wordpress

Are WordPress Site Owners Still Exposed? Vienna Researchers Say 26 Flaws Remain Unpatched

A Vienna-based security shop says WordPress operators are still flying without a net. Aria Akhavan, founder of Haikhavan Security GmbH, told Automattic and the WordPress project about 26 vulnerabilities—several of them serious—and claims the maintainers have left them open.

The weak spots sit in older plumbing that many sites still expose: xmlrpc.php (XML-RPC) and admin-ajax.php. Depending on the path, an attacker may only need a low-privilege account such as Subscriber, Contributor, or Author. Akhavan argues that, given how widely WordPress is deployed, sitting on those reports is hard to justify.

What can leak?

With the right combination of access and reachable endpoints, researchers say an attacker can pull personal details from commenters—email addresses and IP addresses among them. User logins can be enumerated as well, including accounts that hold administrator rights. Under some conditions, titles of drafts plus private or pending posts written by other authors become visible. Metadata and direct URLs to non-public file attachments may also spill.

What has to line up for an attack?

This is not a drive-by exploit against every WordPress install. A successful grab still needs a signed-in account with the matching capabilities, and the vulnerable XML-RPC or Admin-AJAX handlers must be reachable from the internet. Sensitive drafts, comments, or uploads have to exist on that site; empty or tightly locked sites have less to lose.

How disclosure played out

Haikhavan Security filed the findings on 12 August. When the German outlet Tarnkappe.info asked Automattic for comment, the company only confirmed receipt and offered no substance. WordPress shipped security updates on 17 September 2026, but according to the researchers those releases did not fold in Haikhavan’s advisory. The issues remain active.

Practical steps for site owners

Administrators who do not rely on XML-RPC-dependent plugins can turn the interface off. Closing public registration removes an easy on-ramp for fresh accounts. That does not help if an attacker already holds a valid login. On the server side, lock down direct web access to sensitive files under /wp-content/uploads/.

Whether—and when—the WordPress project will close all 26 findings is still unclear. A follow-up request to Automattic again drew no substantive reply. Earlier incidents already showed how slow patches can leave large footprints: industry estimates put WordPress behind roughly 470 to 590 million sites and blogs worldwide. Not every installation is exposed the same way; several conditions must stack before the described data grab works.

Reporting background: Tarnkappe.info coverage of Haikhavan Security’s claims against Automattic.

Leave a Reply

Your email address will not be published. Required fields are marked *