Usama Arshad. Résumé

WordPress Plugin Security Coordinated Disclosure Ongoing research

Vulnerability Research

Security research & disclosures.

A running log of my WordPress plugin security research. Findings are reproduced in a local lab, deduplicated against the NVD and Patchstack catalogues, and reported through WPScan under coordinated disclosure — held private until each vendor ships a fix and a CVE is assigned. Eight are now published.

Reported to WPScan
59+
CVEs published
08
Queued for review
121+

Peaked at 13th on the WPScan researcher leaderboard (Top-15) 8 verified submissions · rolling board, currently 15th

Flagship disclosure · Highest severity

8.8 High CVSS 3.1 base

CheckView · CVE-2026-18786

Unauthenticated Administrator Account Creation via REST API Authentication Bypass

An unauthenticated request could bypass REST API authentication and create a full administrator account — a complete site takeover with no credentials required. Discovered in a local lab, reported through WPScan under coordinated disclosure, and resolved by the vendor before public release.

Access Unauthenticated Fixed in 2.3.2 Published 2026-08-07

Read the WPScan advisory

Assigned & patched

Published disclosures.

CheckView

CVE-2026-18786

Unauthenticated Administrator Account Creation via REST API Authentication Bypass

UnauthenticatedFixed in 2.3.2

8.8 High 2026-08-07

Unauthenticated Database Export via Content Export REST Routes

UnauthenticatedFixed in 2.23.1

7.5 High 2026-08-10

WP Travel Engine

CVE-2026-16737

Unauthenticated Booking Details Disclosure & Modification

UnauthenticatedFixed in 6.8.5

6.5 Medium 2026-08-10

Interactive World Maps

CVE-2024-3681

Reflected Cross-Site Scripting (CWE-79)

Unauthenticated · UI:RAffected ≤ 2.4.14NVD / Wordfence

6.1 Medium 2024

GeoDirectory

CVE-2026-16988

Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint

UnauthenticatedFixed in 2.8.169

5.3 Medium 2026-08-03

MStore API

CVE-2026-16041

Unauthenticated Product Review Creation

UnauthenticatedFixed in 4.21.0

5.3 Medium 2026-08-03

Salon Booking System

CVE-2026-17022

Unauthenticated Booking Information Disclosure via Booking Wizard

UnauthenticatedFixed in 10.30.34

5.3 Medium 2026-08-06

Events Manager

CVE-2026-18050

Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads

UnauthenticatedFixed in 7.4

3.7 Low 2026-07-30

Embargoed

In coordinated disclosure.

Further reported to WPScan — awaiting triage / CVE
~52
Validated in lab — queued for submission
121+

Beyond the eight published CVEs, roughly 52 further vulnerabilities have been reported to WPScan and are awaiting triage or a CVE assignment, with another 121+ validated in the lab and queued for submission.

These remain embargoed. No plugin names, slugs, versions, endpoints, parameters, or proof-of-concept are published for any finding that is still unpatched — specifics are withheld until each vendor ships a fix and, where applicable, a CVE is assigned.

Vulnerability-class mix across the corpus

  • Sensitive Data Disclosure
  • Broken Access Control / Missing Authorization
  • IDOR
  • CSRF
  • SQL Injection
  • Cross-Site Scripting
  • Authentication Bypass
  • RCE (1×)

Access levels — predominantly unauthenticated, plus a minority requiring only low-privilege access (Subscriber / Contributor).

Policy

Responsible disclosure.

Every vulnerability here was reported privately first. Nothing is published — no plugin name, version, endpoint, parameter, or proof-of-concept — while a finding is still unpatched, because that would hand attackers a live roadmap. Details go public only after the vendor ships a fix and, where applicable, a CVE is assigned.

Reported through WPScan & Wordfence · Usama Arshad