
Wordfence’s latest weekly report shows another busy seven days for the WordPress ecosystem: 246 vulnerabilities were disclosed across 174 plugins and five themes added to the Wordfence Intelligence Vulnerability Database between August 24 and August 30, 2026. Of those, 234 were already patched and 12 remained unpatched at the time of publication, while Wordfence says 121 vulnerability researchers contributed to WordPress security last week.
Wordfence Intelligence tracks a surge of new issues
The report is designed as a snapshot of newly disclosed WordPress security issues and the response around them. Wordfence says its goal is to make vulnerability information broadly accessible so site owners, enterprises and hosting providers can use it to build layered defenses.
That includes free access to the Wordfence Intelligence user interface, vulnerability API, webhook integration and Wordfence CLI Vulnerability Scanner. The company also says its database now contains more than 35,000 vulnerabilities.
Firewall protections went out for several high-risk bugs
Wordfence’s Threat Intelligence Team reviewed the newly disclosed issues and rolled out firewall rules in real time for Premium, Care and Response customers. Free users will receive the same enhanced protection after a 30-day delay.
The newly covered vulnerabilities included:
- InfusedWoo Pro <= 5.1.18 — authenticated privilege escalation via password reset link disclosure
- WPeMatico RSS Feed Fetcher <= 2.8.24 — authenticated privilege escalation via arbitrary option update to
wpematico_import_settingsadmin_action - WPMU DEV Dashboard <= 5.0.1 — authentication bypass to administrator via SSO HMAC canonicalization confusion
- WPLP Cookie Consent <= 4.4.1 — unauthenticated arbitrary file upload via the
upload-logoREST endpoint - WAF-RULE-953 and WAF-RULE-955 — details were redacted while Wordfence worked with the vendor on patches
Critical findings were concentrated in plugins, not themes
The weekly tally was dominated by plugin disclosures. Wordfence logged 18 critical issues, 73 high-severity issues, 153 medium-severity issues and two low-severity issues. The largest share of vulnerability types were cross-site scripting, missing authorization and SQL injection.
By CWE classification, the most common categories were:
- Cross-site scripting: 57
- Missing authorization: 46
- SQL injection: 22
- Authorization bypass through user-controlled key: 16
- Exposure of sensitive information to an unauthorized actor: 14
- Path traversal: 14
- Improper privilege management: 13
- Code injection: 10
Other notable categories included deserialization of untrusted data, unrestricted file upload, CSRF, SSRF, improper authentication and several different kinds of authentication bypass.
Notable Wordfence Intelligence findings from the week
Several of the highest-profile entries affected widely used plugins and two Avada-related products. Wordfence listed a mix of unauthenticated takeover, file upload, remote code execution and authentication bypass flaws.
Avada, GiveWP and TranslatePress stand out
Avada <= 7.16 and Fusion Builder <= 3.16 were listed with an unauthenticated remote code execution issue through arbitrary file write. Wordfence marked that one as patched. The vulnerability was assigned CVE-2026-18431 and credited to Alex Thomas and Wordfence Argus.
GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 was reported with unauthenticated PHP object injection leading to remote code execution, patched and assigned CVE-2026-82222. Yuto Hyakumoto was credited for reporting an unauthenticated account takeover issue in TranslatePress – Translate Multilingual sites with AI Translation <= 3.3.1, which Wordfence also says was patched.
Several authentication bypasses were rated critical
WPMU DEV Dashboard <= 5.0.1 was one of the week’s critical findings, with Wordfence describing an authentication bypass to administrator via SSO HMAC canonicalization confusion. The same week also brought an authentication bypass to administrator for SmilePass Selfie Login <= 1.0.2, though that one remained unpatched in the report.
Other critical or near-critical authentication and privilege issues included ACPT (Premium) <= 2.0.63, which Wordfence flagged for unauthenticated privilege escalation, and MyHome Core <= 4.4.5, which it described as an authentication bypass to account takeover via activation token.
File upload and object injection issues remained common
Wordfence reported multiple vulnerabilities that could be chained into worse outcomes if left unpatched. Hash Form – Drag & Drop Form Builder had two separate entries: one for unauthenticated arbitrary file upload and another for unauthenticated PHP object injection. Geo Controller, Tickera, and Share Files were also among the affected plugins, each with high-risk flaws involving object injection or file handling.
Other notable cases from the week included:
- Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 — unauthenticated remote code execution
- ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 — unauthenticated arbitrary file upload via CRM email connect IMAP attachment
- All-in-One WP Migration and Backup <= 7.109 — unauthenticated second-order SQL injection via archive restore to remote code execution
- Rank Math SEO <= 1.0.276 — authenticated remote code execution
- Pods < 3.3.9.1 — authenticated remote code execution
- Classified Listing – Mobile Number Verification <= 1.6.0 — unauthenticated authentication bypass via Firebase OTP login
Researchers drove a large share of the disclosures
Wordfence highlighted 121 researchers who contributed to WordPress security last week, showing how distributed vulnerability discovery has become across the ecosystem. At the top of the leaderboard was Ananda Dhakal with 17 vulnerabilities, followed by Wordfence PRISM with 14, and Jakub Herman and daroo with 12 each.
Other notable contributors included Shikhali Jamalzade and Erwan LR with nine each, JunHee CHO and Sai Praneeth Koti with seven each, and a long tail of researchers who each reported one or two issues. Wordfence says those who responsibly disclose vulnerabilities can be featured in the weekly report and may earn bounties through its Bug Bounty Program.
What site owners should do now
The practical takeaway from the report is straightforward: update affected plugins and themes quickly, and do not assume a popular product is automatically safe. Some of the most serious issues in the list affected backup tools, page builders, form plugins, membership systems and e-commerce extensions — exactly the kind of software many WordPress sites rely on every day.
Wordfence also notes that users running the Wordfence plugin with the scanner enabled should already have received alerts if their site matched any of the affected versions. For teams managing multiple sites, the company points to the CLI scanner, database API and webhook integration as free ways to monitor exposure and react to new disclosures in real time.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: September 5, 2026 at 10:18 am
0 views
