The WP Remote WordPress Plugin
The WP Remote WordPress Plugin has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Use Of Cryptographically Weak Pseudo-Random Number Generator (PRNG).
Every one of the 2 issues recorded for The WP Remote WordPress Plugin has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. The WP Remote WordPress Plugin is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-19718The WP Remote WordPress Plugin, Malcare Security, and BlogVault Backup & Staging < 6.65 - Unauthenticated Site Takeover via Brute Force
Read the full analysisVulnerability Records

The WP Remote WordPress Plugin
Author
akshatc
The WP Remote WordPress Plugin works with WP Remote to enable you to remotely manage and update all your WordPress sites. WP Remote has been acquired by BlogVault. Why you need WP Remote? Features Free to update an unlimited number of sites. Track and update all of your WordPress sites from one place. Track and update all of your WordPress plugins and themes from one place. Install and activate plugins and themes from the one place. Support You can email us at support@wpremote.com for support.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C