Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisoryrapid-weaponization

Critical WordPress Plugin Flaws Expose Sites to File Upload, SQL Injection, and Takeover

Updated 28d agoFirst seen May 25, 202620 sources

Multiple WordPress plugins were flagged for severe vulnerabilities that could let attackers take over sites through unauthenticated file upload, SQL injection, arbitrary file deletion, and authorization bypass. References point to issues in plugins including WP Duplicate, Ninja Forms File Upload, Ultimate Member, Product Addons for WooCommerce, CleanTalk Spam Protect, Ally, Perfmatters, and Kali Forms, alongside identifiers such as CVE-2024-48930, CVE-2025-13192, and CVE-2026-1104. Several flaws were described as allowing arbitrary plugin installation, malicious file upload, or direct database manipulation, creating a path to remote code execution and full site compromise.

Wordfence reports indicate the exposure spans hundreds of thousands of WordPress sites, with some bugs already under active exploitation. The most serious cases include an unauthenticated SQL injection flaw in the Ally plugin affecting roughly 400,000 sites, an arbitrary file deletion issue in Perfmatters affecting about 200,000 sites, and active attacks targeting a critical flaw in Kali Forms. Taken together, the disclosures show a broad wave of high-impact plugin security failures that increase the risk of website defacement, malware deployment, data theft, and administrator-level compromise across the WordPress ecosystem.

Share:
Critical WordPress Plugin Flaws Expose Sites to File Upload, SQL Injection, and Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 13, 20262mo ago

Wordfence reports active exploitation of Kali Forms vulnerability

In April 2026, Wordfence reported that attackers were actively exploiting a critical vulnerability in the Kali Forms plugin. The supplied content supports this as a distinct escalation event because it indicates in-the-wild exploitation rather than only vulnerability disclosure.

Apr 3, 20263mo ago

Wordfence discloses arbitrary file deletion flaw in Perfmatters plugin

Wordfence published an April 2026 report on an arbitrary file deletion vulnerability in the Perfmatters WordPress plugin, saying about 200,000 WordPress sites were affected. No additional remediation or exploitation dates are available in the provided references.

Mar 12, 20263mo ago

Steam-hosted malware campaign targeting crypto users comes under FBI scrutiny

A March 2026 Hypebeast reference indicates the FBI was probing malware-loaded games distributed via Steam that targeted cryptocurrency users. The available reference suggests a law-enforcement investigation into the campaign, but provides no further dated milestones in the supplied content.

Mar 11, 20263mo ago

Wordfence discloses authentication bypass flaw in Tutor LMS Pro plugin

Wordfence reported an authentication bypass vulnerability in the Tutor LMS Pro WordPress plugin affecting about 30,000 sites. The supplied reference indicates this was a separate plugin vulnerability disclosure from the other Wordfence-reported flaws already in the timeline.

[no-title]
Mar 10, 20264mo ago

Wordfence discloses SQL injection flaw affecting Ally WordPress plugin

Wordfence published a March 2026 report about an unauthenticated SQL injection vulnerability in the Ally WordPress plugin, stating that roughly 400,000 WordPress sites were affected. The supplied reference does not include patch timing or exploitation details beyond the disclosure headline.

Feb 11, 20264mo ago

Wordfence discloses arbitrary file upload flaw in WPvivid Backup plugin

Wordfence reported an arbitrary file upload vulnerability in the WPvivid Backup WordPress plugin and said about 800,000 WordPress sites were affected. The supplied reference indicates a vulnerability disclosure involving a separate plugin from those already in the timeline.

[no-title]
Jan 9, 20266mo ago

Wordfence discloses Demo Importer Plus reset and privilege escalation flaw

Wordfence reported vulnerabilities in the Demo Importer Plus WordPress plugin that could allow site reset and privilege escalation. The reference indicates roughly 10,000 WordPress sites were protected against the issue, making this a distinct disclosure from the plugin flaws already in the timeline.

[no-title]

Wordfence discloses password-change flaw in Amelia Booking plugin

Wordfence published a vulnerability report on the Amelia Booking WordPress plugin describing an authenticated customer insecure direct object reference that could allow arbitrary user password changes. The supplied reference indicates a distinct plugin vulnerability disclosure not already represented in the timeline.

[no-title]
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.