Arbitrary Code Execution Vulnerability in Defender Security Plugin for WordPress
CVE-2026-19225
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 27 August 2026
Badges
What is CVE-2026-19225?
The Defender Security plugin for WordPress before version 6.2.0 contains a vulnerability that permits an administrator of any single site within a multisite network to execute arbitrary code across the entire network. This flaw arises from the failure to restrict a critical network-wide setting exclusively to network administrators, exposing the infrastructure to potential exploitation by unprivileged site administrators. As a result, the security posture of the entire multisite network could be compromised, highlighting the importance of updating to the latest version to mitigate such risks.
Affected Version(s)
Defender Security 5.0.0 < 6.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.