
Wordfence Intelligence’s weekly WordPress vulnerability report for July 13 to July 19, 2026 logged another busy week for the ecosystem, with 75 vulnerabilities disclosed in WordPress Core, 68 in plugins and none in themes. Of the 75 issues added to the Wordfence Intelligence Vulnerability Database, 71 were patched and four remained unpatched at the time of publication.
Wordfence highlights a heavy week for WordPress Core and plugins
The report shows how concentrated vulnerability activity continues to be around plugins and core releases. Wordfence said 50 vulnerability researchers contributed to WordPress security last week, with Wordfence PRISM accounting for 25 of the disclosures in the leaderboard snapshot provided in the report.
Wordfence also reiterated its broader mission: to make vulnerability information accessible to the WordPress community and support layered security and defense-in-depth strategies. The company noted that its Intelligence user interface, vulnerability API, webhook integration and Wordfence CLI Vulnerability Scanner are all free to use, both personally and commercially.
Protection delivered through Wordfence firewall rules
According to the report, the Wordfence Threat Intelligence Team reviewed each vulnerability to determine impact, severity and likelihood of exploitation before deploying enhanced firewall rules in real time for Premium, Care and Response customers.
The new firewall protections last week covered the following issues:
- Super Forms <= 6.3.313 – Unauthenticated Arbitrary File Upload via
dataParameter (datauristring / value) - WordPress Core < 7.0.2 – Unauthenticated Remote Code Execution
- WAF-RULE-930 – Data redacted while Wordfence works with the vendor on a patch
- WAF-RULE-931 – Data redacted while Wordfence works with the vendor on a patch
- WAF-RULE-933 – Data redacted while Wordfence works with the vendor on a patch
Free Wordfence users will receive the same enhanced protection after a 30-day delay, the report said.
WordPress Core vulnerabilities included critical remote code execution and SQL injection
WordPress Core appeared several times in the week’s critical and high-severity findings. The most serious was WordPress Core 6.9 – 7.0.1 – Remote Code Execution via REST API Batch Request Route Confusion, rated 9.8 critical and published on July 17, 2026. Wordfence attributed that disclosure to Adam Kues.
The report also listed WordPress Core 6.8 – 7.0.1 – Unauthenticated SQL Injection via author__not_in Parameter, rated 7.5 high and published on July 17, 2026. That issue was credited to Tin Pham (TF1T), Trong Pham (dtro) and haongo.
In total, Wordfence grouped last week’s disclosures into these severity bands:
- Medium severity: 48
- High severity: 21
- Critical severity: 6
Critical plugin issues ranged from privilege escalation to file upload abuse
Several plugin vulnerabilities stood out for their severity and potential impact. Aimogen Pro – All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 was flagged for an unauthenticated privilege escalation via aiomatic_call_google_ai_function, with CVSS 9.8 and a patch already available. The researcher credited was Bao Le.
Bricksforge <= 3.1.8.6 was also rated critical after Wordfence found an unauthenticated privilege escalation via the Pro Forms fieldIds parameter. That issue, CVE-2026-14956, was published on July 16 and attributed to 0xd4rk5id3.
Other critical or high-priority plugin findings included:
- Podlove Podcast Publisher <= 4.5.1 – unauthenticated arbitrary file upload via
podlove_image_cache_urlparameter, CVSS 9.8 - SAML Single Sign On <= 5.4.3 – unauthenticated authentication bypass via
SAMLResponseparameter signature algorithm confusion, CVSS 9.8 - TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 – unauthenticated privilege escalation, CVSS 9.8
- Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 – authenticated privilege escalation via
digits_reg_userroleparameter, CVSS 8.8 - Loco Translate <= 2.8.5 – CSRF to remote code execution via
templateparameter, CVSS 8.8 - Uncanny Automator <= 7.3.1.4 – unauthenticated PHP object injection to arbitrary file deletion via Forminator submitted-field token, CVSS 8.1
SQL injection and XSS remained the most common weakness classes
Wordfence’s CWE summary showed that cross-site scripting remained the most common issue type last week, followed closely by SQL injection and missing authorization flaws. The distribution provides a snapshot of where WordPress developers continue to struggle most.
- Cross-site scripting: 25
- SQL injection: 14
- Missing authorization: 13
- Exposure of sensitive information to an unauthorized actor: 4
- Improper privilege management: 4
- Authorization bypass through user-controlled key: 3
- CSRF: 3
- Path traversal: 3
That spread is reflected in the individual disclosures. Wordfence recorded SQL injection issues in products such as Advance Product Search, Bookly, Premium Packages, MultiVendorX, QSM, Tickera, Tutor LMS, SEO Booster and the WordPress Core itself. XSS issues were also widespread across plugins including Breakdance, Form Vibes, Kali Forms, Smart Custom Fields, wpForo Forum and WP Customer Area.
Several widely used plugins were affected
Beyond the critical findings, the report included a broad mix of popular tools used for forms, bookings, ecommerce, membership and site-building. Some of the more notable affected products were Gravity Forms, GiveWP, LearnPress, Amelia, Smart Slider 3, The Cache Purger, pCloud WP Backup and WP Bot.
A few examples illustrate the range of impact:
- Gravity Forms <= 2.10.4 – unauthenticated arbitrary file read via
gform_uploaded_filesparameter - LearnPress <= 4.4.1 – missing authorization exposing sensitive information through REST endpoints
- pCloud WP Backup <= 2.0.3 – missing authorization on
start_backupAJAX method leading to arbitrary file read - WPBot <= 8.5.6 – missing authorization allowing arbitrary chat session deletion via
useridparameter - Bookly <= 27.7 – unauthenticated SQL injection and unauthenticated stored cross-site scripting
Wordfence also listed unpatched issues in Ultimate Auction Pro <= 2.4.5, which had two separate unauthenticated stored cross-site scripting disclosures, and WooCommerce Placetopay Gateway <= 3.2.2, where reflected cross-site scripting via redirect-url remained unpatched.
What site owners should take from the report
The report’s message is simple: even if your site uses well-known plugins, updates can’t be delayed. Wordfence said users running the Wordfence plugin with the scanner enabled should already have been notified if their site was affected, and that real-time vulnerability alerts are available through its free Slack and HTTP webhook integration.
For enterprises, hosts and individual site owners, the takeaway is to keep WordPress Core, plugins and themes updated, monitor advisories closely and scan regularly. Last week’s report shows that a single update cycle can touch dozens of products, and that high-risk bugs can appear in everything from contact forms to booking engines and e-commerce extensions.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: August 11, 2026 at 3:46 am
1 views
