

Discovered and responsibly disclosed a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (≤ 2.3.0). Resulted in a critical patch release in 2.3.1 and changelog acknowledgement.