Multiple WordPress plugins were flagged for severe vulnerabilities that could let attackers take over sites through unauthenticated file upload, SQL injection, arbitrary file deletion, and authorization bypass. References point to issues in plugins including WP Duplicate, Ninja Forms File Upload, Ultimate Member, Product Addons for WooCommerce, CleanTalk Spam Protect, Ally, Perfmatters, and Kali Forms, alongside identifiers such as CVE-2024-48930, CVE-2025-13192, and CVE-2026-1104. Several flaws were described as allowing arbitrary plugin installation, malicious file upload, or direct database manipulation, creating a path to remote code execution and full site compromise.
Wordfence reports indicate the exposure spans hundreds of thousands of WordPress sites, with some bugs already under active exploitation. The most serious cases include an unauthenticated SQL injection flaw in the Ally plugin affecting roughly 400,000 sites, an arbitrary file deletion issue in Perfmatters affecting about 200,000 sites, and active attacks targeting a critical flaw in Kali Forms. Taken together, the disclosures show a broad wave of high-impact plugin security failures that increase the risk of website defacement, malware deployment, data theft, and administrator-level compromise across the WordPress ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In April 2026, Wordfence reported that attackers were actively exploiting a critical vulnerability in the Kali Forms plugin. The supplied content supports this as a distinct escalation event because it indicates in-the-wild exploitation rather than only vulnerability disclosure.
Wordfence published an April 2026 report on an arbitrary file deletion vulnerability in the Perfmatters WordPress plugin, saying about 200,000 WordPress sites were affected. No additional remediation or exploitation dates are available in the provided references.
A March 2026 Hypebeast reference indicates the FBI was probing malware-loaded games distributed via Steam that targeted cryptocurrency users. The available reference suggests a law-enforcement investigation into the campaign, but provides no further dated milestones in the supplied content.
Wordfence reported an authentication bypass vulnerability in the Tutor LMS Pro WordPress plugin affecting about 30,000 sites. The supplied reference indicates this was a separate plugin vulnerability disclosure from the other Wordfence-reported flaws already in the timeline.
Wordfence published a March 2026 report about an unauthenticated SQL injection vulnerability in the Ally WordPress plugin, stating that roughly 400,000 WordPress sites were affected. The supplied reference does not include patch timing or exploitation details beyond the disclosure headline.
Wordfence reported an arbitrary file upload vulnerability in the WPvivid Backup WordPress plugin and said about 800,000 WordPress sites were affected. The supplied reference indicates a vulnerability disclosure involving a separate plugin from those already in the timeline.
Wordfence reported vulnerabilities in the Demo Importer Plus WordPress plugin that could allow site reset and privilege escalation. The reference indicates roughly 10,000 WordPress sites were protected against the issue, making this a distinct disclosure from the plugin flaws already in the timeline.
Wordfence published a vulnerability report on the Amelia Booking WordPress plugin describing an authenticated customer insecure direct object reference that could allow arbitrary user password changes. The supplied reference indicates a distinct plugin vulnerability disclosure not already represented in the timeline.
20 references tracked. Mallory keeps watching after this page renders.
wordfence.com
Open sourcewordfence.com
Open sourcewordfence.com
Open sourcewordfence.com
Open sourcewordfence.com
Open sourcewordfence.com
Open sourcewordfence.com
Open sourcewordfence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.