
Wordfence’s Quarterly WordPress Threat Intelligence Report – Q2 2026 shows another busy three months for the WordPress ecosystem, with billions of blocked attacks, a rise in high-threat vulnerabilities, and a continued climb in malware infections across protected sites. While the total number of newly published vulnerabilities fell quarter over quarter, the report says the most security-sensitive issues remained plentiful — and attackers kept moving quickly to exploit them.
What changed in Q2 2026
Wordfence says it added 2,073 vulnerabilities to its intelligence database during the quarter, down 24.3% from the previous quarter. At the same time, 182 high-threat vulnerabilities were published, up 15.2%, and 357 common and dangerous vulnerabilities rose 80.3%.
The company also says its firewall blocked 10.4 billion requests, a 14.3% increase, while brute-force defenses stopped 18.2 billion login attempts, up 13.8%. Malware detection numbers moved higher too, with 573,000 sites infected, up 21.0%.
The headline numbers at a glance
- Total vulnerabilities published: 2,073
- High-threat vulnerabilities: 182
- Common and dangerous vulnerabilities: 357
- WAF attacks blocked: 10.4 billion
- Brute-force attacks blocked: 18.2 billion
- Sites infected: 573,000
Wordfence says plugins remain the main risk
The report says most vulnerabilities disclosed in Q2 were related to plugins, not themes or WordPress core. It also notes that most issues required unauthenticated access to exploit, matching the pattern seen in Q1 2026.
That matters because unauthenticated flaws are generally easier for attackers to abuse at scale. Wordfence’s summary frames the result as a reminder that site owners need timely patching, but also layered protection in case a vulnerability is not yet fixed.
Most common vulnerability classes
Wordfence’s top vulnerability categories in Q2 were dominated by familiar security weaknesses, led by cross-site scripting and authorization flaws.
- CWE 79: Cross-site scripting — 600
- CWE 862: Missing authorization — 416
- CWE 89: SQL injection — 213
- CWE 352: Cross-site request forgery — 121
- CWE 502: Deserialization of untrusted data — 103
- CWE 98: PHP remote file inclusion — 101
- CWE 200: Sensitive information exposure — 87
- CWE 639: Authorization bypass through user-controlled key — 85
- CWE 22: Path traversal — 76
- CWE 434: Unrestricted file upload — 51
Attacks targeted known WordPress plugin flaws
Wordfence highlighted several specific vulnerabilities that drew heavy scanning and exploitation attempts. The list suggests attackers are still aggressively chasing widely deployed plugins and components where a successful exploit can lead to account takeover, file upload abuse, or privilege escalation.
Among the most targeted issues were LiteSpeed Cache <= 6.3.0.1 for unauthenticated privilege escalation, WPGraphQL <= 0.2.3 for multiple vulnerable actions, and N-Media Post Front-end Form < 1.1 for arbitrary file upload.
Top targeted vulnerabilities by blocked requests
- LiteSpeed Cache <= 6.3.0.1 — 49,711,496 blocked requests
- WPGraphQL <= 0.2.3 — 29,403,849
- N-Media Post Front-end Form < 1.1 — 23,130,942
- WooCommerce Payments 4.8.0–5.6.1 — 12,610,278
- SureTriggers <= 1.0.78 — 10,602,932
- Ninja Forms <= 3.5.7 — 9,975,128
- Rank Math SEO <= 1.0.40.2 — 7,110,040
- POST SMTP Mailer <= 2.8.7 — 4,890,917
- Discount Rules for WooCommerce <= 2.0.2 — 3,797,139
- Envato Elements & Template Kit — 1,742,988
Firewall activity and attack volume kept rising
Wordfence said its firewall logged or blocked 10.4 billion requests in Q2, and the number of unique IPs involved in WAF attacks reached 19.7 million, up 16.7%. The company also reported 353,000 unique IPs from its blocklist, up 58.9%, and 72.9 million unique user agents, a sharp 263.7% increase.
For Wordfence Premium, Care, and Response users, the report says malicious IPs can be blocked automatically through the company’s threat feed, including activity that does not rely on a known vulnerability.
Notable traffic indicators
- WAF requests blocked/logged: 10.4 billion
- Blocked from IP threat feed: 3.1 billion
- Unique IPs in WAF attacks: 19.7 million
- Unique IPs from blocklist: 353,000
- Unique user agents: 72.9 million
Password attacks stayed relentless
On the login side, Wordfence said it blocked 18.2 billion brute-force attacks during the quarter. The number of unique IPs involved reached 106.2 million, while the average requests per IP fell to 171.
The company emphasizes that its free plugin includes protections such as two-factor authentication, blocking logins using known compromised passwords, and brute-force defense. Its guidance to site owners remains straightforward: use strong passwords, enable 2FA, and avoid relying on a single control to stop credential attacks.
Malware detections climbed alongside infections
Wordfence’s malware section shows 31.6 million unique malware files, up 15.2%, and 85 malware signatures released, down slightly by 4.5%. The average infected site contained 49.3 infected files, while the average number of malware variations per site was 2.2.
The report says malware scanning is not just about cleanup after a compromise. Wordfence also uses malware signatures to block uploads of malicious files that match known patterns, adding another layer of prevention to the detection process.
What Wordfence wants site owners to do next
The report’s recommendations are consistent with long-standing WordPress security advice: keep plugins and themes updated, enable two-factor authentication, run regular scans, and use a web application firewall to reduce exposure before patches are available. Wordfence argues that protection, detection, and active monitoring need to work together because no single control can stop every attack.
It also says more than 29,000 known vulnerabilities are now cataloged in its database, and that its vulnerability intelligence expands by dozens to hundreds of entries each week. For vendors, the company pointed to its Vulnerability Management Portal, where 133 vendors registered in Q2 to manage 412 distinct plugins and themes.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: September 30, 2026 at 10:33 pm
0 views
