
Wordfence Intelligence’s latest weekly WordPress vulnerability report says 501 vulnerabilities were disclosed last week across 367 plugins and 9 themes, with 201 vulnerability researchers contributing to WordPress security. The report, covering September 28, 2026 to October 4, 2026, also notes that Wordfence deployed a new firewall rule in real time for one issue while the vendor works on a patch.
Wordfence Intelligence reports a busy week for WordPress security
The weekly roundup is part of Wordfence’s broader effort to make vulnerability data easier to use for site owners, developers, and hosting teams. Wordfence says its Intelligence user interface, vulnerability API, and webhook integration are free for personal and commercial use, and that the database now contains more than 40,000 vulnerabilities.
The company says the goal is to support layered security and defense-in-depth planning by making it easier to monitor newly disclosed issues and updates as they are added. Enterprises, hosting providers, and individual site owners can pull a full database dump through the API or use webhooks to track changes in real time.
New firewall protection was rolled out for one disclosed issue
According to the report, Wordfence’s Threat Intelligence Team reviewed each vulnerability to assess impact, severity, and exploitation likelihood before deciding whether the firewall needed additional protection. Last week, the team deployed enhanced protection for one vulnerability identified as WAF-RULE-963, with the underlying data redacted while the company works with the vendor on a patch.
That protection was delivered immediately to Wordfence Premium, Care, and Response customers. Users of the free version will receive the same enhanced protection after a 30-day delay, which follows Wordfence’s normal release timing for firewall rule updates.
Patch status: most issues were already fixed, but dozens remained open
Wordfence’s summary shows a strong bias toward patched issues, though the volume remains high. Of the vulnerabilities disclosed last week, 449 were marked patched and 52 were still unpatched at the time of the report.
- Patched: 449
- Unpatched: 52
That split matters because the presence of a patch does not always mean every affected site has applied it. For WordPress administrators, the report is a reminder to check installed plugin and theme versions rather than assuming a product is safe simply because a fix exists.
Severity breakdown shows most disclosures were medium or high risk
By CVSS severity, the week was dominated by medium and high findings, with a smaller but still notable set of critical issues. Wordfence listed just one low-severity issue, compared with 306 medium-severity vulnerabilities, 174 high-severity vulnerabilities, and 20 critical vulnerabilities.
- Low severity: 1
- Medium severity: 306
- High severity: 174
- Critical severity: 20
That mix suggests a steady flow of bugs that could have meaningful operational impact, even when they do not rise to the most severe tier. For site owners, the practical takeaway is that “medium” does not mean harmless, especially when flaws involve access control, data exposure, or injection-style problems.
Cross-site scripting and authorization failures led the pack
Wordfence also broke down the week’s disclosures by CWE type, and one category stood out clearly: cross-site scripting. The report counted 206 cases of improper neutralization of input during web page generation, followed by 68 missing authorization issues and 42 SQL injection vulnerabilities.
Other common categories included exposure of sensitive information to an unauthorized actor, deserialization of untrusted data, authorization bypass through user-controlled keys, and code injection. The list reflects the broad mix of application-layer mistakes that continue to affect the WordPress ecosystem.
- Cross-site scripting: 206
- Missing authorization: 68
- SQL injection: 42
- Exposure of sensitive information: 34
- Deserialization of untrusted data: 30
- Authorization bypass through user-controlled key: 23
- Code injection: 14
- Path traversal: 13
- Improper privilege management: 13
The remaining categories were spread across issues such as client-side enforcement of server-side security, improper authentication, CSRF, unrestricted file upload, SSRF, and several one-off findings including hard-coded passwords and insufficiently protected credentials. In total, the distribution points to a familiar theme in plugin and theme security: many weaknesses still stem from weak validation, missing checks, and unsafe trust in user-supplied input.
Researchers behind the disclosures
Wordfence credited 201 researchers for contributing to WordPress security during the week. At the top of the leaderboard was Ananda Dhakal with 72 vulnerabilities, followed by Intrudify with 19, Jakub Herman with 14, and both nh4tvd and neurotx with 12 each.
Other notable contributors included Artus KG with 10 disclosures, Kuba and Rafie Muhammad with 9 each, and a large group of researchers credited with between seven and one vulnerability apiece. Wordfence says researchers who responsibly disclose issues can be featured in the weekly report and may also earn bounties on in-scope findings through its Bug Bounty Program.
The company frames the leaderboard as a way to recognize ongoing reporting work as well as a practical source of visibility for security researchers. For WordPress users, it is a reminder that the ecosystem’s defensive posture depends not just on patching, but on a steady pipeline of disclosure and coordination.
What WordPress site owners should do now
The report does not single out a short list of universally affected plugins or themes in the summary data, but the scale alone makes review worthwhile. Wordfence’s recommendation is implicit in the publication itself: review the vulnerabilities, confirm whether any affected software is installed, and patch promptly where fixes are available.
A sensible response for site operators includes:
- Updating all plugins and themes to the latest versions.
- Removing unused software that no longer needs to be installed.
- Checking whether privileged accounts are limited to essential users.
- Monitoring security logs for suspicious admin actions or file changes.
- Using firewall and vulnerability intelligence feeds to track new disclosures.
For organizations managing multiple sites, the Wordfence API and webhook tools may be especially useful because they can help automate visibility across a broader footprint. In a week with 501 newly disclosed vulnerabilities, scale itself is the main risk signal.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: October 10, 2026 at 10:33 pm
0 views
