Home/Security Research

Security Research

CVE advisories from responsible disclosure of WordPress plugin vulnerabilities. All findings were reported to the relevant vendor or disclosure program prior to publication.

CVE ID
Plugin
Vulnerability Title
Severity
Disclosed
CVE-2026-57661WPComplete
Broken Access Control in WPComplete

Missing authorization checks and nonce validation on a sensitive function allows Subscriber-level users to perform privileged actions including manipulating course completion records for arbitrary users. Patched in 2.9.5.6.

MEDIUM 5.4Jun 2026
CVE-2026-15048GeekyBot
Unauthenticated Sensitive Information Exposure in GeekyBot

Missing authorization check on AJAX action allows unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps. Patched in 1.2.8.

MEDIUM 5.3Jul 2026
CVE-2026-14821Quiz and Survey Master
Missing Authorization in Quiz and Survey Master

Missing capability checks on output template deletion allow Contributor-level users or higher to delete arbitrary output templates in Quiz and Survey Master < 11.1.5. Patched in version 11.1.5.

LOW 2.7May 2026
CVE-2026-14322Timetics
Unauthenticated Booking Auto-Approval in Timetics

Missing payment method verification and status enforcement allows unauthenticated users to create fully-approved bookings for priced appointments without payment. Patched in 1.0.57.

MEDIUM 5.3Jul 2026
CVE-2026-10749Post Duplicator
PHP Object Injection in Post Duplicator

Unsanitized input passed to PHP's unserialize() via the customMetaData parameter allows Contributor-level users to inject arbitrary PHP objects, potentially leading to RCE when a gadget chain is present. Patched in 3.0.15.

HIGH 7.2Jun 2026
Showing 5 of 5 disclosuresPowered by TanStack Table v8

Vendor Recognitions & Changelog Credits

Additional security disclosures and contributions recognized in official plugin changelogs and release notes.

MapPress Maps 2.97.2Changelog Credit2026

Security Assistance Recognition in MapPress Google Maps for WordPress

Discovered and reported security issues in MapPress Maps. The plugin author published official changelog appreciation in version 2.97.2:"Thanks to https://shovon.bd for security assistance in 2.97"

WP Store Locator 2.3.1Patch Release2026

Stored XSS (CVSS 8.1) Coordinated Patch Release

Discovered and responsibly disclosed a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (≤ 2.3.0). Resulted in a critical patch release in 2.3.1 and changelog acknowledgement.