
Wordfence Intelligence says 224 WordPress vulnerabilities were disclosed last week across 177 plugins and two themes, with 119 researchers contributing to the database between July 27, 2026 and August 2, 2026. The weekly report highlights a mix of patched and unpatched issues, including several critical flaws that Wordfence says it has already covered with firewall protections for paid customers.
Wordfence Intelligence Weekly WordPress Vulnerability Report
The company frames Wordfence Intelligence as a free way to surface vulnerability data for the WordPress community, with access through its user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner. Wordfence says the scanner can be used by enterprises, hosting providers, and individual site owners to run regular checks, while the API can provide a complete dump of its database of more than 35,000 vulnerabilities.
For site owners, the practical takeaway is simple: last week’s disclosures were broad, varied, and in several cases severe enough to warrant immediate review. Wordfence also says users running its plugin with the scanner enabled should have already been notified if their site was affected.
What changed last week
According to the report, 186 vulnerabilities were patched and 38 remained unpatched at the time of publication. Severity was weighted toward lower tiers, but the total still included 13 critical issues and 61 high-severity issues.
- Patched: 186
- Unpatched: 38
- Medium severity: 150
- High severity: 61
- Critical severity: 13
Across the full set, the most common weakness categories were cross-site scripting, missing authorization, SQL injection, and exposure of sensitive information. That pattern suggests the week was dominated by familiar web application problems rather than a single exploit trend.
Most common vulnerability types
- Cross-site scripting: 72
- Missing authorization: 47
- SQL injection: 31
- Exposure of sensitive information to an unauthorized actor: 14
- Authorization bypass through user-controlled key: 12
- Path traversal: 10
- CSRF: 7
- SSRF: 6
Wordfence Intelligence firewall rules deployed in real time
Wordfence said its Threat Intelligence Team reviewed the newly disclosed issues for impact, severity, and exploitability, then deployed firewall rules to protect Premium, Care, and Response customers where needed. The company listed protections for two specific vulnerabilities and also noted two redacted WAF rules while it continued working with vendors on patches.
- WPMU DEV Dashboard <= 5.0.0 — Authentication bypass to arbitrary plugin installation, which could lead to remote code execution, via forged WDP_AUTH HMAC on the
?wpmudev-hub=endpoint. - Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 — Unauthenticated authentication bypass via a hardcoded backdoor in the
_wploginparameter. - WAF-RULE-935 — Data redacted while Wordfence works with the vendor on a patch.
- WAF-RULE-937 — Data redacted while Wordfence works with the vendor on a patch.
Wordfence said Premium, Care, and Response users received the extra protection immediately, while free users will get it after a 30-day delay.
Notable critical issues in WordPress plugins
The report’s most urgent entries include several critical vulnerabilities rated 9.8 under CVSS. Some were already patched, while others remained open at publication. The mix shows why WordPress operators are often told to prioritize both update management and defensive monitoring.
- Admin and Site Enhancements (ASE) Pro <= 8.9.0 — Unauthenticated remote code execution via PHP code injection through the
cfgroup[input]repeater row key. CVE-2026-16610, patched, published Jul. 29, 2026. - Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 — Unauthenticated authentication bypass via hardcoded backdoor in
_wplogin. CVE-2026-18072, unpatched, published Jul. 28, 2026. - AI Copilot – Content Generator <= 1.5.6 — Unauthenticated privilege escalation. CVE-2026-65507, patched, published Jul. 28, 2026.
- Cost Calculator Builder PRO <= 4.0.3 — Unauthenticated remote code execution via the
orderDetailsparameter. CVE-2026-14900, patched, published Jul. 28, 2026. - Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 — Unauthenticated arbitrary file upload via the
files[file]parameter through public I/Oset_propertycommand. CVE-2026-14483, unpatched, published Jul. 30, 2026. - Single Sign On For TNG <= 2.0.0 — Unauthenticated privilege escalation via unverified password change. CVE-2026-15964, patched, published Jul. 31, 2026.
- SMS Alert <= 3.9.7 — Unauthenticated authentication bypass to account takeover via the
billing_phoneparameter. CVE-2026-15014, patched, published Jul. 27, 2026. - Spider Analyser <= 2.1.3 — Unauthenticated remote code execution. CVE-2026-65553, unpatched, published Jul. 29, 2026.
- Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 — Missing authorization leading to unauthenticated privilege escalation via admin account creation. CVE-2025-10656, unpatched, published Jul. 28, 2026.
- WooCommerce – Social Login <= 2.8.7 — Unauthenticated authentication bypass via forged Apple
id_tokenJWT. CVE-2026-8457, patched, published Aug. 1, 2026.
High-severity bugs in popular plugins and themes
Beyond the critical findings, the weekly report includes several high-severity issues that could still be valuable to attackers, especially in sites that delay updates. These span authentication weaknesses, file deletion, arbitrary file upload, and object injection paths.
- AI Engine <= 3.6.5 — CSRF to privilege escalation via REQUEST_URI substring match. CVE-2026-15988, patched.
- Betheme <= 28.4.2 — Authenticated contributor-and-above remote code execution. CVE-2026-65548, unpatched.
- Eazy Plugin Manager <= 4.4.1 — Authenticated subscriber-and-above privilege escalation via the
pos_get_optionAJAX action and admin/login REST endpoint. CVE-2026-14328, unpatched. - Extra Checkout Options <= 2.3.2 — Missing authorization leading to authenticated subscriber-and-above arbitrary file upload in
eco_save_settings. CVE-2026-14270, patched. - FleekDash V2 <= 2.6.2.2 — Missing authorization leading to authenticated subscriber-and-above administrator account takeover via the
/users/{id}REST endpoint. CVE-2026-14356, patched. - Pronamic Pay <= 10.1.0 — Authenticated subscriber-and-above privilege escalation via Gravity Forms “Update user role” field. CVE-2026-16635, patched.
- Subscriptions for WooCommerce <= 2.0.0 — Authenticated contributor-and-above privilege escalation via the
_wps_plan_user_rolemembership plan meta. CVE-2026-15414, patched. - WP Password Policy <= 3.7.1 — Authenticated subscriber-and-above privilege escalation. CVE-2026-15992, patched.
- BuddyPress <= 14.5.0 — Authenticated subscriber-and-above PHP object injection via XProfile field data. CVE-2026-1360, unpatched.
- CubeWP Framework <= 1.1.30 — Unauthenticated arbitrary file read via
prev_icon/next_iconparameter. CVE-2026-13339, patched.
Researchers who stood out
Wordfence credited 119 vulnerability researchers during the week, with Wordfence PRISM leading the list at 49 reports. Ananda Dhakal followed with 26, while daroo contributed 11.
Other notable contributors included Nabil Irawan and Rafie Muhammad with four findings each, Abdullah Kareem “cyberkareem” with four, and a long tail of researchers with one to three disclosures. Wordfence also reiterated that responsible disclosure can earn a bounty on in-scope findings and a spot on the leaderboard.
What WordPress site owners should do now
The report does not suggest that every site is affected, but it does reinforce the need for routine patching and active monitoring. In particular, site owners running any of the affected plugins or themes should check version numbers, apply available updates, and review Wordfence notifications if the scanner is enabled.
For teams managing multiple sites, Wordfence’s free API and webhook tools may be the fastest way to keep vulnerability intelligence flowing into existing workflows. The report’s scale also underscores a recurring reality in the WordPress ecosystem: even a single week can bring enough disclosures to justify a broad review of the software inventory.
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: August 10, 2026 at 4:58 pm
1 views
