Security Research
CVE advisories from responsible disclosure of WordPress plugin vulnerabilities. All findings were reported to the relevant vendor or disclosure program prior to publication.
CVE ID↓ | Plugin↕ | Vulnerability Title↕ | Severity↕ | Disclosed↕ |
|---|---|---|---|---|
| CVE-2026-57661 | WPComplete | Broken Access Control in WPComplete Missing authorization checks and nonce validation on a sensitive function allows Subscriber-level users to perform privileged actions including manipulating course completion records for arbitrary users. Patched in 2.9.5.6. | MEDIUM 5.4 | Jun 2026 |
| CVE-2026-15048 | GeekyBot | Unauthenticated Sensitive Information Exposure in GeekyBot Missing authorization check on AJAX action allows unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps. Patched in 1.2.8. | MEDIUM 5.3 | Jul 2026 |
| CVE-2026-14821 | Quiz and Survey Master | Missing Authorization in Quiz and Survey Master Missing capability checks on output template deletion allow Contributor-level users or higher to delete arbitrary output templates in Quiz and Survey Master < 11.1.5. Patched in version 11.1.5. | LOW 2.7 | May 2026 |
| CVE-2026-14322 | Timetics | Unauthenticated Booking Auto-Approval in Timetics Missing payment method verification and status enforcement allows unauthenticated users to create fully-approved bookings for priced appointments without payment. Patched in 1.0.57. | MEDIUM 5.3 | Jul 2026 |
| CVE-2026-10749 | Post Duplicator | PHP Object Injection in Post Duplicator Unsanitized input passed to PHP's unserialize() via the customMetaData parameter allows Contributor-level users to inject arbitrary PHP objects, potentially leading to RCE when a gadget chain is present. Patched in 3.0.15. | HIGH 7.2 | Jun 2026 |
Vendor Recognitions & Changelog Credits
Additional security disclosures and contributions recognized in official plugin changelogs and release notes.
Security Assistance Recognition in MapPress Google Maps for WordPress
Discovered and reported security issues in MapPress Maps. The plugin author published official changelog appreciation in version 2.97.2:"Thanks to https://shovon.bd for security assistance in 2.97"
Stored XSS (CVSS 8.1) Coordinated Patch Release
Discovered and responsibly disclosed a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (≤ 2.3.0). Resulted in a critical patch release in 2.3.1 and changelog acknowledgement.