Critical Vulnerabilities in Major WordPress Plugins Expose Millions of Sites to Attack
A series of severe security flaws in widely used WordPress plugins has put millions of websites at risk of remote code execution, site takeovers, and unauthorized access, prompting urgent calls for updates.
Read the full story → · Latest coverage 5 Sept 2026, 9:50 am UTC
Key moments · 10
Forminator Forms plugin flaw exposes 600,000 sites
DEV Community ↗Privilege escalation vulnerability found in Pods plugin
Wordfence ↗Everest Forms vulnerability allows complete site takeover
Cyber Security News ↗Critical miniOrange SAML flaws allow admin account hijacking
GBHackers On Security ↗WPMU DEV Dashboard plugin flaw enables admin access
GBHackers On Security ↗Critical GiveWP vulnerability allows server command execution
Security Affairs ↗All-in-One WP Migration plugin SQL injection affects millions
Wordfence ↗Critical Elementor Pro flaw exploited in the wild
BleepingComputer ↗Super Forms plugin RCE flaw actively exploited
GBHackers On Security ↗Over 440,000 exploit attempts target Super Forms and Elementor Pro
The Hacker News ↗









