Wordfence Intelligence Weekly WordPress Vulnerability Report (January 19, 2026 to January 25, 2026)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 215 vulnerabilities disclosed in 180 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 65 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

      • WAF-RULE-891 – Data redacted while we work with the vendor on a patch.

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 98
Unpatched 117

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 2
Medium Severity 156
High Severity 48
Critical Severity 9

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Missing Authorization 75
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 60
Cross-Site Request Forgery (CSRF) 16
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 11
Exposure of Sensitive Information to an Unauthorized Actor 10
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 10
Improper Privilege Management 6
Incorrect Privilege Assignment 5
Improper Control of Generation of Code (‘Code Injection’) 4
Server-Side Request Forgery (SSRF) 4
Unrestricted Upload of File with Dangerous Type 4
Deserialization of Untrusted Data 3
Authorization Bypass Through User-Controlled Key 2
Improper Access Control 1
Improper Authentication 1
Improper Authorization 1
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 1
Incorrect Authorization 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
25
24
22
10
9
7
6
6
6
5
5
5
5
5
4
4
3
3
3

Mdr
3
3
3
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
ABG Rich Pins abg-rich-pins
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution academy
Accordion – Add Horizontal / Vertical Accordion in WP b-accordion
AdForest Elementor adforest-elementor
Admin login URL Change admin-login-url-change
Administrative Shortcodes administrative-shortcodes
AdminQuickbar adminquickbar
Advanced Custom Fields: Extended acf-extended
Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp
AIKTP aiktp
Alchemist Ajax Upload alchemist-ajax-upload
Alex User Counter user-counter
All-in-One Video Gallery all-in-one-video-gallery
Alpha Blocks alpha-blocks
amr cron manager amr-cron-manager
Anything Order by Terms anything-order-by-terms
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps appexperts
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments
ArtPlacer Widget artplacer-widget
Automatic Featured Images from Videos automatic-featured-images-from-videos
Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version
Blockons – Gutenberg blocks for WordPress and WooCommerce websites blockons
Booking (Reservation & Appointment) directorist-booking
Booking Activities booking-activities
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings bookingor
Booter – Bots & Crawlers Manager booter-bots-crawlers-manager
BOX NOW Delivery box-now-delivery
Broadstreet broadstreet
BuddyPress buddypress
Canto Testimonials canto-testimonials
Cloudinary – Deliver Images and Videos at Scale cloudinary-image-management-and-manipulation-in-the-cloud-cdn
CM CSS Columns cm-css-columns
Contact Form 7 GetResponse Extension contact-form-7-getresponse-extension
Cookie consent for developers cookie-consent-for-developers
Coven – Furniture Store WooCommerce Theme coven-core
Creator LMS – The LMS for Creators, Coaches, and Trainers creatorlms
CubeWP Framework cubewp-framework
Custom Fonts – Host Your Fonts Locally custom-fonts
Dinatur dinatur
Directorist Social Login directorist-social-login
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy dokan-lite
Download After Email – Subscribe & Download Form Plugin download-after-email
Easy Property Listings easy-property-listings
Easy Theme Options easy-theme-options
Ecwid by Lightspeed Ecommerce Shopping Cart ecwid-shopping-cart
Edwiser Bridge – WordPress Moodle Integration edwiser-bridge
ElementCamp element-camp
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) wp-event-solution
ExpressTechSoftwares Addon for MemberPress and Discord expresstechsoftwares-memberpress-discord-add-on
File Manager for Google Drive – Integrate Google Drive integrate-google-drive
Final User final-user
Fitness Trainer- Training Membership Plugin fitness-trainer
FlatPM – Ad Manager, AdSense and Custom Code flatpm-wp
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration fluent-boards
Fraud Prevention For WooCommerce and EDD woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
Friendly Functions for Welcart friendly-functions-for-welcart
Frontis Blocks — Block Library for the Block Editor frontis-blocks
GDPR CCPA Compliance & Cookie Consent Banner ninja-gdpr-compliance
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory
GZSEO gzseo
Happy Addons for Elementor happy-elementor-addons
HD Quiz hd-quiz
Head Meta Data head-meta-data
Homey Core homey-core
Hospital Doctor Directory hospital-doctor-directory
Hotel Listings hotel-listing
Hustle – Email Marketing, Lead Generation, Optins, Popups wordpress-popup
Hydra Booking — Appointment Scheduling & Booking Calendar hydra-booking
Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite
iNET Webkit inet-webkit
Institutions Directory institutions-directory
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-hubspot
iRobots.txt SEO irobotstxt-seo
JavaScript Notifier javascript-notifier
JobBank – WordPress Job manager plugin jobbank
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin jobwp
JustClick registration plugin justclick-subscriber
Kalrav AI Agent kalrav-ai-agent
Kentha Elementor Widgets kentha-elementor
KiviCare – Clinic & Patient Management System (EHR) kivicare-clinic-management-system
Koko Analytics – Privacy+Friendly statistics for WordPress koko-analytics
LA-Studio Element Kit for Elementor lastudio-element-kit
Lawyer Directory lawyer-directory
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart lazytasks-project-task-management
LeadBI Plugin for WordPress leadbi
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress
LifePress lifepress
ListingHub listinghub
Listivo Core listivo-core
Login Page Editor login-page-editor
MailerLite – WooCommerce integration woo-mailerlite
Materialis Companion materialis-companion
Media Library File Size media-library-file-size
Melapress Role Editor melapress-role-editor
Meta-box GalleryMeta meta-box-gallerymeta
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor metform
Moderate Selected Posts moderate-selected-posts
Monetag Official Plugin monetag-official
Movie Booking movie-booking
My auctions allegro my-auctions-allegro-free-edition
My Post Order my-posts-order
MyHome Core myhome-core
Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization nelio-ab-testing
Nelio Content – Editorial Calendar & Social Media Auto-Posting nelio-content
Newsletter – Send awesome emails from WordPress newsletter
Nexter Extension – Site Enhancements Toolkit nexter-extension
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar notificationx
Omnipress omnipress
Order Notification for WooCommerce – Get Audio Alert on new Orders woc-order-alert
Paid Downloads paid-downloads
PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) peachpay-for-woocommerce
Photo Gallery by 10Web – Mobile-Friendly Image Gallery photo-gallery
Pie Register – User Registration, Profiles & Content Restriction pie-register
Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification points-and-rewards-for-woocommerce
Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX ultimate-post
Postalicious postalicious
Protección de datos – RGPD proteccion-datos-rgpd
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player radio-player
ravpage ravpage
Real Estate Pro – WordPress Plugin real-estate-pro
RealHomes CRM realhomes-crm
Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder
Responsive Header Plugin responsive-header
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging wp-rss-aggregator
Ryviu – Product Reviews for WooCommerce ryviu
Salon Booking System – Free Version salon-booking-system
Same Category Posts same-category-posts
Save as PDF Plugin by PDFCrowd save-as-pdf-by-pdfcrowd
Scalenut scalenut
Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp
Send Notifications from Woocommerce, Form Plugins and More! notifier
SEO Booster seo-booster
Set Bulk Post Categories set-bulk-post-categories
ShoutOut shoutout
Simple Crypto Shortcodes simple-crypto-shortcodes
SiteLock Security – WP Hardening, Login Security & Malware Scans sitelock
Star Review Manager star-review-manager
SumUp Payment Gateway For WooCommerce sumup-payment-gateway-for-woocommerce
SurveyJS: Drag & Drop Form Builder surveyjs
Tabby Checkout tabby-checkout
Table of Contents Creator table-of-contents-creator
TableOn – WordPress Posts Table Filterable  posts-table-filterable
TaxCloud for WooCommerce simple-sales-tax
Textmetrics webtexttool
The Events Calendar the-events-calendar
ThemeRuby Multi Authors – Assign Multiple Writers to Posts themeruby-multi-authors
Timeline Event History timeline-event-history
Tutor LMS BunnyNet Integration tutor-lms-bunnynet-integration
Tutor LMS – eLearning and online course solution tutor
Ultra Portfolio ultra-portfolio
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator
UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin user-registration
User Submitted Posts – Enable Users to Submit Posts from the Front End user-submitted-posts
UX Flat ux-flat
Viet contact viet-contact
VK Google Job Posting Manager vk-google-job-posting-manager
Web Push Notifications – Webpushr webpushr-web-push-notifications
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot wedocs
weMail – Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation wemail
Wise Analytics wise-analytics
Wishlist Member wishlist-member-x
Wizit Gateway for WooCommerce wizit-gateway-for-woocommerce
Workscout Core workscout-core
WP BackItUp Community Edition wp-backitup
WP Directory Kit wpdirectorykit
WP DSGVO Tools (GDPR) shapepress-dsgvo
WP Go Maps (formerly WP Google Maps) wp-google-maps
WP Hello Bar wp-hello-bar
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website wp-job-portal
WP Membership wp-membership
WP Term Order wp-term-order
WP Travel – Ultimate Travel Booking System, Tour Management Engine wp-travel
WP Youtube Video Gallery wp-youtube-video-gallery
WP-ClanWars wp-clanwars
wpCAS wpcas
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) wpo365-login
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons
ZT Captcha zt-captcha

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
AdForest adforest
CarSpot – Dealership WordPress Classified Theme carspot
Craft | Coffee Shop Cafe Restaurant WordPress craftcoffee
DotLife | Coaching Online Courses WordPress dotlife
EcoBlue ecoblue
enfold enfold
Grand Magazine | Blog WordPress grandmagazine
Grand Spa | Massage Salon WordPress grandspa
Grand Tour | Travel Agency WordPress grandtour
Hostiko – Hosting WordPress & WHMCS Theme hostiko
Hoteller Booking WordPress hoteller
Listihub – Directory Listing WordPress Theme listihub
PeakShops – Modern & Multi-Concept WooCommerce Theme peakshops
Prowess – Fitness and Gym WordPress Theme prowess
Travel Booking WordPress Theme traveler
Werkstatt – Creative Portfolio WordPress Theme werkstatt
WorkScout – Job Board WordPress Theme workscout

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-14533
Patch Status
Patched
Published
Jan 19, 2026
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-67953
Patch Status
Patched
Published
Jan 20, 2026
Affected Software
Booking Activities
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2026-22337
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
Directorist Social Login
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-68027
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-13374
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Kalrav AI Agent
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-68869
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2025-67963
Patch Status
Patched
Published
Jan 21, 2026
Affected Software
Movie Booking
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-69319
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-69293
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Final User
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-69183
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Hospital Doctor Directory
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-69182
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Institutions Directory
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-67966
Patch Status
Patched
Published
Jan 21, 2026
Affected Software
Lawyer Directory
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-69292
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
WP Membership
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-67968
Patch Status
Patched
Published
Jan 21, 2026
Affected Software
RealHomes CRM
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-69312
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67946
Patch Status
Patched
Published
Jan 20, 2026
Affected Software
AdForest
CVSS Rating
High (8.1)
CVE-ID
CVE-2026-22338
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
EcoBlue
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67957
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67955
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-69322
Patch Status
Patched
Published
Jan 23, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-69314
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-1257
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Administrative Shortcodes
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-69295
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-22336
Patch Status
Unpatched
Published
Jan 20, 2026
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68047
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-0911
Patch Status
Patched
Published
Jan 23, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-24390
Patch Status
Patched
Published
Jan 24, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-22850
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-67945
Patch Status
Patched
Published
Jan 20, 2026
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-24538
Patch Status
Unpatched
Published
Jan 24, 2026
Affected Software
Omnipress
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68857
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
Paid Downloads
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-69294
Patch Status
Patched
Published
Jan 23, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-24531
Patch Status
Unpatched
Published
Jan 25, 2026
CVSS Rating
High (7.3)
CVE-ID
CVE-2024-11976
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
BuddyPress
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67947
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-68848
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
amr cron manager
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-68866
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
Dinatur
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67952
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67964
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
Homey Core
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67949
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-69318
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67943
Patch Status
Patched
Published
Jan 19, 2026
Affected Software
My auctions allegro
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67944
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2019-25297
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
High (7.2)
CVE-ID
Unknown
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2026-24548
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67959
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67960
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-14947
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
All-in-One Video Gallery
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-68881
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-68030
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-68999
Patch Status
Patched
Published
Jan 23, 2026
Affected Software
Happy Addons for Elementor
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2026-24572
Patch Status
Unpatched
Published
Jan 21, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2026-24367
Patch Status
Patched
Published
Jan 22, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-69180
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
Ultra Portfolio
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-24558
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
ABG Rich Pins
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-1099
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Administrative Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14985
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Alpha Blocks
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-24555
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
ArtPlacer Widget
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-24550
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-1095
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Canto Testimonials
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-1098
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
CM CSS Columns
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-68900
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
enfold
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14941
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
GZSEO
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-0608
Patch Status
Patched
Published
Jan 20, 2026
Affected Software
Head Meta Data
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-1189
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
LeadBI Plugin for WordPress
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14069
Patch Status
Patched
Published
Jan 22, 2026
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-24584
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
Tutor LMS BunnyNet Integration
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-24576
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
UX Flat
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12836
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-0914
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
WP DSGVO Tools (GDPR)
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-67961
Patch Status
Patched
Published
Jan 21, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69317
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68538
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68520
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68839
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
Easy Theme Options
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69320
Patch Status
Patched
Published
Jan 22, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69321
Patch Status
Patched
Published
Jan 22, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68518
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68840
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
iRobots.txt SEO
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13676
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68838
Patch Status
Unpatched
Published
Jan 20, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68004
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
My Post Order
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68835
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
ravpage
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2026-0862
Patch Status
Patched
Published
Jan 24, 2026
Affected Software
Save as PDF Plugin by PDFCrowd
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68894
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
ShoutOut
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68836
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
Table of Contents Creator
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69316
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2026-1127
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Timeline Event History
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68858
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
wpCAS
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2026-1103
Patch Status
Patched
Published
Jan 23, 2026
Affected Software
AIKTP
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-14797
Patch Status
Patched
Published
Jan 23, 2026
Affected Software
Same Category Posts
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2026-24564
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
Textmetrics
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-15043
Patch Status
Patched
Published
Jan 20, 2026
Affected Software
The Events Calendar
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14629
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Alchemist Ajax Upload
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68039
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
WP BackItUp Community Edition
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24557
Patch Status
Unpatched
Published
Jan 22, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14351
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24541
Patch Status
Unpatched
Published
Jan 24, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68072
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Easy Property Listings
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24556
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
ElementCamp
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69187
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Final User
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69188
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69186
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Hospital Doctor Directory
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69185
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Hotel Listings
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69184
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Institutions Directory
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69189
Patch Status
Unpatched
Published
Jan 22, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69181
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
Lawyer Directory
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69190
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69191
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
ListingHub
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69193
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
WP Membership
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68018
Patch Status
Unpatched
Published
Jan 19, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24577
Patch Status
Unpatched
Published
Jan 20, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69313
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24539
Patch Status
Patched
Published
Jan 24, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69192
Patch Status
Unpatched
Published
Jan 22, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24562
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68882
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
Scalenut
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68019
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
SEO Booster
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69315
Patch Status
Patched
Published
Jan 20, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24583
Patch Status
Unpatched
Published
Jan 19, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68035
Patch Status
Patched
Published
Jan 21, 2026
Affected Software
Tabby Checkout
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67958
Patch Status
Patched
Published
Jan 21, 2026
Affected Software
TaxCloud for WooCommerce
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24568
Patch Status
Unpatched
Published
Jan 21, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67969
Patch Status
Patched
Published
Jan 23, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68020
Patch Status
Unpatched
Published
Jan 20, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-24536
Patch Status
Unpatched
Published
Jan 25, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14609
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Wise Analytics
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14843
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13920
Patch Status
Patched
Published
Jan 23, 2026
Affected Software
WP Directory Kit
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2026-0806
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
WP-ClanWars
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1084
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Cookie consent for developers
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1191
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
JavaScript Notifier
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1302
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Meta-box GalleryMeta
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1266
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Postalicious
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1300
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Responsive Header Plugin
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1045
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
Viet contact
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-1042
Patch Status
Unpatched
Published
Jan 19, 2026
Affected Software
WP Hello Bar
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24578
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
Admin login URL Change
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14630
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
AdminQuickbar
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24579
Patch Status
Unpatched
Published
Jan 20, 2026
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-1070
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Alex User Counter
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-15516
Patch Status
Patched
Published
Jan 23, 2026
Affected Software
All-in-One Video Gallery
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24567
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
Anything Order by Terms
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24535
Patch Status
Patched
Published
Jan 25, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24565
Patch Status
Unpatched
Published
Jan 21, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12573
Patch Status
Unpatched
Published
Jan 20, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24534
Patch Status
Unpatched
Published
Jan 25, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24571
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
BOX NOW Delivery
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69311
Patch Status
Patched
Published
Jan 19, 2026
Affected Software
Broadstreet
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24560
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68046
Patch Status
Unpatched
Published
Jan 20, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-6461
Patch Status
Patched
Published
Jan 24, 2026
Affected Software
CubeWP Framework
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24580
Patch Status
Unpatched
Published
Jan 19, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24570
Patch Status
Unpatched
Published
Jan 21, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24561
Patch Status
Patched
Published
Jan 22, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24553
Patch Status
Unpatched
Published
Jan 22, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-1208
Patch Status
Patched
Published
Jan 23, 2026
Affected Software
Friendly Functions for Welcart
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68073
Patch Status
Patched
Published
Jan 19, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24544
Patch Status
Unpatched
Published
Jan 24, 2026
Affected Software
HD Quiz
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68057
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Hospital Doctor Directory
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68059
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Hotel Listings
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24566
Patch Status
Unpatched
Published
Jan 21, 2026
Affected Software
iNET Webkit
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68058
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
Institutions Directory
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24540
Patch Status
Unpatched
Published
Jan 24, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67967
Patch Status
Patched
Published
Jan 22, 2026
Affected Software
Lawyer Directory
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24563
Patch Status
Unpatched
Published
Jan 22, 2026
Affected Software
LifePress
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-1088
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Login Page Editor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24543
Patch Status
Unpatched
Published
Jan 24, 2026
Affected Software
Materialis Companion
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24569
Patch Status
Patched
Published
Jan 21, 2026
Affected Software
Media Library File Size
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-0687
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Meta-box GalleryMeta
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14907
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Moderate Selected Posts
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24551
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Monetag Official Plugin
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-1081
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14903
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Simple Crypto Shortcodes
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24532
Patch Status
Unpatched
Published
Jan 25, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-1076
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
Star Review Manager
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13139
Patch Status
Unpatched
Published
Jan 23, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24542
Patch Status
Unpatched
Published
Jan 24, 2026
Affected Software
WP Term Order
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13921
Patch Status
Patched
Published
Jan 22, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-24575
Patch Status
Unpatched
Published
Jan 20, 2026
Affected Software
Wishlist Member
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14906
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
WP Youtube Video Gallery
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-1075
Patch Status
Unpatched
Published
Jan 23, 2026
Affected Software
ZT Captcha
CVSS Rating
Low (3.1)
CVE-ID
CVE-2025-67954
Patch Status
Patched
Published
Jan 21, 2026
Researcher

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (January 19, 2026 to January 25, 2026) appeared first on Wordfence.

Leave a Comment