📅 Source : Blog Sucuri — publié le 1er octobre 2026. Récapitulatif mensuel des correctifs de sécurité pour l’écosystème WordPress (plugins et thèmes).

Contexte

Sucuri compile chaque mois les vulnérabilités découvertes et corrigées dans les plugins et thèmes WordPress. Ce bulletin de septembre 2026 couvre un volume exceptionnel de failles, touchant des plugins parmi les plus installés au monde, avec des bases d’installation allant de 50 000 à plus de 7 000 000 sites.

Vulnérabilités critiques (sélection)

Plusieurs vulnérabilités de criticité maximale ont été identifiées, permettant une compromission sans authentification :

  • The Events Calendar (≤ 6.17.3 / ≤ 6.17.4) : RCE sans authentification via injection de code (CVE-2026-78159) et PHP Object Injection → RCE (CVE-2026-78006) — 600 000+ installations
  • Unlimited Elements For Elementor (≤ 2.0.16) : SQL Injection sans authentification (CVE-2026-18561) — 300 000+ installations
  • JetFormBuilder (≤ 3.6.2) : Privilege Escalation sans authentification (CVE-2026-12793) et Arbitrary Shortcode Execution (CVE-2026-19859) — 80 000+ installations
  • Hummingbird Performance (≤ 3.21.0) : RCE sans authentification via cookie name dans le debug log (CVE-2026-83627) — 70 000+ installations
  • Ultra Addons for Contact Form 7 (3.2.4 - 3.5.50) : Arbitrary File Upload sans authentification (CVE-2026-84750) — 60 000+
  • Customer Reviews for WooCommerce (≤ 5.120.0) : Arbitrary Attachment Deletion sans authentification (CVE-2026-89055) — 80 000+
  • Comments (< 7.6.66) : SQL Injection sans authentification (CVE-2026-19704) — 60 000+
  • Product Filter for WooCommerce by WBW (≤ 3.1.7) : SQL Injection sans authentification (CVE-2026-95601) — 50 000+
  • Online Scheduling and Appointment Booking System (≤ 28.2) : IDOR → disclosure et suppression de tokens de réservation (CVE-2026-93399) — 60 000+
  • WP Recipe Maker (≤ 10.8.1) : Arbitrary Shortcode Execution sans authentification via commentaire (CVE-2026-89274) — 50 000+

Plugins très répandus affectés (7M+ installations)

  • WooCommerce : DoS sans auth (CVE-2026-48888), SQL Injection authentifiée Shop Manager+ (CVE-2026-57777)
  • LiteSpeed Cache : SSRF sans auth (CVE-2026-84761), XSS réfléchi (CVE-2026-76579)

Types de vulnérabilités dominants

  • Stored XSS sans authentification : très nombreux cas (Ninja Forms, Forminator, WP Statistics, Kirki, Jetpack, etc.)
  • Arbitrary Shortcode Execution sans authentification : WPForms, Ninja Forms, GiveWP, Spam protection CleanTalk, etc.
  • PHP Object Injection : ShortPixel, Unlimited Elements, Everest Forms, Ninja Forms, etc.
  • Privilege Escalation : GiveWP, JetFormBuilder, Theme My Login, JetBackup, etc.
  • SQL Injection : WooCommerce, Kirki, WPvivid, Event Tickets, etc.
  • Information Exposure / IDOR : Rank Math SEO, UpdraftPlus, The Events Calendar, etc.
  • Missing Authorization : très répandu sur l’ensemble des plugins listés

Thème affecté

  • Astra (≤ 4.13.12) : Arbitrary CSS Injection authentifiée Shop Manager+ (CVE-2026-27085) — 1 000 000+ installations

Nature de l’article

Il s’agit d’un bulletin de patch de sécurité mensuel publié par Sucuri, à destination des administrateurs de sites WordPress. Son but principal est de recenser les vulnérabilités corrigées et d’inciter à la mise à jour des composants affectés.

🧠 TTPs et IOCs détectés

TTP

  • T1190 — Exploit Public-Facing Application (Initial Access)
  • T1059.004 — Command and Scripting Interpreter: Unix Shell (Execution)
  • T1505.003 — Server Software Component: Web Shell (Persistence)
  • T1078 — Valid Accounts (Defense Evasion)
  • T1548 — Abuse Elevation Control Mechanism (Privilege Escalation)
  • T1083 — File and Directory Discovery (Discovery)
  • T1005 — Data from Local System (Collection)
  • T1189 — Drive-by Compromise (Initial Access)

IOC

⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 1 octobre 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.


🟡 Indice de vérification factuelle : 45/100 (moyenne)

  • ⬜ blog.sucuri.net — source non référencée (0pts)
  • ✅ 174285 chars — texte complet (15pts)
  • ✅ 366 IOCs (IPs/domaines/CVEs) (10pts)
  • ⬜ pas d’IOC vérifié (0pts)
  • ✅ 8 TTPs MITRE identifiées (15pts)
  • ⬜ date RSS ou approximée (0pts)
  • ⬜ aucun acteur de menace nommé (0pts)
  • ✅ 5/5 CVE(s) confirmée(s) (CIRCL) (5pts)

🔗 Source originale : https://blog.sucuri.net/2026/09/vulnerability-patch-roundup-september-2026.html

🖴 Archive : https://web.archive.org/web/20261001071651/https://blog.sucuri.net/2026/09/vulnerability-patch-roundup-september-2026.html