40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin

On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site administrator, resulting in full administrative takeover of … Read more

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)

Last week, there were 249 vulnerabilities disclosed in 197 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 136 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with … Read more

WordPress 7.0.4 Release

WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support … Read more

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)

Last week, there were 224 vulnerabilities disclosed in 177 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 119 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with … Read more