{"id":1784,"date":"2026-10-05T13:50:50","date_gmt":"2026-10-05T16:50:50","guid":{"rendered":"https:\/\/www.linuxpro.com.br\/?p=1784"},"modified":"2026-10-05T13:56:41","modified_gmt":"2026-10-05T16:56:41","slug":"wordpress-cves-da-semana-e-como-se-proteger","status":"publish","type":"post","link":"https:\/\/www.linuxpro.com.br\/en\/2026\/10\/wordpress-cves-da-semana-e-como-se-proteger\/","title":{"rendered":"WordPress: this week's CVEs and how to stay safe"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2026\/10\/wordpress-cves-setembro-outubro-2026-v1.webp\" alt=\"Mascote LinuxPro atualizando um servidor WordPress, acompanhado do cachorro caramelo cyborg, em uma sala t\u00e9cnica iluminada.\" width=\"1486\" height=\"856\" \/><\/p>\n<p>Updating only the WordPress core does not fix a flaw in a plugin. In the week of <strong>28 through 4 of 2026<\/strong>, advisories involving ConvertPlus, WPMobile.App, Download Monitor, and CTX Feed Pro showed different risks: PHP object injection, account takeover, and persistent malicious JavaScript. See what to check, which versions to look for, and how to reduce exposure while the fix is not yet in production.<\/p>\n<p><strong>Reporting in 05\/10\/2026.<\/strong> This is a selection of four relevant CVEs, not a complete inventory of the week. The dates below are from public disclosure by Wordfence; in the three advisories for 01\/10, the CVE records were published in 02\/10. There is also an earlier core alert, set apart because it already has confirmed exploitation.<\/p>\n<h2>CVEs of the week: affected components and fixes<\/h2>\n<table>\n<thead>\n<tr>\n<th>Component and CVE<\/th>\n<th>Disclosure<\/th>\n<th>Affected versions<\/th>\n<th>Action<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>ConvertPlus<br \/><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/convertplug\/convertplus-363-authenticated-subscriber-php-object-injection-via-style-parameter\">CVE-2026-87741<\/a><\/td>\n<td>28\/09\/2026<\/td>\n<td>Up to 3.6.3<\/td>\n<td>Update to 3.6.4 or a later fixed version.<\/td>\n<\/tr>\n<tr>\n<td>WPMobile.App<br \/><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpappninja\/wpmobileapp-1182-unauthenticated-admin-account-takeover-via-wpapp-category-parameter\">CVE-2026-94541<\/a><\/td>\n<td>01\/10\/2026<\/td>\n<td>Up to 11.82<\/td>\n<td>The advisory recommends 11.85 or a later fixed version.<\/td>\n<\/tr>\n<tr>\n<td>Download Monitor<br \/><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/download-monitor\/download-monitor-5210-unauthenticated-stored-cross-site-scripting-via-cross-origin-postmessage-to-admin-editor\">CVE-2026-100182<\/a><\/td>\n<td>01\/10\/2026<\/td>\n<td>Up to 5.2.10<\/td>\n<td>Apply the security update 5.2.11 or a later fixed version.<\/td>\n<\/tr>\n<tr>\n<td>CTX Feed Pro<br \/><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/webappick-product-feed-for-woocommerce-pro\/ctx-feed-pro-7612-authenticated-administrator-remote-code-execution\">CVE-2026-10026<\/a><\/td>\n<td>01\/10\/2026<\/td>\n<td>Through 7.6.12<\/td>\n<td>No known fix in the advisory consulted on 05\/10\/2026. Evaluate deactivation and replacement.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>ConvertPlus: a subscriber login is enough to reach the flaw<\/h3>\n<p>Insecure deserialization allows an authenticated user with subscriber or higher capabilities to inject a PHP object. The impact depends on a <em>POP chain<\/em>: a sequence of class behaviors in another plugin or theme. The advisory does not identify that chain within ConvertPlus itself. Therefore, it is not correct to advertise guaranteed remote code execution across every installation. The reference assigns <strong>CVSS 3.1 of 8,8<\/strong>.<\/p>\n<p>Update through the vendor's official channel. If the plugin came bundled with a theme, check whether the distributor already provides the fix. Without access to the patched package, disable the component and plan its removal or replacement; first assess the popups and forms that depend on it. Blocking new signups does not eliminate already existing accounts.<\/p>\n<h3>WPMobile.App: a recovery email cannot become a public push<\/h3>\n<p>With <em>mail-to-push<\/em> enabled, password reset links can be copied into an accessible queue without authentication. This allows accounts to be taken over, including administrative ones. The advisory assigns <strong>CVSS 3.1 of 9,8<\/strong> and recommends version <strong>11.85<\/strong>.<\/p>\n<p>The <a href=\"https:\/\/wordpress.org\/plugins\/wpappninja\/\">developer changelog<\/a> records a temporary deactivation of the feature in 11.83, reinforcement in 11.84, and another security fix in 11.85. Do not treat the interim solution as the end point. If you cannot update, shut down the feature and disable the plugin until you can patch it. Turning off sending does not prove that previously queued data has been deleted; ask the vendor for guidance on cleaning and invalidating links, preserving evidence if there is suspicion of abuse.<\/p>\n<h3>Download Monitor: the administrator is also part of the attack path<\/h3>\n<p>The persistent XSS involves messages between browser pages and the download editing screen. According to the CVE record, the attacker needs to trick an authenticated administrator into visiting a page controlled by them, targeted at an open download editor. It is not a zero-interaction exploit just because the attacker does not need an account.<\/p>\n<p>The <a href=\"https:\/\/wordpress.org\/plugins\/download-monitor\/\">official changelog<\/a> lists the security update <strong>5.2.11 in 28\/09\/2026<\/strong>, before disclosure. Update; in the meantime, avoid external browsing on the same profile used to manage the site and close the affected screen. This reduces the opportunity, but it does not replace the patch. Investigate already-altered content: fixing the plugin does not automatically remove a script that may have been written beforehand.<\/p>\n<h3>CTX Feed Pro: PHP execution requires administrative access<\/h3>\n<p>A <strong>CVE-2026-10026<\/strong> affects the <strong>CTX Feed Pro through 7.6.12<\/strong>. The field <em>Feed Config<\/em> reaches the function <code data-no-translation=\"\">eval()<\/code> without sufficient validation, allowing arbitrary PHP to be executed on the server. The attacker must be authenticated as an <strong>administrator or higher<\/strong>: it is not an intrusion available to any visitor. The <a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/webappick-product-feed-for-woocommerce-pro\/ctx-feed-pro-7612-authenticated-administrator-remote-code-execution\">Wordfence advisory<\/a>, disclosed on 01\/10, assigns <strong>CVSS 3.1 of 7,2<\/strong>; the CVE record was published in 02\/10.<\/p>\n<p><strong>No known fix in the query at 05\/10\/2026.<\/strong> Do not assume that a later version fixes the flaw without confirmation from the vendor. Consider disabling and removing the component, after exporting the settings and planning an alternative for the commercial feeds. The disruption may affect the update of the catalogs used in campaigns and marketplaces.<\/p>\n<p>While you arrange the replacement, reduce administrative access, require MFA, and review changes to the plugin settings. These measures reduce the risk of account abuse, but they do not fix the code. Disabling the file editor with <code data-no-translation=\"\">DISALLOW_FILE_EDIT<\/code> also does not block this path via <code data-no-translation=\"\">eval()<\/code>. If you suspect improper execution, follow the incident response procedure below.<\/p>\n<h2>Earlier alert: the core flaw remains a priority<\/h2>\n<p>A <strong>CVE-2026-87902<\/strong> was disclosed on <strong>22\/09\/2026<\/strong>, outside the selected week. The <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-7hp8-65ch-5whp\">official WordPress advisory<\/a> describes improper inclusion of a local PHP file while resolving templates. Exploitation depends on the active theme containing a top-level directory whose name starts with <code data-no-translation=\"\">page-<\/code> and on a usable, readable local PHP file; whether it escalates to remote code execution also depends on the environment.<\/p>\n<p>Among the fixes are <strong>7.1.2, 7.0.6, 6.9.9 and 6.8.10<\/strong>, each in its respective series. The advisory lists the other branches. This does not mean that every version numerically lower than 7.1.2 remains vulnerable: there are backports.<\/p>\n<p>The <a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/wordpress-security-advisory-av26-952\">Canadian Centre for Cyber Security<\/a> confirmed exploitation in the wild and reported inclusion in the CISA KEV catalog at 25\/09. Prioritize the update. MFA on the dashboard does not fix an inclusion of a file accessible without login.<\/p>\n<h2>Defense in layers: where each protection acts<\/h2>\n<p>The diagram presents a reference logical architecture: the WAF filters requests before the application, WordPress receives the patches, the database remains in a private connection, and the backups stay separate. Logs help investigate; backup helps recover. None of these layers turn vulnerable code into fixed code.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2026\/10\/wordpress-defense-flow.webp\" width=\"1200\" height=\"700\" alt=\"Diagrama da defesa em camadas do WordPress: Internet, WAF, aplica\u00e7\u00e3o atualizada, banco privado, administra\u00e7\u00e3o protegida, logs e backups separados.\" \/><figcaption>Defense in depth: filters reduce exposure, patches fix the code, and separate backups let you recover the environment.<\/figcaption><\/figure>\n<p>In an edge WAF, confirm specific coverage for the CVE, that the rule is enabled, and the paths through which the origin server can still be reached directly. Do not block the entire REST API or the whole <code data-no-translation=\"\">admin-ajax.php<\/code> blindly: that can break the site without addressing the cause. Legitimate integrations, such as <a href=\"\/en\/2026\/09\/mcp-wp-go-wordpress-por-mcp-sem-ssh\/\">WordPress automation via MCP<\/a>, also use the API.<\/p>\n<h2>Fix playbook with WP-CLI<\/h2>\n<p>The examples are for a simple installation with WP-CLI already installed, run by the user who administers the files \u2014 not by root. Replace the path. On managed hosting, use the panel or ask the provider to run them. In Multisite, plan the update and testing for the entire network. <strong>Do not run these commands as triage on a possibly compromised environment:<\/strong> commands that load WordPress can execute tampered code; in that case, isolate and preserve a copy first.<\/p>\n<h3>1. Inventory before changing<\/h3>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\">cd \/var\/www\/seu-site\nwp core version\nwp plugin list --fields=name,status,version,update,update_version\nwp theme list --fields=name,status,version,update\n<\/code><\/pre>\n<p>Compare the technical name, version, and conditions of each advisory. The slugs involved are <code data-no-translation=\"\">convertplug<\/code>, <code data-no-translation=\"\">wpappninja<\/code>, <code data-no-translation=\"\">download-monitor<\/code> and <code data-no-translation=\"\">webappick-product-feed-for-woocommerce-pro<\/code>. For CTX Feed Pro, with no known patch at the time of investigation, follow the mitigation from the dedicated section; there is no update command in this script that is proven to be corrective. Do not install one just to follow the example. The absence of an update in the panel does not prove safety, especially in commercial plugins. References: <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/plugin\/list\/\">plugin inventory<\/a> and <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/theme\/list\/\">themes<\/a>.<\/p>\n<h3>2. Prepare a working recovery<\/h3>\n<p>Before maintenance, ensure a consistent copy of the files and the database outside the public root and test the restore in an isolated environment. In stores, plan how to preserve orders received during the window. Do not leave a SQL dump in <code data-no-translation=\"\">public_html<\/code>. See the guide on <a href=\"\/en\/2026\/09\/databasus-backup-de-postgresql-mysql-e-mariadb-com-restore-testado\/\">backup with tested restore<\/a>.<\/p>\n<h3>3. Update effectively installed components<\/h3>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\"># Veja primeiro o que seria atualizado; n\u00e3o altera os plugins.\nwp plugin update --all --dry-run\n\n# N\u00facleo: atualiza para a vers\u00e3o est\u00e1vel oferecida pelo WordPress.org.\n# Teste antes a compatibilidade se houver mudan\u00e7a de s\u00e9rie.\nwp core update\nwp core update-db\n\n# Execute apenas as linhas dos plugins presentes no seu invent\u00e1rio.\nwp plugin update wpappninja\nwp plugin update download-monitor\nwp plugin update convertplug\n<\/code><\/pre>\n<p>The last command depends on the commercial update channel being configured. If it fails or keeps offering a vulnerable release, get the package from the vendor; do not use ZIPs from third parties. The versions in the table are references for the fix, not a reason to downgrade. The option <code data-no-translation=\"\">wp core update --minor<\/code> limits the update to the current series, but you still need to check whether it received the fix. Documentation: <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/core\/update\/\">core update<\/a>, <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/core\/update-db\/\">update-db<\/a> and <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/plugin\/update\/\">plugin update<\/a>.<\/p>\n<h3>4. Verify integrity and operation<\/h3>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\">wp core version\nwp plugin list --fields=name,status,version,update\nwp core verify-checksums --include-root\nwp plugin verify-checksums --all\n<\/code><\/pre>\n<p>The <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/core\/verify-checksums\/\">core checksums<\/a> and the <a href=\"https:\/\/developer.wordpress.org\/cli\/commands\/plugin\/verify-checksums\/\">plugin checksums<\/a> compare files against WordPress.org references. Commercial or proprietary components may not have checksums available. Mismatches require investigation, not automatic deletion; a clean result does not scan the entire database nor prove the absence of an intrusion.<\/p>\n<p>Check login, public pages, forms, downloads, password recovery, and application features. Clear the affected caches after the update and watch for errors. These commands were verified against the documentation; they do not represent exploitation tests nor an audit of your server.<\/p>\n<h2>Best practices that reduce risk<\/h2>\n<ul>\n<li>Keep the core, plugins, themes, PHP, and operating system up to date. Assign responsible parties and alerts for update failures.<\/li>\n<li>Use MFA and unique passwords; reserve the administrator profile for maintenance and remove unnecessary access.<\/li>\n<li>Remove unused components. Download software only from legitimate sources.<\/li>\n<li>Limit write permissions; do not fix errors with <code data-no-translation=\"\">chmod -R 777<\/code>. Separate credentials and databases for different sites.<\/li>\n<li>Protect backups and monitor changes to files, accounts, and settings.<\/li>\n<\/ul>\n<p>The <a href=\"https:\/\/developer.wordpress.org\/advanced-administration\/security\/hardening\/\">official hardening guide<\/a> also allows you to disable the file editor in the dashboard by adding the following configuration to <code data-no-translation=\"\">wp-config.php<\/code>, before WordPress loads and without duplicating an existing definition:<\/p>\n<pre data-no-translation=\"\"><code class=\"language-php\" data-no-translation=\"\">define( 'DISALLOW_FILE_EDIT', true );\n<\/code><\/pre>\n<p>This does not stop malicious uploads, does not remove backdoors, and does not replace patches. To review the execution layer, see <a href=\"\/en\/2026\/09\/nginx-varias-versoes-php-debian-ubuntu\/\">Nginx and various PHP versions<\/a>.<\/p>\n<h2>Suspected intrusion: updating is not enough<\/h2>\n<p>If unknown administrators, redirects, or unexpected files appear, treat it as an incident. Restrict exposure, preserve logs and a copy of the environment, contact the hosting provider, and investigate the entry and persistence. Avoid wiping everything before preserving evidence.<\/p>\n<p>After containment and rebuilding from trusted sources, revoke application sessions and passwords, replace potentially exposed credentials, and review integrations. Restore only assessed backups and fix the vulnerability before reopening. The official <a href=\"https:\/\/wordpress.org\/documentation\/article\/faq-my-site-was-hacked\/\">hacked sites playbook<\/a> helps organize the response.<\/p>\n<p><strong>Summary:<\/strong> take inventory, compare with the correct advisory, apply the patched version, and validate. Mitigation buys time; updating closes the flaw; investigation determines whether someone has already gained access.<\/p>","protected":false},"excerpt":{"rendered":"<p>CVEs disclosed from 28\/09 to 04\/10\/2026: affected plugins, fixed versions, mitigation, walkthrough using WP-CLI and security best practices.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[46,25,120],"tags":[410,521,523,479,520,522],"class_list":["post-1784","post","type-post","status-publish","format-standard","hentry","category-devops","category-noticias","category-servidores","tag-backup","tag-cve","tag-plugins","tag-seguranca","tag-wordpress","tag-wp-cli"],"_links":{"self":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts\/1784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/comments?post=1784"}],"version-history":[{"count":2,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts\/1784\/revisions"}],"predecessor-version":[{"id":1791,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts\/1784\/revisions\/1791"}],"wp:attachment":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/media?parent=1784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/categories?post=1784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/tags?post=1784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}