WooCommerce is the foundation of our entire ecosystem
Our product and engineering teams are focusing on our core WooCommerce plugin for the next few months. Here’s why…
Our product and engineering teams are focusing on our core WooCommerce plugin for the next few months. Here’s why…
In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by the Wordfence Threat Intelligence team, with validated vulnerabilities responsibly disclosed to vendors, often through the Wordfence Vulnerability … Read more
Learn how to catch security issues with tips from a WooCommerce Solutions Engineer.
Last week, there were 223 vulnerabilities disclosed in 175 WordPress Plugins and 6 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 88 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with … Read more
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal administrator capabilities, such as uploading a plugin. The chain consists of two vulnerabilities: an unauthenticated SQL injection vulnerability identified … Read more