
Wordfence Intelligence’s weekly WordPress vulnerability report for September 14 to September 20, 2026, shows another busy week for the ecosystem: 358 vulnerabilities were disclosed across 243 plugins and four themes, with 184 researchers contributing to WordPress security. The latest data also highlights several critical issues affecting widely used plugins, including unauthenticated file uploads, privilege escalation, authentication bypasses, and remote code execution.
What the latest Wordfence Intelligence data shows
Wordfence says its mission is to make vulnerability information easy to access so WordPress site owners and security teams can apply layered defenses. The company notes that its Intelligence UI, vulnerability API, and webhook integration are free to use, both personally and commercially, and that its database now contains more than 40,000 vulnerabilities.
For organizations with many sites or rapid release cycles, the API and webhook options are meant to reduce the delay between disclosure and action. Wordfence also says enterprises, hosting providers, and individual users can pull the full vulnerability database and receive real-time updates when new entries are added or changed.
Patch status: most issues fixed, but dozens remain open
Of the vulnerabilities added last week, Wordfence categorized 311 as patched and 47 as unpatched. That distribution suggests many vendors moved quickly, but it also leaves a meaningful number of issues that still need attention from site operators.
- Patched: 311
- Unpatched: 47
Wordfence also reported 18 critical vulnerabilities, 74 high-severity issues, 262 medium-severity issues, and four low-severity issues. While the majority landed in the medium range, the volume of critical findings makes timely updates especially important for sites running affected software.
Wordfence firewall rules addressed one core vulnerability in real time
The Wordfence Threat Intelligence Team said it reviewed each vulnerability for impact, severity, and exploit likelihood before deciding whether the firewall offered enough protection. Last week, the team deployed an enhanced firewall rule for a WordPress core issue described as “WordPress Core <= 7.1 – Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling.”
Wordfence said Premium, Care, and Response customers received protection immediately, while free users will get the same enhanced protection after a 30-day delay. The company also identified the rule as WAF-RULE-957 and noted that some details were redacted while it works with the vendor on a patch.
Standout critical vulnerabilities in plugins
Several of the week’s highest-risk issues affected popular plugin categories such as forms, booking, uploads, and e-commerce extensions. In many cases, the problems were severe enough to allow unauthenticated attacks, which is why Wordfence assigned them critical CVSS scores of 9.8 or 9.1.
Among the critical entries were the following:
- Admin Menu Editor Pro 2.35–2.36 — backdoored software, CVSS 9.8, unpublished patch status, researched by Unknown.
- Advanced Custom Fields: Extended PRO <= 0.9.2.6 — unauthenticated remote code execution via Dynamic Render Field Type, CVSS 9.8, patched.
- Choose User Role at Registration for WooCommerce <= 1.3.2 — unauthenticated privilege escalation, CVSS 9.8, patched, with CVE-2026-85128.
- DS Ad Rotator <= 0.8 — unauthenticated arbitrary file upload, CVSS 9.8, unpatched, with CVE-2026-81402.
- Gravity Forms <= 3.1.0.4 — unauthenticated arbitrary file upload via Hidden File Upload Field, CVSS 9.8, patched, with CVE-2026-84434.
- JetFormBuilder <= 3.6.2 — unauthenticated privilege escalation via the
_jet_engine_booking_form_idparameter, CVSS 9.8, patched, with CVE-2026-12793. - Login with QR <= 1.0.0 — authentication bypass, CVSS 9.8, unpatched, with CVE-2026-86710.
- Migratico Lite <= 2.6.8 — unauthenticated remote code execution, CVSS 9.8, patched, with CVE-2026-62104.
- Multi Uploader for Gravity Forms <= 1.1.9 — unauthenticated arbitrary file upload via chunked file upload, CVSS 9.8, unpatched, with CVE-2026-87796.
- Private Feed Key <= 0.1 — authentication bypass, CVSS 9.8, unpatched, with CVE-2026-86707.
- The Pressengine <= 1.0 — authentication bypass, CVSS 9.8, unpatched, with CVE-2026-86709.
- TrueBooker <= 1.2.3 — missing authorization leading to unauthenticated arbitrary user email modification via the
admin_addcustomerAJAX action, CVSS 9.8, patched, with CVE-2026-14349. - Ultimate Addons for Contact Form 7 3.2.4–3.5.50 — unauthenticated arbitrary file upload, CVSS 9.8, patched, with CVE-2026-84750.
- WooCommerce Online Product Designer <= 2.14.0 — unauthenticated arbitrary file upload, CVSS 9.8, patched, with CVE-2026-82187.
- WP images upload on piclect <= 1.0 — unauthenticated arbitrary file upload, CVSS 9.8, unpatched, with CVE-2026-84171.
- wpShopGermany IT-RECHT KANZLEI <= 2.3 — unauthenticated remote code execution, CVSS 9.8, patched, with CVE-2026-88795.
Wordfence also flagged a critical issue in Forminator Forms <= 1.57.2: unauthenticated arbitrary shortcode execution via the current_url parameter. That vulnerability carries a CVSS score of 9.1 and is patched, with CVE-2026-92229.
Another 9.1-severity issue affected WP Recipe Maker <= 10.8.1, where unauthenticated arbitrary shortcode execution was possible via recipe comment content. Wordfence lists that issue as patched, with CVE-2026-89274.
Common attack paths: file upload, auth bypass, and injection
The week’s CWE breakdown shows what attackers are most likely to target in WordPress plugins and themes. Cross-site scripting led the list with 94 findings, followed by missing authorization with 68 and SQL injection with 35.
That pattern fits the kinds of bugs that continue to show up in plugin ecosystems: flaws in permission checks, user input handling, and upload logic. Wordfence’s figures also show 27 cases of authorization bypass through user-controlled keys and 26 cases of sensitive information exposure.
- Cross-site scripting: 94
- Missing authorization: 68
- SQL injection: 35
- Authorization bypass through user-controlled key: 27
- Exposure of sensitive information: 26
- Improper privilege management: 19
- Code injection: 13
- Unrestricted file upload: 12
For site owners, the practical takeaway is straightforward: plugins that accept uploads, expose AJAX actions, or handle user-generated content deserve extra scrutiny. Those are the places where a missed permission check or weak validation can become a high-impact incident.
Researcher activity remained broad and international
Wordfence credited 184 vulnerability researchers last week, underscoring how distributed WordPress security research has become. The leaderboard was topped by Wordfence PRISM with 25 findings, followed by Karthik Ramakrishnan with 17, Ananda Dhakal with 13, Artus KG with 12, and several researchers tied around the low double digits.
Notable names in the top group also included Pablo González Pérez, Francisco José Ramírez Vicente, Iñigo Sánchez Enciso, and mak3bread. Wordfence says researchers can join its bug bounty program, responsibly disclose vulnerabilities, and earn recognition on the Intelligence leaderboard as well as in the weekly report.
What site owners should do now
With 358 vulnerabilities disclosed in a single week, the most important action is still the simplest one: inventory what you run and patch quickly. If a plugin is no longer maintained, or if you do not need a feature tied to a vulnerable component, removal may be safer than waiting for a fix.
It is also worth checking whether your Wordfence scanner is enabled, since the company says affected customers should already have been notified. For organizations that want faster alerts across many environments, Wordfence recommends its free Slack and HTTP webhook integration for real-time vulnerability notifications.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: September 25, 2026 at 10:33 pm
0 views
