
Wordfence Intelligence’s weekly WordPress vulnerability report for September 7 to September 13, 2026 shows another busy seven days for the ecosystem, with 260 vulnerabilities disclosed across 207 WordPress plugins and 147 researchers contributing findings. The latest report highlights a mix of patched and still-open issues, including critical flaws tied to privilege escalation, arbitrary file upload, authentication bypass, and remote code execution.
What stood out in Wordfence Intelligence this week
Wordfence says its vulnerability database, user interface, API, and webhook integration are free to use personally and commercially, and that the weekly report is part of its broader effort to make WordPress security data easier to act on. The company also notes that its database now contains more than 40,000 vulnerabilities, which can be accessed through the database API and real-time webhook updates.
For site owners, the headline number is not just the volume of disclosures but the spread of severity and patch status. Of the vulnerabilities added last week, 218 were patched, one was partially patched, and 41 remained unpatched at the time of publication.
Severity breakdown
- Medium severity: 184
- High severity: 66
- Critical severity: 10
Cross-site scripting remained the most common weakness class, but authorization and data exposure problems were close behind. That pattern is familiar in WordPress plugin research: a large share of practical risk comes from access control failures and unsafe handling of user input rather than from a single bug type.
Most common weakness types in the report
- Improper Neutralization of Input During Web Page Generation, or cross-site scripting: 66
- Missing Authorization: 58
- Exposure of Sensitive Information to an Unauthorized Actor: 21
- Improper Neutralization of Special Elements used in an SQL Command, or SQL injection: 18
- Improper Privilege Management: 15
- Authorization Bypass Through User-Controlled Key: 13
- Path Traversal: 11
- Deserialization of Untrusted Data: 10
- Code Injection: 9
Other recurring issues included improper authentication, unrestricted file upload, CSRF, open redirect, SSRF, and unverified password change. The mix suggests that defenders should continue treating plugin updates as a high-priority maintenance task, especially for sites that rely on advanced form builders, LMS tools, ecommerce extensions, and page builders.
Critical WordPress plugin flaws worth watching
Several of the most serious findings involved direct paths to takeover or code execution. One of the most severe was Advanced Customized Prompts <= 1.0.1, which had an unauthenticated privilege escalation via account takeover issue rated 9.8 and tracked as CVE-2026-14563. Wordfence marked it as unpatched, and the issue was published on September 9, 2026.
Another critical issue affected Frontegg SAML SSO <= 1.0.1, where an authentication bypass to admin also scored 9.8 under CVE-2026-75800. That flaw was likewise listed as unpatched and published on September 10.
The report also included two critical vulnerabilities in Teddy Bear Customize Addon <= 1.0.5: an unauthenticated arbitrary file upload issue and an unauthenticated privilege escalation via account takeover issue, both rated 9.8. Wordfence marked both as unpatched and assigned them CVE-2026-14560 and CVE-2026-14559.
Other high-impact issues
- The Events Calendar <= 6.17.3: unauthenticated code injection to remote code execution via widget “classes” map callable invocation, CVSS 9.8, patched, CVE-2026-78159.
- The Events Calendar <= 6.17.4: unauthenticated PHP object injection to remote code execution, CVSS 9.8, patched, CVE-2026-78006.
- Advanced Product Fields Extended for WooCommerce <= 3.1.6: unauthenticated arbitrary file deletion, CVSS 9.1, unpatched, CVE-2026-81789.
- CryptoPayment Gateway 1.2.1–1.2.2: unauthenticated arbitrary file deletion, CVSS 9.1, unpatched, CVE-2026-81648.
- FireBox <= 3.1.10: authenticated remote code execution to privilege escalation, CVSS 8.8, patched, CVE-2026-76801.
- Gpx2Graphics <= 0.3: CSRF to arbitrary file upload, CVSS 8.8, unpatched, CVE-2026-81090.
Patterns across the week’s disclosures
Many of the issues reported last week clustered around plugins that extend common WordPress workflows: forms, booking, ecommerce, memberships, and page building. Those categories are attractive targets because they often interact with logged-in users, process uploads, or touch sensitive account data.
Several authenticated flaws were also notable because they could let lower-privileged users step up to broader access. Examples included MemberPress Corporate Accounts, YITH WooCommerce Waitlist Premium, SureCart, and UsersWP, all of which were listed with privilege escalation or account takeover-style problems. Even when a bug is not unauthenticated, it can still be serious in a multi-user WordPress environment where contributors, subscribers, and customer accounts are common.
Researchers driving the disclosures
Wordfence credited 147 researchers for the week’s findings, with Wordfence PRISM leading the list at 25 vulnerabilities. Other top contributors included Artus KG, Ananda Dhakal, and Jakub Herman, each with 10, followed by Yaswanth Reddy Sunkara, 0xBassia, and Karthik Ramakrishnan with six each.
The report also shows how broad the contributor base has become, with dozens of researchers credited for single findings. Wordfence says researchers who responsibly disclose WordPress vulnerabilities can be added to the Wordfence Intelligence leaderboard and may earn bounties through the company’s bug bounty program for in-scope issues.
What site owners should do now
The practical takeaway from this report is straightforward: plugin inventory matters, and update discipline matters even more. Wordfence says users of its plugin with the scanner enabled should already have been notified if their sites were affected, but site owners should still review the weekly disclosures against their installed plugins and versions.
- Check whether any installed plugin appears in the week’s affected software list.
- Update patched plugins immediately, especially those tied to file uploads, authentication, or account management.
- Remove plugins that are no longer needed, since unused software still expands attack surface.
- Pay extra attention to unpatched issues and watch for vendor follow-up releases.
- Use layered defenses such as least privilege, backups, and security monitoring.
Wordfence is also encouraging users to subscribe to its mailing list for weekly reports and important WordPress security updates. For teams managing multiple WordPress sites, that kind of recurring visibility can help turn vulnerability intelligence into a routine maintenance process rather than a reactive scramble after an incident.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: September 20, 2026 at 10:32 pm
0 views
