Skip to content
Critical WordPress Plugin Vulnerabilities Expose Sites to Severe Attacks

Critical WordPress Plugin Vulnerabilities Expose Sites to Severe Attacks

First seen 14 Sep 2026, 04:05 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 05:39 UTC

Three critical vulnerabilities have been identified in popular WordPress plugins, affecting educational and backup systems. CVE-2026-82845 in Masteriyo LMS allows users with basic accounts to execute arbitrary code, while CVE-2026-14563 in 'advanced-customized-prompts' enables attackers to take control of admin accounts without passwords. Additionally, CVE-2026-77006 in WebTotem Backups permits authenticated users to delete arbitrary files on the server. All vulnerabilities have been classified as critical by the National Vulnerability Database. The issues stem from poor authentication and validation practices, making exploitation straightforward for attackers. Users of affected plugins are urged to update immediately to mitigate risks. The vulnerabilities were disclosed between September 11 and September 12, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
CVE-2026-14563 published
Vulnerability in 'advanced-customized-prompts' allows admin account takeover without password verification.
Ciberseguridadlatam
2026-09-12
CVE-2026-82845 published
Masteriyo LMS vulnerability allows arbitrary code execution for users with basic accounts.
Ciberseguridadlatam
2026-09-12
CVE-2026-77006 published
WebTotem Backups vulnerability allows authenticated users to delete arbitrary files on the server.
Ciberseguridadlatam

More articles in this cluster (4)

Following this threat?

Track CVE-2026-14563 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed