
Wordfence Intelligence’s weekly WordPress vulnerability report for August 17 to August 23, 2026 shows another heavy seven days for the ecosystem: 240 vulnerabilities were disclosed across 184 plugins and 17 themes added to the database, with 105 researchers contributing findings. The week included a mix of patched and still-open issues, from critical unauthenticated attacks to high-severity bugs that could affect authenticated users and site administrators.
Wordfence’s weekly snapshot of WordPress risk
Wordfence says its Intelligence platform is designed to make vulnerability data accessible to the broader WordPress community, and the company again used the report to point site owners toward its free tools. Those include the Wordfence Intelligence user interface, vulnerability API, webhook integration, and the Wordfence CLI Vulnerability Scanner, all available for personal and commercial use.
The report also notes that enterprises, hosting providers, and individuals can use the CLI scanner to check protected sites regularly, or pull the full vulnerability database through the API and subscribe to real-time updates through webhooks. Wordfence says its database now contains more than 35,000 vulnerabilities.
Critical flaws dominated the week’s biggest disclosures
Of the vulnerabilities added last week, 167 were listed as patched and 73 as unpatched. By severity, Wordfence recorded 111 medium-severity issues, 112 high-severity issues, and 17 critical issues.
The report’s highest-profile items were mostly 9.8 CVSS bugs affecting widely used plugins. Several involved unauthenticated file upload, privilege escalation, remote code execution, or SSRF, the kind of issues that can lead to full site compromise if exploited before patching.
Some of the most serious vulnerabilities
- Automation Web Platform <= 4.8.6 — unauthenticated authentication bypass via
otp_transienttoken disclosure; CVSS 9.8; CVE-2026-77264; unpatched. - Broken Link Checker < 2.4.12 — unauthenticated remote code execution; CVSS 9.8; CVE-2026-18937; patched.
- DynamicKit for Elementor < 1.0.3 — unauthenticated privilege escalation via account takeover; CVSS 9.8; CVE-2026-14596; patched.
- Elementor Pro <= 4.2.1 — unauthenticated arbitrary file upload via upload field array validation bypass; CVSS 9.8; CVE-2026-32475; patched.
- Forminator Forms <= 1.56.1 — unauthenticated arbitrary file upload via forged upload field configuration; CVSS 9.8; CVE-2026-15748; patched.
- JetEngine <= 3.8.14 — unauthenticated remote code execution; CVSS 9.8; CVE-2026-66613; patched.
- JSON Options <= 0.0.4 — unauthenticated remote code execution; CVSS 9.8; CVE-2026-75860; unpatched.
- Mailgun for WordPress <= 2.2.0 — unauthenticated SSRF via
addressesarray keys; CVSS 9.8; CVE-2026-78003; patched. - Masteriyo LMS <= 2.3.2 — unauthenticated arbitrary file upload; CVSS 9.8; CVE-2026-73996; patched.
- ShopMonitor.io < 1.2.0 — unauthenticated privilege escalation via account takeover; CVSS 9.8; CVE-2026-14919; patched.
- Total Donations <= 2.0.5 — unauthenticated privilege escalation and unauthenticated SQL injection; both CVSS 9.8; CVE-2026-78570 and CVE-2026-78568; both unpatched.
- TrueBooker <= 1.2.6 — unauthenticated authorization bypass through user-controlled key to account takeover via
truebooker_wp_user_id; CVSS 9.8; CVE-2026-18315; patched. - User Registration PRO <= 5.4.5 — unauthenticated privilege escalation via account takeover; CVSS 9.8; CVE-2026-74001; patched.
- WP Compress < 7.20.01 — unauthenticated remote code execution; CVSS 9.8; CVE-2026-73343; patched.
- WS Form LITE <= 1.10.80 — unauthenticated PHP object injection via form submission; CVSS 9.8; CVE-2026-4703; patched.
Where the week’s bugs clustered
Across all disclosures, cross-site scripting remained the most common weakness class, with 73 findings. Missing authorization followed with 42, then SQL injection with 27. Wordfence also logged a notable number of deserialization issues, privilege management failures, file upload flaws, and path traversal bugs.
Top CWE categories reported
- Cross-site scripting: 73
- Missing authorization: 42
- SQL injection: 27
- Deserialization of untrusted data: 14
- Improper privilege management: 12
- Authorization bypass through user-controlled key: 11
- PHP remote file inclusion: 11
- Exposure of sensitive information to an unauthorized actor: 10
- Unrestricted upload of dangerous file types: 10
The mix suggests that developers are still struggling with the same recurring problem areas: access control, input validation, and secure file handling. For site owners, those categories matter because they often map directly to exploitable outcomes such as admin takeover, data theft, or remote code execution.
Notable themes and plugins affected
The list of affected software was broad, spanning e-commerce, booking, form-building, SEO, backup, media, and membership plugins, plus several themes. Wordfence’s database additions included both well-known products and smaller utilities, showing that security exposure is not limited to the largest vendors.
Among the affected plugins were Advanced File Manager, All-in-One WP Migration and Backup, Atarim, BookingPress Appointment Booking Pro, Easy Media Replace, Forminator, GeoDirectory, Login With Ajax, NextGEN-related Smart Image Search, SmartSMTP, W3 Total Cache, WP Statistics, WPForms Pro, WPvivid, YITH WooCommerce Membership Premium, and many more. Themes added to the report included Altair, Chaplin, FreightCo, Koji, Shuffle, TheGem, Tonda, and Warehouse Cargo.
Researchers driving disclosure
Wordfence credited 105 researchers for the week’s findings, with several names standing out for volume. The top contributors were daroo with 19 reported vulnerabilities, Ananda Dhakal with 17, dutafi with 16, Tran Nguyen Bao Khanh with 12, and Jakub Herman with 10.
Other prominent contributors included Asim Alshaya, Erwan LR, Wordfence PRISM, Austin Ginder, Denver Jackson, and a long tail of researchers with one or two disclosures each. Wordfence also reminds security researchers that responsible disclosure can earn bug bounties for in-scope vulnerabilities and may result in recognition on its weekly leaderboard.
What site owners should do now
For administrators, the practical takeaway is simple: review installed plugins and themes against the week’s disclosures and patch anything affected as soon as possible. The report notes that Wordfence plugin users with scanning enabled should already have received notifications if their sites were exposed to any of these vulnerabilities.
Even when a vulnerability is marked patched, the risk doesn’t disappear if a site has not updated. Unpatched items are more urgent, particularly where the flaw allows unauthenticated access, remote code execution, or account takeover.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: August 29, 2026 at 1:52 am
6 views

