Technology 15 sources · over 7 days Latest coverage 5 Sept 2026, 9:50 am UTC

Critical Vulnerabilities in Major WordPress Plugins Expose Millions of Sites to Attack

A series of severe security flaws in widely used WordPress plugins has put millions of websites at risk of remote code execution, site takeovers, and unauthorized access, prompting urgent calls for updates.

By Isabel Navarro · First published 5 Sept 2026

In brief

  1. Multiple popular WordPress plugins have been found to contain critical vulnerabilities enabling remote code execution and site takeover.
  2. More than five million sites are impacted by flaws in plugins such as All-in-One WP Migration, Elementor Pro, and Super Forms.
  3. Attackers have actively exploited these vulnerabilities in the wild, with hundreds of thousands of exploit attempts recorded in recent weeks.
  4. Security experts and plugin developers have released patches, but many sites remain unprotected as not all users have updated.
  5. Website administrators are urged to update affected plugins and monitor for suspicious activity to mitigate ongoing threats.
Critical Vulnerabilities in Major WordPress Plugins Expose Millions of Sites to Attack
Source: The Hacker News

Timeline · 10 moments

10 moments Open the full timeline →

Forminator Forms plugin flaw exposes 600,000 sites

DEV Community ↗

Privilege escalation vulnerability found in Pods plugin

Wordfence ↗

Everest Forms vulnerability allows complete site takeover

Cyber Security News ↗

Critical miniOrange SAML flaws allow admin account hijacking

GBHackers On Security ↗

WPMU DEV Dashboard plugin flaw enables admin access

GBHackers On Security ↗

Critical GiveWP vulnerability allows server command execution

Security Affairs ↗

All-in-One WP Migration plugin SQL injection affects millions

Wordfence ↗

Critical Elementor Pro flaw exploited in the wild

BleepingComputer ↗

Super Forms plugin RCE flaw actively exploited

GBHackers On Security ↗

Over 440,000 exploit attempts target Super Forms and Elementor Pro

The Hacker News ↗

How the Vulnerabilities Emerged

Over the past several weeks, security researchers and plugin developers discovered a wave of critical vulnerabilities in widely used WordPress plugins. These flaws include remote code execution, SQL injection, privilege escalation, and authentication bypass, affecting both established and newer plugins.

The vulnerabilities first came to light as reports surfaced of attackers exploiting weak file upload validation and broken access controls. The affected plugins are installed on millions of sites, making the impact far-reaching. As news spread, both security firms and plugin developers began issuing advisories and patches.

Key Developments and Escalation

On August 19, 2026, a flaw in the Forminator Forms plugin was reported, exposing over 600,000 sites to unauthenticated remote code execution. The following days saw similar disclosures for the Outranking, InfiniteWP Client, and Pods plugins, each affecting tens or hundreds of thousands of sites with risks of admin access or database compromise.

By late August, attackers began targeting the Everest Forms and miniOrange SAML 2.0 Single Sign-On plugins, with vulnerabilities enabling complete site takeovers and admin account hijacking. Security researchers documented active exploitation of these flaws, some with severity scores as high as 9.8 out of 10.

The pace intensified as flaws were found in WPMU DEV Dashboard, Sigma Forms Pro, and the widely used All-in-One WP Migration and Backup plugin. The latter, with over five million active installations, was found vulnerable to unauthenticated SQL injection, enabling attackers to take control of affected sites.

By early September, attacks expanded to the Super Forms and Elementor Pro plugins. Security firms recorded over 440,000 exploit attempts targeting these flaws, with attackers uploading webshells and executing arbitrary code on compromised servers. Patches have been released for many of the affected plugins, but not all sites have applied them.

Current Situation

Millions of WordPress sites remain vulnerable as attackers continue to scan for and exploit unpatched plugins. Security firms have confirmed ongoing exploitation, with some attacks leading to full site takeovers and persistent backdoors.

Many plugin developers have issued fixes, but the large number of affected sites means that full remediation will take time. Website owners are being urged to update their plugins immediately and to monitor their sites for unusual activity or signs of compromise.

What Happens Next

The situation remains fluid as researchers monitor for new exploits and plugin developers work to patch additional flaws. Website owners should expect further advisories and may need to apply more updates as new vulnerabilities are discovered or as attackers shift tactics.

Written from 15 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →