
Wordfence Intelligence’s weekly WordPress vulnerability report for July 20 through July 26, 2026 shows another heavy stretch for the ecosystem, with 223 vulnerabilities disclosed across 175 plugins and 6 themes. Wordfence says 88 researchers contributed findings during the week, while its firewall team deployed immediate protection for selected flaws that it assessed as requiring rapid coverage.
Wordfence Intelligence weekly WordPress vulnerability report: the big picture
The report underscores how broad the WordPress attack surface remains. Most of last week’s disclosures were already patched, but a meaningful share were still listed as unpatched at publication time, leaving site owners to verify whether affected software is installed and updated.
Wordfence also reiterated that its Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are free for personal and commercial use. The company says that approach is meant to support layered security and defense in depth for WordPress sites of all sizes.
Weekly totals at a glance
- 223 vulnerabilities disclosed
- 175 WordPress plugins affected
- 6 WordPress themes affected
- 88 vulnerability researchers contributed
- 156 vulnerabilities marked patched
- 67 vulnerabilities marked unpatched
Severity skewed toward medium risk, but critical issues stood out
Most of the disclosures were rated medium severity, but the report still included a notable number of high and critical findings. That matters because even a small number of critical weaknesses in widely used plugins can have outsized impact when attackers move quickly to weaponize them.
- 172 medium-severity vulnerabilities
- 42 high-severity vulnerabilities
- 9 critical vulnerabilities
Among the critical issues highlighted in the report were unauthenticated code injection, privilege escalation, arbitrary file upload, and authentication bypass scenarios. Several of those were patched, but a few of the week’s other findings remained unpatched when Wordfence published the summary.
What Wordfence blocked in real time
Wordfence said its Threat Intelligence Team reviewed each issue to determine impact, severity, and likelihood of exploitation before deciding whether firewall coverage was needed. For Premium, Care, and Response customers, the company rolled out enhanced protection immediately for one specific vulnerability last week.
The firewall rule covered Admin and Site Enhancements (ASE) Pro <= 8.9.0, described as an Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key. Free users will receive the same enhanced protection after the standard 30-day delay.
Notable critical vulnerabilities in WordPress plugins
Several critical plugin issues were among the week’s most serious disclosures. These are the kinds of flaws that site owners should prioritize because they can enable complete compromise, file writes, or unauthorized access without much friction for an attacker.
- Customer Support Ticket System & Helpdesk <= 6.0.5 — Unauthenticated Code Injection via
pathParameter, CVSS 9.8, CVE-2026-15011, patched, published Jul 22, 2026. Researcher: theviper17y. - Easy Form Builder by WhiteStudio <= 4.0.11 — Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint, CVSS 9.8, CVE-2026-13439, patched, published Jul 20, 2026. Researcher: CHOIGYEONGMIN.
- GoDAM <= 1.12.2 — Unauthenticated Arbitrary File Upload via WPForms File Upload Field, CVSS 9.8, CVE-2026-14282, patched, published Jul 22, 2026. Researcher: CHOIGYEONGMIN.
- MountDev AI MCP Connector for WordPress <= 1.6.1 — Unauthenticated Privilege Escalation via OAuth Authorization Endpoint, CVSS 9.8, CVE-2026-15015, patched, published Jul 22, 2026. Researcher: AeonRisk.
- SAML Single Sign On <= 5.4.4 — Unauthenticated Authentication Bypass via SAMLResponse Parameter, CVSS 9.8, CVE-2026-15981, patched, published Jul 23, 2026. Researcher: Supakiad S. (m3ez).
- SMS Alert – SMS & OTP for WooCommerce <= 3.9.6 — Unauthenticated Privilege Escalation, CVSS 9.8, CVE-2026-59540, patched, published Jul 22, 2026. Researcher: Taylsec.
- WP BASE Booking of Appointments, Services and Events <= 6.3.1 — Authenticated (Subscriber+) Privilege Escalation, CVSS 9.8, CVE-2026-59541, patched, published Jul 22, 2026. Researcher: Afan.
High-severity issues across forms, commerce, maps, and utilities
Beyond the critical findings, Wordfence logged a broad mix of high-severity flaws affecting payment, booking, forms, ecommerce, and mapping plugins. Some of these were exploitable only by authenticated users, while others were unauthenticated SQL injection or file deletion bugs.
- Broadcast Live Video <= 7.2.4 — Unauthenticated Arbitrary File Deletion, CVSS 9.1, CVE-2026-57716, patched. Researcher: dutafi.
- Participants Database <= 2.7.8.3 — Unauthenticated Arbitrary File Deletion, CVSS 9.1, CVE-2026-59555, patched. Researcher: hhhai.
- Fluent Forms Pro Add On Pack <= 6.2.6 — Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field, CVSS 8.8, CVE-2026-15962, patched. Researcher: daroo.
- WPO365 | LOGIN <= 43.2 — CSRF to Privilege Escalation via Plugin Settings Update, CVSS 8.8, CVE-2026-15212, patched. Researcher: Osvaldo Noe Gonzalez Del Rio (Os).
- Easy Appointments <= 3.12.27 — Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion, CVSS 8.1, CVE-2026-8789, patched. Researcher: Vamshi Krishna Upadrasta.
- WPForms Pro <= 1.10.1.1 — Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering, CVSS 8.1, CVE-2026-10818, patched. Researcher: lhking.
- WPify Woo <= 5.4.16 — Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint, CVSS 8.0, CVE-2026-12736, patched. Researcher: Wordfence PRISM.
Repeated patterns: SQL injection, XSS, and missing authorization
Wordfence’s CWE breakdown suggests familiar bug classes continued to dominate. Cross-site scripting led the list, followed by missing authorization and SQL injection, which together account for a large portion of the week’s work for site operators and plugin maintainers.
- Cross-site scripting: 70
- Missing authorization: 59
- SQL injection: 25
- Exposure of sensitive information: 13
- CSRF: 11
- Path traversal: 8
- SSRF: 7
That breakdown helps explain why so many WordPress advisories continue to center on access control failures and input handling problems. The report also shows why even popular plugins with mature user bases can still ship exploitable bugs.
Researchers driving the disclosures
Wordfence highlighted 88 researchers in the weekly leaderboard, with Ananda Dhakal leading the list at 49 reported vulnerabilities and Wordfence PRISM contributing 28. Several other researchers appeared multiple times, including Trương Hữu Phúc (truonghuuphuc), dutafi, Que Thanh Tuan, Nabil Irawan, Phat RiO, and hhhai.
The company also reminded researchers that responsible disclosure through its bug bounty program can result in both bounty eligibility and recognition in the weekly report. That incentive structure helps explain the steady flow of findings across the WordPress ecosystem.
What site owners should do now
The practical takeaway is straightforward: check whether your site uses any of the listed plugins or themes, then confirm that the installed versions are newer than the affected releases. If a product remains unpatched, reduce exposure by disabling it where possible, limiting access, or applying compensating controls until an update arrives.
Wordfence says users running its plugin with the scanner enabled should already have been notified if their site was affected. Administrators can also use the free CLI Vulnerability Scanner, the vulnerability database API, or webhook integrations to monitor changes in real time.
- Audit installed plugins and themes against the report’s affected versions
- Update immediately where patches are available
- Watch especially for unauthenticated RCE, file upload, file deletion, and auth-bypass issues
- Use scanning and alerting tools to catch newly disclosed vulnerabilities quickly
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: August 10, 2026 at 6:24 pm
0 views
