
Wordfence Intelligence says 247 WordPress vulnerabilities were disclosed last week across 195 plugins and two themes, with 135 researchers contributing new findings to the database between August 3, 2026 and August 9, 2026. The weekly report highlights a mix of patched and unpatched issues, including several critical flaws that site owners and administrators should review promptly.
Wordfence Intelligence weekly WordPress vulnerability report
The Wordfence Intelligence report is designed to make vulnerability data easier to consume for the WordPress community, whether the user is an individual site owner or an enterprise security team. Wordfence says its user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all free to use personally and commercially, and the company says the goal is to support layered security and defense-in-depth strategies.
According to the report, the Wordfence CLI Vulnerability Scanner can be used to run regular scans across protected sites, while the database API can provide a full dump of the more than 35,000 vulnerabilities in the Wordfence Intelligence database. The webhook integration is also available for real-time alerts when new vulnerabilities are added or updated.
The big picture: patched issues outnumber unpatched ones
Of the 247 vulnerabilities disclosed last week, Wordfence lists 216 as patched and 31 as unpatched. Severity-wise, the week was dominated by medium-risk findings, but the report still included a notable number of high and critical issues.
- Medium severity: 174
- High severity: 60
- Critical severity: 13
By weakness category, cross-site scripting led the pack, followed by missing authorization and SQL injection. That distribution is a reminder that common implementation mistakes continue to create security exposure across the plugin ecosystem.
- Cross-site scripting: 79
- Missing authorization: 54
- SQL injection: 29
- Authorization bypass through user-controlled key: 17
- Exposure of sensitive information to an unauthorized actor: 17
- Path traversal: 10
- CSRF: 9
- SSRF: 6
Wordfence Intelligence weekly WordPress vulnerability report: notable critical issues
Several of last week’s highest-severity findings involved remote code execution, authentication bypass, arbitrary file upload, and privilege escalation. Some have already been patched, while others remain unpatched at the time of the report.
Critical vulnerabilities that were patched
Among the patched critical issues, Wordfence lists a remote code execution flaw in Admin and Site Enhancements (ASE) Pro <= 8.9.0, tracked as CVE-2026-16610, which was disclosed on July 29, 2026 and rated 9.8. The issue is described as unauthenticated remote code execution via PHP code injection through the cfgroup[input] repeater row key.
Other patched critical vulnerabilities include:
- AI Copilot – Content Generator <= 1.5.6: unauthenticated privilege escalation, CVE-2026-65507, CVSS 9.8.
- Cost Calculator Builder PRO <= 4.0.3: unauthenticated remote code execution via the
orderDetailsparameter, CVE-2026-14900, CVSS 9.8. - Single Sign On For TNG <= 2.0.0: unauthenticated privilege escalation via unverified password change, CVE-2026-15964, CVSS 9.8.
- SMS Alert <= 3.9.7: unauthenticated authentication bypass to account takeover via the
billing_phoneparameter, CVE-2026-15014, CVSS 9.8. - WooCommerce – Social Login <= 2.8.7: unauthenticated authentication bypass via forged Apple
id_tokenJWT, CVE-2026-8457, CVSS 9.8.
The report also includes several patched critical file and directory deletion issues, such as Demi <= 0.0.6 with CVE-2026-14490 and FormGent <= 1.9.2 with CVE-2026-3141. Both were rated 9.1.
Critical vulnerabilities still unpatched
Not all of the most severe findings were resolved. Wordfence says Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 remains unpatched for an unauthenticated authentication bypass via a hardcoded backdoor in the _wplogin parameter, tracked as CVE-2026-18072 and rated 9.8.
Two other critical issues were also listed as unpatched:
- Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0: unauthenticated arbitrary file upload via the
files[file]parameter through the public I/Oset_propertycommand, CVE-2026-14483, CVSS 9.8. - Spider Analyser <= 2.1.3: unauthenticated remote code execution, CVE-2026-65553, CVSS 9.8.
- Betheme <= 28.4.2: authenticated contributor-and-above remote code execution, CVE-2026-65548, CVSS 8.8.
- BuddyPress <= 14.5.0: authenticated subscriber-and-above PHP object injection via XProfile field data, CVE-2026-1360, CVSS 7.5.
Plugins and themes on the watch list
The report’s software lists are broad, spanning popular builders, form plugins, backup tools, e-commerce add-ons, membership systems, and SEO products. Alongside the high-profile findings above, Wordfence also recorded vulnerabilities in products such as AI Engine, Meta Box AIO, Pronamic Pay, Subscriptions for WooCommerce, Wholesale for WooCommerce, WP Password Policy, Kali Forms, NEX-Forms, and Bit integrations.
On the theme side, the two products named in the week’s disclosures were Betheme and Gillion | Multi-Concept Blog/Magazine & Shop WordPress AMP Theme. The report does not say Gillion appears among the detailed vulnerability entries shown in the source material, but it is included in the week’s overall tally of affected themes.
Why Wordfence says the report matters
Wordfence notes that users running the Wordfence plugin with scanning enabled should already have been notified if their site was affected by any of these vulnerabilities. The company also says its Premium, Care, and Response customers received firewall protection immediately for selected issues last week, while free users will receive equivalent protection after a 30-day delay.
For security teams, the practical takeaway is simple: even when a vulnerability is already patched upstream, exposure can persist if a site has not yet updated. The week’s mix of RCE, authentication bypass, file upload, file deletion, and privilege escalation bugs shows why plugin and theme inventory management remains a core part of WordPress defense.
Wordfence also continues to use the weekly report to highlight the researchers behind the disclosures. Top contributors last week included Wordfence PRISM, Ananda Dhakal, daroo, Dmitrii Ignatyev, Mustafa Ahmed, Rafie Muhammad, and others across a long list of individual submissions.
Site owners who want ongoing visibility can subscribe to Wordfence’s mailing list for weekly vulnerability reports and related WordPress security updates. The company says its free webhook and API tools are intended to help teams keep pace with the steady flow of new disclosures.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: August 16, 2026 at 1:52 am
0 views
