← All articles Blog

Anatomy of 2026: four trusted WordPress plugins, four critical holes

Short answer: Through the first half of 2026, four of the most widely installed WordPress plugins — a backup tool, a cache plugin, a privacy-analytics add-on and a page builder — each shipped a critical security hole rated 9.8 out of 10, exploitable by anyone with no login required. Between them they run on more than two million sites. Not one of the holes was in WordPress itself; all four were in plugins. That’s the pattern worth understanding: the risk isn’t WordPress core, it’s the add-ons bolted onto it — and the gap between the day a hole goes public and the day your site is updated.

We run managed hosting and track these advisories for client sites, so here’s the plain-language anatomy — built from the official CVE records and the plugin directory’s own install numbers, not from headlines.

The four holes, side by side

Plugin (what it does)Active sitesThe hole, in plain termsSeverityMade public
WPvivid Backup & Migration — backups900,000+A stranger could upload a file and run their own code — no login (CVE-2026-1357)9.8 / 10Feb 2026
Breeze — caching / speed400,000+A stranger could upload a dangerous file — no login (CVE-2026-3844)9.8 / 10Apr 2026
Burst Statistics — privacy analytics200,000+The login check could be skipped to act as an administrator (CVE-2026-8181)9.8 / 10May 2026
Kirki — page builder / customizer500,000+An admin account could be taken over through a broken password reset (CVE-2026-8206)9.8 / 10Jun 2026

Severity is the industry’s standard 0–10 score (CVSS); 9.8 is about as bad as it gets short of a perfect 10. “No login” is the dangerous part: the attacker needs no account, no password, and no victim to click anything.

What they have in common is the whole story

Look down that table. Four different jobs — backup, speed, measurement, design. Four different companies. And the same verdict on every row: critical, and reachable by a complete stranger.

Two of them sting more than the rest. The backup plugin is the one you install precisely so a disaster can’t hurt you — and it became the way in. The privacy-analytics plugin is the one you add to respect your visitors — and it let an attacker pose as the administrator. The tools you bolt on for safety are still just software, and software has holes.

It is almost never WordPress itself

Here’s the number that reframes everything. In 2025, Patchstack recorded 11,334 new vulnerabilities across the WordPress world — up 42% on the year before. Of those, 91% were in plugins, 9% in themes, and just 6 in WordPress core — all of them low-priority.

WordPress core is audited by thousands of people and hard to break. The countdown timer, the contact form, the cache plugin — each is one small team’s side project, and a typical site runs a dozen of them. That’s where the doors are.

The dangerous part isn’t the hole — it’s the wait

All four plugins were fixed. A patch usually ships within days of a flaw going public. So why do sites still get hit?

Because the clock starts the moment a flaw is disclosed. Patchstack rated 1,966 of 2025’s holes — 17% — as high-severity, “likely to be exploited in automated mass-scale attacks.” In plain terms: bots read the same public advisories you do, then sweep the internet for sites that haven’t updated yet. The danger lives in the gap between “fix released” and “fix installed on your site.” If no one is closing that gap, a same-week patch you never applied protects nothing.

What this means if you own the site, not the server

  • Update on the week, not the quarter. For a critical, no-login plugin hole, “I’ll get to it” is measured against bots that move in days.
  • Run fewer plugins. Every one is another small company, another codebase, another possible 9.8. The plugin you installed once and forgot is the one that bites.
  • Keep backups that actually restore — and off the server. WPvivid is the reminder: even your backup tool can be the hole, so the backup that saves you is the tested, off-site one.
  • Have someone watching the feed. Not you, at 11pm, reading CVE bulletins. Someone whose job is to spot “critical hole in a plugin you run” and act before the scanners do.

Where we come in

Most of this is what managed hosting quietly does in the background: follow the security feeds, patch critical plugin holes inside the dangerous window, keep the plugin count lean, and hold tested off-site backups — so a 9.8 in the news is a five-minute update instead of a weekend of cleanup. You don’t have to become a security analyst to run a business website. But someone should be the person who reads the advisory and acts on it.

To see, for free, which known holes affect your own site, start here: where to check which holes threaten your site. For the flip side — a plugin that turned dangerous because its owner changed, not its code — see someone bought 30 plugins and backdoored every one. And if your site was built and then handed off to nobody in particular: the developer disappeared — who’s watching the site now?

Talk to us

Bring us your site. We'll tell you what's actually wrong.

Free 30-min intro via WhatsApp, Telegram or call. No pitch, no upsell. If we're not the right fit, we'll tell you who is.

Get in touch