News

WordPress Security Update: Key Vulnerabilities Disclosed This Week

By David Albinson on

WordPress Vulnerabilities

Keeping WordPress websites secure is an ongoing job and this week has brought a number of new plugin vulnerabilities that website owners, developers and maintenance providers should be aware of. Several of the issues disclosed between 10 and 13 August 2026 are considered critical, including vulnerabilities that could allow attackers to reset passwords, escalate privileges, inject SQL or potentially execute malicious code. If you manage a WordPress website, now is a good time to check your plugins and make sure everything is fully up to date.

The most important WordPress vulnerabilities this week

Ninja Tables Pro

One of the most serious issues disclosed this week affects Ninja Tables Pro version 5.2.11. The vulnerability has been given a CVSS score of 10.0, the highest possible severity rating, due to concerns around remote code execution and malicious code being present within that specific release. Anyone running Ninja Tables Pro 5.2.11 should update directly to version 5.2.13 or later. Because of the severity of this issue, we would recommend treating this as an urgent update rather than waiting for your next routine maintenance window.

TrueBooker

TrueBooker versions up to and including 1.2.3 contain a critical access control vulnerability. The issue could allow an unauthenticated attacker to reset user passwords without the proper authorisation checks. It carries a CVSS score of 9.8 and has been fixed in version 1.2.4. If your website uses TrueBooker, updating should be a priority.

AIWU / AI Copilot Content Generator

The AIWU / AI Copilot Content Generator plugin, up to version 1.5.6, has been found to contain an unauthenticated privilege escalation vulnerability. This means an attacker may be able to gain elevated permissions without needing an existing user account. The vulnerability has been given a CVSS score of 9.8. At the time of writing, no official patched release has been listed. If your website uses this plugin, it would be sensible to disable it until a confirmed secure version becomes available.

Tablesome

Tablesome versions up to 1.2.9 are affected by an unauthenticated SQL injection vulnerability. SQL injection vulnerabilities can allow attackers to interfere with database queries and potentially access, change or extract information stored within the website database. The issue has been rated 9.3 out of 10. At the time of writing, no official patched version has been listed. Websites using Tablesome should consider disabling the plugin until an update is released.

Other important vulnerabilities

Several other WordPress plugins have also received security updates this week.

Frontend Admin by DynamiApps

Versions up to 3.29.9 are affected by a password reset and privilege escalation vulnerability. The issue has been rated 8.8 High and is fixed in version 3.29.10 or later.

Formidable Digital Signatures

Versions up to 3.0.6 contain an unauthenticated arbitrary file deletion vulnerability. In some circumstances, this could allow an attacker to remove important files from a WordPress installation. The vulnerability has been rated 8.6 High and is fixed in version 3.1 or later.

Passwordless Login by VentraConnect

Versions up to 1.4.3 are affected by an authentication bypass vulnerability. This has been rated 8.1 High and has been fixed in version 1.4.4 or later.

GeoDirectory

GeoDirectory versions up to 2.8.169 contain an arbitrary file deletion vulnerability. Website owners using GeoDirectory should update to version 2.8.170 or later.

InstaWP Connect

InstaWP Connect versions up to 0.1.3.6 contain a cryptographic key disclosure vulnerability. While this issue has a lower severity rating than some of the vulnerabilities above, it can be exploited without authentication. Updating to version 0.1.3.7 or later is recommended.

FluentCommunity

FluentCommunity versions up to 2.7.5 contain a stored Cross-Site Scripting vulnerability. Stored XSS vulnerabilities can allow malicious scripts to be saved within a website and later executed when another user views the affected content. The vulnerability is fixed in version 2.7.7.

WP Umbrella

WP Umbrella versions 2.24.2 to 2.26.2 are affected by a Cross-Site Request Forgery vulnerability. The issue is less severe than the critical vulnerabilities listed above but website owners should still update to version 2.27.0 or later.

GiveWP

GiveWP has also received security attention this week, including a Cross-Site Scripting vulnerability and a separate access control issue. Websites using GiveWP should make sure they are running version 4.16.6 or later.

Ongoing BdThemes security concerns

There is also an ongoing security issue affecting plugins within the BdThemes ecosystem. The incident was initially identified on 7 August but remains relevant this week due to the nature of the compromise. Security researchers reported that a compromised API response was capable of introducing malicious behaviour into affected plugins. Some BdThemes plugins were temporarily closed within the WordPress plugin repository while the issue was investigated. If you use any BdThemes products, it is worth checking for updates and reviewing your site for unexpected changes.

What about WordPress itself?

There has not been a new WordPress Core security release so far this week. However, website owners should still make sure they are running a supported and fully patched version of WordPress. A significant WordPress Core security update was released in July 2026 to address vulnerabilities involving the REST API and SQL injection, including an attack chain that could potentially lead to remote code execution. Depending on the WordPress branch being used, websites should already be running WordPress 6.8.6, 6.9.5 or 7.0.2 or later.

What should website owners do?

If you manage your own WordPress website, the most important thing is not to panic but to act quickly where necessary. Start by checking whether your website uses any of the affected plugins listed above. Pay particular attention to: Ninja Tables Pro Tablesome AIWU / AI Copilot Content Generator TrueBooker Frontend Admin by DynamiApps Formidable Digital Signatures Passwordless Login by VentraConnect GeoDirectory InstaWP Connect Plugins from the BdThemes ecosystem Critical vulnerabilities should be dealt with as soon as possible. Before carrying out updates, make sure you have a reliable backup of your website and database. For business-critical websites, updates should ideally be tested on a staging environment before being applied to the live site. It is also worth checking administrator accounts, recent file changes and security logs for anything unexpected, particularly if you have been running a vulnerable version for some time.

WordPress security is about maintenance, not just updates

Installing WordPress updates is important but good website security goes further than simply clicking an update button. A well-maintained WordPress website should also have regular backups, strong passwords, multi-factor authentication where possible, appropriate user permissions and ongoing monitoring for suspicious activity. Plugins and themes that are no longer being used should also be removed rather than simply deactivated. Every additional piece of software installed on a website can potentially increase its attack surface. For businesses that rely on their website for enquiries, sales or day-to-day operations, regular maintenance should be considered part of normal website management rather than something that only happens when a problem appears.

Keeping your WordPress website protected

WordPress remains a secure and reliable platform when it is properly maintained. Most serious security incidents occur because vulnerable software has been left installed or updates have been ignored for too long. This week's disclosures are a useful reminder of how quickly the WordPress security landscape can change. If you manage your own website, check your plugins regularly and apply important security updates promptly. If your website is managed by a developer or support provider, they should already be monitoring these types of vulnerabilities as part of their maintenance process. We will continue to keep an eye on major WordPress security issues and share updates when vulnerabilities are likely to affect businesses and website owners.