Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Last week, there were 215 vulnerabilities disclosed in 180 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 65 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
-
-
- WAF-RULE-891 – Data redacted while we work with the vendor on a patch.
-
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
| Patch Status | Number of Vulnerabilities |
|---|---|
| Patched | 98 |
| Unpatched | 117 |
Total Vulnerabilities by CVSS Severity Last Week
| Severity Rating | Number of Vulnerabilities |
|---|---|
| Low Severity | 2 |
| Medium Severity | 156 |
| High Severity | 48 |
| Critical Severity | 9 |
Total Vulnerabilities by CWE Type Last Week
| Vulnerability Type by CWE | Number of Vulnerabilities |
|---|---|
| Missing Authorization | 75 |
| Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 60 |
| Cross-Site Request Forgery (CSRF) | 16 |
| Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 11 |
| Exposure of Sensitive Information to an Unauthorized Actor | 10 |
| Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 10 |
| Improper Privilege Management | 6 |
| Incorrect Privilege Assignment | 5 |
| Improper Control of Generation of Code (‘Code Injection’) | 4 |
| Server-Side Request Forgery (SSRF) | 4 |
| Unrestricted Upload of File with Dangerous Type | 4 |
| Deserialization of Untrusted Data | 3 |
| Authorization Bypass Through User-Controlled Key | 2 |
| Improper Access Control | 1 |
| Improper Authentication | 1 |
| Improper Authorization | 1 |
| Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 1 |
| Incorrect Authorization | 1 |
Researchers That Contributed to WordPress Security Last Week
| Researcher Name | Number of Vulnerabilities |
|---|---|
| 25 | |
| 24 | |
| 22 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| ABG Rich Pins | abg-rich-pins |
| Academy LMS – WordPress LMS Plugin for Complete eLearning Solution | academy |
| Accordion – Add Horizontal / Vertical Accordion in WP | b-accordion |
| AdForest Elementor | adforest-elementor |
| Admin login URL Change | admin-login-url-change |
| Administrative Shortcodes | administrative-shortcodes |
| AdminQuickbar | adminquickbar |
| Advanced Custom Fields: Extended | acf-extended |
| Ai Image Alt Text Generator for WP | ai-image-alt-text-generator-for-wp |
| AIKTP | aiktp |
| Alchemist Ajax Upload | alchemist-ajax-upload |
| Alex User Counter | user-counter |
| All-in-One Video Gallery | all-in-one-video-gallery |
| Alpha Blocks | alpha-blocks |
| amr cron manager | amr-cron-manager |
| Anything Order by Terms | anything-order-by-terms |
| APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps | appexperts |
| Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | simply-schedule-appointments |
| ArtPlacer Widget | artplacer-widget |
| Automatic Featured Images from Videos | automatic-featured-images-from-videos |
| Beaver Builder Page Builder – Drag and Drop Website Builder | beaver-builder-lite-version |
| Blockons – Gutenberg blocks for WordPress and WooCommerce websites | blockons |
| Booking (Reservation & Appointment) | directorist-booking |
| Booking Activities | booking-activities |
| Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings | bookingor |
| Booter – Bots & Crawlers Manager | booter-bots-crawlers-manager |
| BOX NOW Delivery | box-now-delivery |
| Broadstreet | broadstreet |
| BuddyPress | buddypress |
| Canto Testimonials | canto-testimonials |
| Cloudinary – Deliver Images and Videos at Scale | cloudinary-image-management-and-manipulation-in-the-cloud-cdn |
| CM CSS Columns | cm-css-columns |
| Contact Form 7 GetResponse Extension | contact-form-7-getresponse-extension |
| Cookie consent for developers | cookie-consent-for-developers |
| Coven – Furniture Store WooCommerce Theme | coven-core |
| Creator LMS – The LMS for Creators, Coaches, and Trainers | creatorlms |
| CubeWP Framework | cubewp-framework |
| Custom Fonts – Host Your Fonts Locally | custom-fonts |
| Dinatur | dinatur |
| Directorist Social Login | directorist-social-login |
| Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy | dokan-lite |
| Download After Email – Subscribe & Download Form Plugin | download-after-email |
| Easy Property Listings | easy-property-listings |
| Easy Theme Options | easy-theme-options |
| Ecwid by Lightspeed Ecommerce Shopping Cart | ecwid-shopping-cart |
| Edwiser Bridge – WordPress Moodle Integration | edwiser-bridge |
| ElementCamp | element-camp |
| Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) | wp-event-solution |
| ExpressTechSoftwares Addon for MemberPress and Discord | expresstechsoftwares-memberpress-discord-add-on |
| File Manager for Google Drive – Integrate Google Drive | integrate-google-drive |
| Final User | final-user |
| Fitness Trainer- Training Membership Plugin | fitness-trainer |
| FlatPM – Ad Manager, AdSense and Custom Code | flatpm-wp |
| FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration | fluent-boards |
| Fraud Prevention For WooCommerce and EDD | woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers |
| Friendly Functions for Welcart | friendly-functions-for-welcart |
| Frontis Blocks — Block Library for the Block Editor | frontis-blocks |
| GDPR CCPA Compliance & Cookie Consent Banner | ninja-gdpr-compliance |
| GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | geodirectory |
| GZSEO | gzseo |
| Happy Addons for Elementor | happy-elementor-addons |
| HD Quiz | hd-quiz |
| Head Meta Data | head-meta-data |
| Homey Core | homey-core |
| Hospital Doctor Directory | hospital-doctor-directory |
| Hotel Listings | hotel-listing |
| Hustle – Email Marketing, Lead Generation, Optins, Popups | wordpress-popup |
| Hydra Booking — Appointment Scheduling & Booking Calendar | hydra-booking |
| Image Photo Gallery Final Tiles Grid | final-tiles-grid-gallery-lite |
| iNET Webkit | inet-webkit |
| Institutions Directory | institutions-directory |
| Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms | cf7-hubspot |
| iRobots.txt SEO | irobotstxt-seo |
| JavaScript Notifier | javascript-notifier |
| JobBank – WordPress Job manager plugin | jobbank |
| JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin | jobwp |
| JustClick registration plugin | justclick-subscriber |
| Kalrav AI Agent | kalrav-ai-agent |
| Kentha Elementor Widgets | kentha-elementor |
| KiviCare – Clinic & Patient Management System (EHR) | kivicare-clinic-management-system |
| Koko Analytics – Privacy+Friendly statistics for WordPress | koko-analytics |
| LA-Studio Element Kit for Elementor | lastudio-element-kit |
| Lawyer Directory | lawyer-directory |
| LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart | lazytasks-project-task-management |
| LeadBI Plugin for WordPress | leadbi |
| LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | learnpress |
| LifePress | lifepress |
| ListingHub | listinghub |
| Listivo Core | listivo-core |
| Login Page Editor | login-page-editor |
| MailerLite – WooCommerce integration | woo-mailerlite |
| Materialis Companion | materialis-companion |
| Media Library File Size | media-library-file-size |
| Melapress Role Editor | melapress-role-editor |
| Meta-box GalleryMeta | meta-box-gallerymeta |
| MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | metform |
| Moderate Selected Posts | moderate-selected-posts |
| Monetag Official Plugin | monetag-official |
| Movie Booking | movie-booking |
| My auctions allegro | my-auctions-allegro-free-edition |
| My Post Order | my-posts-order |
| MyHome Core | myhome-core |
| Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization | nelio-ab-testing |
| Nelio Content – Editorial Calendar & Social Media Auto-Posting | nelio-content |
| Newsletter – Send awesome emails from WordPress | newsletter |
| Nexter Extension – Site Enhancements Toolkit | nexter-extension |
| NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar | notificationx |
| Omnipress | omnipress |
| Order Notification for WooCommerce – Get Audio Alert on new Orders | woc-order-alert |
| Paid Downloads | paid-downloads |
| PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) | peachpay-for-woocommerce |
| Photo Gallery by 10Web – Mobile-Friendly Image Gallery | photo-gallery |
| Pie Register – User Registration, Profiles & Content Restriction | pie-register |
| Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification | points-and-rewards-for-woocommerce |
| Poll, Survey & Quiz Maker Plugin by Opinion Stage | social-polls-by-opinionstage |
| Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | ultimate-post |
| Postalicious | postalicious |
| Protección de datos – RGPD | proteccion-datos-rgpd |
| Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | radio-player |
| ravpage | ravpage |
| Real Estate Pro – WordPress Plugin | real-estate-pro |
| RealHomes CRM | realhomes-crm |
| Responsive Contact Form Builder & Lead Generation Plugin | lead-form-builder |
| Responsive Header Plugin | responsive-header |
| RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging | wp-rss-aggregator |
| Ryviu – Product Reviews for WooCommerce | ryviu |
| Salon Booking System – Free Version | salon-booking-system |
| Same Category Posts | same-category-posts |
| Save as PDF Plugin by PDFCrowd | save-as-pdf-by-pdfcrowd |
| Scalenut | scalenut |
| Schema & Structured Data for WP & AMP | schema-and-structured-data-for-wp |
| Send Notifications from Woocommerce, Form Plugins and More! | notifier |
| SEO Booster | seo-booster |
| Set Bulk Post Categories | set-bulk-post-categories |
| ShoutOut | shoutout |
| Simple Crypto Shortcodes | simple-crypto-shortcodes |
| SiteLock Security – WP Hardening, Login Security & Malware Scans | sitelock |
| Star Review Manager | star-review-manager |
| SumUp Payment Gateway For WooCommerce | sumup-payment-gateway-for-woocommerce |
| SurveyJS: Drag & Drop Form Builder | surveyjs |
| Tabby Checkout | tabby-checkout |
| Table of Contents Creator | table-of-contents-creator |
| TableOn – WordPress Posts Table Filterable | posts-table-filterable |
| TaxCloud for WooCommerce | simple-sales-tax |
| Textmetrics | webtexttool |
| The Events Calendar | the-events-calendar |
| ThemeRuby Multi Authors – Assign Multiple Writers to Posts | themeruby-multi-authors |
| Timeline Event History | timeline-event-history |
| Tutor LMS BunnyNet Integration | tutor-lms-bunnynet-integration |
| Tutor LMS – eLearning and online course solution | tutor |
| Ultra Portfolio | ultra-portfolio |
| Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | uncanny-automator |
| UPI QR Code Payment Gateway for WooCommerce | upi-qr-code-payment-for-woocommerce |
| User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin | user-registration |
| User Submitted Posts – Enable Users to Submit Posts from the Front End | user-submitted-posts |
| UX Flat | ux-flat |
| Viet contact | viet-contact |
| VK Google Job Posting Manager | vk-google-job-posting-manager |
| Web Push Notifications – Webpushr | webpushr-web-push-notifications |
| weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot | wedocs |
| weMail – Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation | wemail |
| Wise Analytics | wise-analytics |
| Wishlist Member | wishlist-member-x |
| Wizit Gateway for WooCommerce | wizit-gateway-for-woocommerce |
| Workscout Core | workscout-core |
| WP BackItUp Community Edition | wp-backitup |
| WP Directory Kit | wpdirectorykit |
| WP DSGVO Tools (GDPR) | shapepress-dsgvo |
| WP Go Maps (formerly WP Google Maps) | wp-google-maps |
| WP Hello Bar | wp-hello-bar |
| WP Job Portal – AI-Powered Recruitment System for Company or Job Board website | wp-job-portal |
| WP Membership | wp-membership |
| WP Term Order | wp-term-order |
| WP Travel – Ultimate Travel Booking System, Tour Management Engine | wp-travel |
| WP Youtube Video Gallery | wp-youtube-video-gallery |
| WP-ClanWars | wp-clanwars |
| wpCAS | wpcas |
| WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) | wpo365-login |
| Xpro Addons — 140+ Widgets for Elementor | xpro-elementor-addons |
| ZT Captcha | zt-captcha |
WordPress Themes with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| AdForest | adforest |
| CarSpot – Dealership WordPress Classified Theme | carspot |
| Craft | Coffee Shop Cafe Restaurant WordPress | craftcoffee |
| DotLife | Coaching Online Courses WordPress | dotlife |
| EcoBlue | ecoblue |
| enfold | enfold |
| Grand Magazine | Blog WordPress | grandmagazine |
| Grand Spa | Massage Salon WordPress | grandspa |
| Grand Tour | Travel Agency WordPress | grandtour |
| Hostiko – Hosting WordPress & WHMCS Theme | hostiko |
| Hoteller Booking WordPress | hoteller |
| Listihub – Directory Listing WordPress Theme | listihub |
| PeakShops – Modern & Multi-Concept WooCommerce Theme | peakshops |
| Prowess – Fitness and Gym WordPress Theme | prowess |
| Travel Booking WordPress Theme | traveler |
| Werkstatt – Creative Portfolio WordPress Theme | werkstatt |
| WorkScout – Job Board WordPress Theme | workscout |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (January 19, 2026 to January 25, 2026) appeared first on Wordfence.