Security Advisory - Published 2026-06-27 - WordPress / CMS

WordPress critical plugin batch: check SQL, upload, privilege, and object-injection risks

This page groups the higher-risk WordPress plugin issues from the June 27 monitor window: SQL injection, file upload, privilege escalation, PHP object injection, RCE-labeled plugin paths, and sensitive control surfaces. Patch the affected component first, then preserve logs and review users, files, and database activity.

Defensive scope: check systems you own or are approved to repair. This page keeps to version checks, exposure review, logs, patching, and compromise indicators. It stays on inventory, patching, log review, and compromise triage.

Affected CVEs in this batch

CVEProductAffectedReviewCVSS
CVE-2026-57700Daan.Dev OMGF Provendor-fixed releasefiles and uploads10.0
CVE-2026-56027Booster for WooCommerce<= 8.0.1files and uploads9.9
CVE-2026-56058Quform<= 2.23.0files and uploads9.9
CVE-2026-56059Travel Booking<= 2.2.5files and uploads9.9
CVE-2026-54823Widget Options<= 4.2.3logs and users9.9
CVE-2026-56032Buddyboss Platform<= 3.0.4logs and users9.8
CVE-2026-56033Dokan Pro<= 5.0.4users and access9.8
CVE-2026-56028Easy Elements for Elementor - Addons and Website Templates<= 1.4.9users and access9.8
CVE-2026-56030Paytium<= 5.0.2users and access9.8
CVE-2026-56057Uncanny Automator Pro<= 7.3.0.6logs and users9.8
CVE-2026-56070Advance Product Search<= 1.4.4database logs9.3
CVE-2026-54831GeoDirectory<= 2.8.162database logs9.3
CVE-2026-54820JetBooking<= 4.0.4.1database logs9.3
CVE-2026-56068JetEngine<= 3.8.10.2database logs9.3
CVE-2026-56067JetSmartFilters<= 3.8.3database logs9.3
CVE-2026-56036Korean SimplePay WooCommerce plugin<= 5.5.6database logs9.3
CVE-2026-56034Library Management System<= 3.5.7database logs9.3
CVE-2026-54843MDTF<= 1.3.7database logs9.3
CVE-2026-54849Premmerce Wishlist for WooCommerce<= 1.1.11database logs9.3
CVE-2026-56062Quotes llama<= 3.1.5database logs9.3
CVE-2026-54827Real Estate 7<= 3.5.9database logs9.3
CVE-2026-54825wpDataTables<= 7.4database logs9.3
CVE-2026-54836YMC Filtervendor-fixed releasedatabase logs9.3
CVE-2026-57658TemplateSpare<= 4.2.0files and uploads9.1
CVE-2026-56010Abandoned Cart Pro for WooCommerce<= 10.4.0users and access8.8
CVE-2025-68052Eagle Booking<= 1.3.4.3users and access8.8
CVE-2026-56053EventPrime<= 4.3.4.1logs and users8.8
CVE-2026-56038Frisbii Pay<= 1.8.2users and access8.8
CVE-2026-56008Fusion Builder<= 3.15.4users and access8.8
CVE-2026-57659Paid Memberships Pro - Add Member From Admin<= 0.7.2users and access8.8
CVE-2026-56055RealHomes<= 4.5.3logs and users8.8
CVE-2026-56035BitFire Security<= 5.0.3users and access8.6
CVE-2026-57315Blocksy Companion Pro<= 2.1.45logs and users8.5
CVE-2026-57662Contest Gallery<= 30.0.0database logs8.5
CVE-2026-57642Gallery<= 4.7.8database logs8.5
CVE-2026-57667Groundhogg<= 4.5database logs8.5
CVE-2026-56049Post Snippets<= 4.0.19logs and users8.5
CVE-2026-57663Recipe Maker For Your Food Blog from Zip Recipes<= 8.2.7database logs8.5
CVE-2026-57644Restaurant Menu by MotoPress<= 2.4.10database logs8.5
CVE-2026-54822SALESmanago & Leadoo<= 3.11.2database logs8.5
CVE-2026-56064Tourfic<= 2.22.5database logs8.5
CVE-2026-54838WC Vendors Marketplace<= 2.6.8database logs8.5
CVE-2026-57653WP Job Portal<= 2.5.2database logs8.5
CVE-2026-57643WP Post Author<= 3.9.1database logs8.5
CVE-2026-57636wpForo Forum<= 3.0.9database logs8.5
CVE-2026-56063MailChimp Block<= 1.1.15users and access8.3
CVE-2026-54848Saad Iqbal APIExperts Square for WooCommercevendor-fixed releasedata exposure8.3
CVE-2026-57655Child Theme Wizard<= 1.4users and access8.2
CVE-2026-54845MDTF<= 1.3.8files and uploads8.1
CVE-2026-57645Newsletters<= 4.13users and access8.1
CVE-2026-54842Royal Plugins Royal MCPvendor-fixed releaseusers and access8.1
CVE-2026-56031Uncanny Automator<= 7.3.1.2users and access8.1

What to check

  • Plugin and theme versions listed in the table, including premium or bundled copies.
  • New administrator users, changed roles, password resets, and suspicious sessions.
  • Recent PHP, ZIP, PHAR, PHTML, JavaScript, and template file changes under wp-content.
  • Database errors, unusual search/filter requests, order or membership changes, and plugin-specific logs.
  • Payment, marketplace, booking, form, membership, and automation integrations touched by the affected plugin.

Safe fix path

  1. Patch or disable the affected plugin or theme before cleanup.
  2. Keep web logs, wp-content file timestamps, user exports, and plugin update history.
  3. Remove unknown administrator accounts and rotate WordPress, SFTP, database, and payment/API credentials when compromise signs exist.
  4. Restore files from a clean backup only after the vulnerable component is updated or removed.

Compromise indicators

  • New users, role changes, unexpected sessions, or unknown API tokens.
  • Files changed during the exposure window, especially executable files or generated configs.
  • Repeated application errors, database errors, queue failures, or unusual outbound requests.
  • Plugin, container, service, or package versions that differ from the expected deployment record.

When to ask Ping7 for repair

Use Ping7 CVE Repair when the affected component is public, logs show suspicious activity, patching may break production, or cleanup requires file, database, user, token, or container review.

References