< Back to situation

[REVISION HISTORY]

Cybersecurity vulnerabilities in WordPress and Joomla

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-04 22:36 UTC → 2026-09-06 21:14 UTC · added removed

Cybersecurity experts and agencies, including CISA, have reported an increase in attacks targeting WordPress and Joomla websites. Vulnerabilities in the WordPress ecosystem have risen significantly, with data from Patchstack indicating approximately 11,334 new vulnerabilities discovered in 2025, a 42 percent increase from the prior year. Most of these flaws reside in plugins and themes rather than the core software. Specific threats have been identified in the Astroid template framework and the JCE content editor, with risk scores reaching 10.0. A high-severity second-order SQL injection vulnerability, CVE-2026-19949, has been identified in the All-in-One WP Migration and Backup plugin, affecting versions 7.109 and earlier. Discovered by researcher Jack Taylor and reported via Wordfence, the flaw allows unauthenticated attackers to execute remote code by planting malicious data through WordPress trackbacks. This data remains dormant until an administrator performs a site export or restoration, at which point the plugin’s database rewriting process can trigger the injected SQL and potentially expose the plugin’s secret import key. An attacker can then use this key to import a malicious archive and take complete control of the website. While the developer, ServMask, released a patch in version 7.110, the scale of risk remains substantial. As as of early September 2026, it was estimated that approximately 3.25 million out of more than five million active installations were still running vulnerable versions, leaving millions versions. Further complicating the landscape, a critical-severity vulnerability (CVE-2026-32475) has been identified in the Elementor Pro plugin, carrying a CVSS score of sites potentially exposed 9.8. Security firm Defiant reported that the flaw involves an arbitrary file upload issue within the plugin’s form submission function. By submitting an array containing an empty slot followed by a PHP payload, unauthenticated attackers can bypass security checks to takeover. execute code on the server. Although a patch was released in version 4.2.2 on August 19, Defiant noted that threat actors began exploiting the defect immediately following the release, blocking over 190,000 exploit attempts to date.

Versions

  1. 2026-09-06 21:14 UTC Cybersecurity vulnerabilities in WordPress and Joomla
  2. 2026-09-04 22:36 UTC Cybersecurity vulnerabilities in WordPress and Joomla
  3. 2026-09-03 05:07 UTC Cybersecurity vulnerabilities in WordPress and Joomla

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.