Skip to main content

Get a quote

Menu

WordPress security bulletins

Stay informed with up-to-date WordPress CVE security bulletins covering known Common Vulnerabilities and Exposures that may impact WordPress websites, plugins, themes, and hosting environments.

Our WordPress security experts help identify potential risks, explain vulnerability impact, and provide guidance on remediation so you can better protect your website and maintain a secure WordPress environment.

300+5-star Google reviews
100%Satisfaction guaranteed
30+Expert team members

WordPress security bulletins

Stay up to date with the latest WordPress CVE security alerts affecting plugins, themes, and site components so you can quickly understand risks and take action when needed.

InfusedWoo Pro Plugin Vulnerability (CVE-2026-6514)

Security bulletinCVE-2026-6514

Security Alert Summary — The InfusedWoo Pro plugin for WordPress contains an arbitrary file read vulnerability in versions up to and including 5.1.2. An unauthenticated attacker may be able to exploit this issue to access sensitive files on affected systems.

Database Backup for WordPress Plugin Vulnerability (CVE-2026-4029)

Security bulletinCVE-2026-4029

Security Alert Summary — The Database Backup for WordPress plugin is vulnerable to unauthorized database export in versions up to and including 2.5.2 due to improper access control enforcement.

Royal Elementor Addons and Templates Plugin Vulnerability (CVE-2026-6504)

Security bulletinCVE-2026-6504

Security Alert Summary — The plugin contains a stored cross-site scripting (XSS) vulnerability via the title_tag parameter in versions up to and including 1.x, allowing malicious scripts to be stored and executed.

InfusedWoo Pro Plugin Vulnerability (CVE-2026-6512)

Security bulletinCVE-2026-6512

Security Alert Summary — The plugin contains an authorization bypass vulnerability in versions up to and including 5.1.2, allowing improper access to restricted functionality.

Database Backup for WordPress Plugin Vulnerability (CVE-2026-4031)

Security bulletinCVE-2026-4031

Security Alert Summary — The plugin contains an authorization bypass issue allowing unauthorized influence over temporary backup operations in versions up to and including 2.5.2.

Database Backup for WordPress Plugin Vulnerability (CVE-2026-4030)

Security bulletinCVE-2026-4030

Security Alert Summary — The plugin contains a vulnerability that may allow unauthenticated attackers to read or delete arbitrary files in certain multisite configurations.

My Calendar – Accessible Event Manager Plugin Vulnerability (CVE-2026-7525)

Security bulletinCVE-2026-7525

Security Alert Summary — The plugin contains an authorization bypass vulnerability allowing users with elevated roles to modify POST data improperly.

MW WP Form Plugin Vulnerability (CVE-2026-6206)

Security bulletinCVE-2026-6206

Security Alert Summary — The plugin contains an information exposure vulnerability due to insufficient restriction in post selection logic.

Ready to start your
WordPress project?