Critical Vulnerabilities in Major WordPress Plugins Expose Millions of Sites to Attack
A series of severe security flaws in widely used WordPress plugins has put millions of websites at risk of remote code execution, site takeovers, and unauthorized access, prompting urgent calls for updates.
By Isabel Navarro · First published 5 Sept 2026
In brief
- Multiple popular WordPress plugins have been found to contain critical vulnerabilities enabling remote code execution and site takeover.
- More than five million sites are impacted by flaws in plugins such as All-in-One WP Migration, Elementor Pro, and Super Forms.
- Attackers have actively exploited these vulnerabilities in the wild, with hundreds of thousands of exploit attempts recorded in recent weeks.
- Security experts and plugin developers have released patches, but many sites remain unprotected as not all users have updated.
- Website administrators are urged to update affected plugins and monitor for suspicious activity to mitigate ongoing threats.
Timeline · 10 moments
Forminator Forms plugin flaw exposes 600,000 sites
DEV Community ↗Privilege escalation vulnerability found in Pods plugin
Wordfence ↗Everest Forms vulnerability allows complete site takeover
Cyber Security News ↗Critical miniOrange SAML flaws allow admin account hijacking
GBHackers On Security ↗WPMU DEV Dashboard plugin flaw enables admin access
GBHackers On Security ↗Critical GiveWP vulnerability allows server command execution
Security Affairs ↗All-in-One WP Migration plugin SQL injection affects millions
Wordfence ↗Critical Elementor Pro flaw exploited in the wild
BleepingComputer ↗Super Forms plugin RCE flaw actively exploited
GBHackers On Security ↗Over 440,000 exploit attempts target Super Forms and Elementor Pro
The Hacker News ↗How the Vulnerabilities Emerged
Over the past several weeks, security researchers and plugin developers discovered a wave of critical vulnerabilities in widely used WordPress plugins. These flaws include remote code execution, SQL injection, privilege escalation, and authentication bypass, affecting both established and newer plugins.
The vulnerabilities first came to light as reports surfaced of attackers exploiting weak file upload validation and broken access controls. The affected plugins are installed on millions of sites, making the impact far-reaching. As news spread, both security firms and plugin developers began issuing advisories and patches.
Key Developments and Escalation
On August 19, 2026, a flaw in the Forminator Forms plugin was reported, exposing over 600,000 sites to unauthenticated remote code execution. The following days saw similar disclosures for the Outranking, InfiniteWP Client, and Pods plugins, each affecting tens or hundreds of thousands of sites with risks of admin access or database compromise.
By late August, attackers began targeting the Everest Forms and miniOrange SAML 2.0 Single Sign-On plugins, with vulnerabilities enabling complete site takeovers and admin account hijacking. Security researchers documented active exploitation of these flaws, some with severity scores as high as 9.8 out of 10.
The pace intensified as flaws were found in WPMU DEV Dashboard, Sigma Forms Pro, and the widely used All-in-One WP Migration and Backup plugin. The latter, with over five million active installations, was found vulnerable to unauthenticated SQL injection, enabling attackers to take control of affected sites.
By early September, attacks expanded to the Super Forms and Elementor Pro plugins. Security firms recorded over 440,000 exploit attempts targeting these flaws, with attackers uploading webshells and executing arbitrary code on compromised servers. Patches have been released for many of the affected plugins, but not all sites have applied them.
Current Situation
Millions of WordPress sites remain vulnerable as attackers continue to scan for and exploit unpatched plugins. Security firms have confirmed ongoing exploitation, with some attacks leading to full site takeovers and persistent backdoors.
Many plugin developers have issued fixes, but the large number of affected sites means that full remediation will take time. Website owners are being urged to update their plugins immediately and to monitor their sites for unusual activity or signs of compromise.
What Happens Next
The situation remains fluid as researchers monitor for new exploits and plugin developers work to patch additional flaws. Website owners should expect further advisories and may need to apply more updates as new vulnerabilities are discovered or as attackers shift tactics.
