Remote Code Execution vulnerabilities in WordPress plugins and themes
Remote code execution means the attacker gets to run their own instructions on your server. There is no partial version of this outcome: once code runs, the attacker can read every file, reach the database, install a backdoor and persist through a password change. RCE flaws are the ones worth dropping other work to patch.
What an attacker can do: run their own code on the server, which is total control of the site CWE-94
- Wp User Avatar - Remote Code Execution (CVE-2026-66047) CRITICAL
- Sigma Forms Pro - Remote Code Execution (CVE-2026-14494) CRITICAL
- Rank Math SEO - Remote Code Execution (CVE-2026-81757) HIGH
- User Frontend - Remote Code Execution (CVE-2026-14558) HIGH
- One User Avatar - Remote Code Execution (CVE-2026-18983) HIGH
- Elearning And Online Course Solution - Remote Code Execution (CVE-2026-16759) MEDIUM
- Workeera - Remote Code Execution (CVE-2026-77018) HIGH
- Accounting & CRM Suite Built for WooCommerce - Remote Code Execution (CVE-2026-18080) CRITICAL
- Avada - Remote Code Execution (CVE-2026-18431) CRITICAL
- A Few Clicks - Remote Code Execution (CVE-2026-16601) HIGH
- Query Wrangler - Remote Code Execution (CVE-2026-73992) CRITICAL
- Kirki - Remote Code Execution (CVE-2026-74992) MEDIUM
- Slider Builder - Remote Code Execution (CVE-2026-15049) HIGH
- JetEngine - Remote Code Execution (CVE-2026-66613) CRITICAL
- Atarim Visual Collaboration - Remote Code Execution (CVE-2026-19942) HIGH
- CVE-2026-73343 CRITICAL
- Cwicly - Remote Code Execution (CVE-2026-32444) CRITICAL
- Forminator - Remote Code Execution (CVE-2026-15748) CRITICAL
- CVE-2026-65640 HIGH
- For Woocommerce - Remote Code Execution (CVE-2026-17581) HIGH
- Podlove Podcast Publisher - Remote Code Execution (CVE-2026-16099) HIGH
- Prosolution Wp Client - Remote Code Execution (CVE-2026-16098) CRITICAL
- Prosolution Wp Client - Remote Code Execution (CVE-2026-14524) CRITICAL
- Query Wrangler - Remote Code Execution (CVE-2026-14498) HIGH
- Link Library - Remote Code Execution (CVE-2026-18855) CRITICAL
- Elementor - Remote Code Execution (CVE-2026-18438) HIGH
- Increase Maximum File Upload Size - Remote Code Execution (CVE-2026-15965) HIGH
- Rapisafe Multi File Cf7 - Remote Code Execution (CVE-2026-14484) CRITICAL
- CVE-2026-61962 CRITICAL
- QA Analytics - Remote Code Execution (CVE-2026-27544) CRITICAL