
Wordfence Intelligence’s weekly WordPress vulnerability report for August 10 to August 16, 2026 shows another heavy seven-day stretch for the ecosystem, with 259 vulnerabilities disclosed across 199 plugins and five themes. Of those issues, 204 were already patched and 55 remained unpatched at the time of the report, while 142 vulnerability researchers contributed findings that were added to the Wordfence Intelligence database.
WordPress vulnerability totals keep climbing
The report highlights how broad the attack surface remains across the WordPress plugin and theme ecosystem. Wordfence says its Intelligence database grew with vulnerabilities affecting a wide range of tools used for forms, bookings, membership management, file handling, ecommerce, backups, and marketing.
That volume matters because many of the affected products are popular site infrastructure components. Even when vendors move quickly, the report shows how quickly risk can accumulate for site owners that delay updates or do not actively monitor their installed plugins and themes.
Severity breakdown: more than 100 high and critical issues
Of last week’s disclosures, 157 were rated medium severity, 74 were high severity, and 28 were critical. Wordfence’s data suggests that while medium-severity bugs remain common, the number of high-risk problems is still large enough to warrant close attention from site administrators.
- Medium severity: 157
- High severity: 74
- Critical severity: 28
Common vulnerability types point to familiar WordPress risks
The weekly breakdown by CWE type shows the same kinds of flaws surfacing again and again across third-party plugins. Cross-site scripting was the most common issue class, followed closely by authorization problems and SQL injection.
For WordPress operators, that mix is a reminder that the most serious threats are often not exotic zero-days. They are often implementation mistakes in widely used plugins that expose admin actions, sensitive data, file operations, or authentication flows.
- Cross-site scripting: 59
- Missing authorization: 50
- SQL injection: 38
- Authorization bypass through user-controlled key: 14
- Exposure of sensitive information: 14
- Path traversal: 13
- Deserialization of untrusted data: 9
- Improper privilege management: 9
- Unrestricted file upload: 8
- Server-side request forgery: 7
Other categories included CSRF, authentication bypass, code injection, incorrect authorization, and weak password recovery, though in lower numbers. The pattern is consistent with the broader WordPress security landscape: plugin code often needs broad access to users, files, and external services, which makes small logic errors especially costly.
High-profile plugin flaws drew immediate firewall coverage
Wordfence said its Threat Intelligence team reviewed each vulnerability for impact, severity, and likely exploitability, then deployed new firewall rules in real time for Premium, Care, and Response customers. Free users will receive the same enhanced protection after a 30-day delay.
Among the vulnerabilities protected by new firewall rules last week were:
- Pods <= 3.3.9 — Unauthenticated privilege escalation via authorization bypass to admin methods through the
pods_adminAJAX router - Wishlist Member X <= 3.34.1 — Unauthenticated account takeover via the
mergewithparameter - WAF-RULE-946 — Data redacted while Wordfence works with the vendor on a patch
- WAF-RULE-947 — Data redacted while Wordfence works with the vendor on a patch
- WAF-RULE-950 — Data redacted while Wordfence works with the vendor on a patch
The report also notes that Wordfence plugin users with the scanner enabled should already have been notified if their site was affected. For organizations relying on multiple sites, Wordfence again points to its CLI Vulnerability Scanner, database API, and webhook integration as free tools for monitoring exposures at scale.
Notable critical issues in the weekly report
The vulnerability details section includes a long list of serious flaws, many of them rated 9.8 and tagged as critical. Several stand out because they affect tools used for authentication, booking, file handling, and membership management.
Examples from the report include unauthenticated account takeover in 6Storage Rentals <= 2.27.0, unauthenticated PHP object injection in ARForms <= 1.8.5, unauthenticated privilege escalation in Customer Email Verification for WooCommerce < 3.2.6, authentication bypass in Ezoic <= 2.22.11, and unauthenticated remote code execution in QA Assistants – Driven by data <= 5.2.0.0.
Other high-impact issues included:
- Formidable Digital Signatures <= 3.0.6 — unauthenticated arbitrary file deletion via signature field
- Frontend Admin by DynamiApps <= 3.29.9 — unauthenticated privilege escalation via
item_id - Gift Cards For WooCommerce Pro <= 4.2.9 — unauthenticated arbitrary file upload
- KiviCare – Clinic & Patient Management System (EHR) < 4.5.2 — unauthenticated privilege escalation
- Log in with Google <= 1.4.2 — authentication bypass
- miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 — unauthenticated privilege escalation
- MStore API <= 4.20.0 — unauthenticated privilege escalation
- Pods <= 3.3.9 — unauthenticated privilege escalation
- ProSolution WP Client <= 2.0.10 — unauthenticated arbitrary file upload via
Content-Dispositionheader filename override - TrueBooker <= 1.2.6 — unauthenticated account takeover via insecure direct object reference in
truebooker_wp_user_id - User Profile Builder <= 3.16.4 — unauthenticated authentication bypass leading to administrator account takeover via
username - WP BASE Booking of Appointments, Services and Events <= 6.3.0 — unauthenticated remote code execution
Not all critical issues were patched by the time of publication. Wordfence marked 6Storage Rentals, Piotnet Addons For Elementor Pro, User Session Synchronizer, and RapiSafe as unpatched in the report, alongside several other vulnerabilities that had already received fixes.
Researchers behind the disclosures
Wordfence credited 142 researchers for contributing vulnerabilities to WordPress security last week, with Wordfence PRISM leading the leaderboard at 29 findings. Among the most active named researchers were Asim Alshaya with 10 vulnerabilities, daroo with 9, and Muni Nitish Kumar Yaddala with 6.
Multiple researchers were tied on five findings each, including Jakub Herman, Pedro Pinho, luc, Farid Narimanov, Taylsec, and Tran Nguyen Bao Khanh. Wordfence also used the report to remind researchers that responsible disclosure through its bug bounty program can lead to both bounty eligibility and a place on the Wordfence Intelligence leaderboard.
What site owners should take away
The week’s report is less about any single bug than about the pace and variety of WordPress security findings. Booking systems, login tools, file managers, form builders, and membership plugins all appeared in the disclosure list, underscoring how often attackers can find a path through everyday functionality.
For site owners, the practical takeaway is straightforward: update plugins and themes quickly, remove anything not in active use, and make sure security scanning is enabled. For larger environments, Wordfence’s free API, webhook integration, and CLI scanner are positioned as ways to track new disclosures without waiting for a manual review.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: August 23, 2026 at 1:52 am
0 views
