Wordfence Weekly Vulnerability Report: 146 Vulnerabilities in 127 Plugins and 1 Theme
Patch the 7 unpatched vulnerabilities, including the 7 critical ones, as soon as possible and run the Wordfence CLI scanner to verify all sites are secure.
Patch the 7 unpatched vulnerabilities, especially the 7 critical ones, and run the Wordfence CLI scanner to confirm all sites are secure.
Summary
Wordfence released its latest weekly vulnerability report, revealing 146 new vulnerabilities across 127 WordPress plugins and a single theme. The report lists 85 researchers who contributed, with daroo leading at 14 findings, followed by Nguyen Ba Khanh (8), Chloe Chamberland (7), PRISM (7), dodoh4t (6), and endy (4). Of the disclosed issues, 139 have been patched while 7 remain unpatched, including 7 critical, 48 high, 90 medium, and 1 low severity cases. The most common CWE categories are Missing Authorization (36), SQL Injection (31), Cross‑Site Scripting (26), Exposure of Sensitive Information (10), Authorization Bypass (7), Path Traversal (7), Incorrect Privilege Assignment (5), and several others totaling 18 distinct types. Wordfence’s free tools—UI, API, webhook, and CLI scanner—enable site owners to ingest the full database of over 35,000 vulnerabilities and run regular scans. The report urges enterprises, hosting providers, and individuals to use the CLI scanner or API to stay ahead of new threats in real time. Wordfence’s mission to provide defense‑in‑depth security remains central, with the database updated weekly and notifications available via email. The article also highlights the importance of timely patching and continuous monitoring for all WordPress sites.
Key changes
- 146 new vulnerabilities disclosed across 127 plugins and 1 theme
- 85 researchers contributed, with daroo (14), Nguyen Ba Khanh (8), Chloe Chamberland (7), PRISM (7), dodoh4t (6), endy (4) leading
- 139 vulnerabilities patched, 7 remain unpatched (7 critical, 48 high, 90 medium, 1 low)
- Severity distribution: Low 1, Medium 90, High 48, Critical 7
- CWE distribution: Missing Authorization 36, SQL Injection 31, XSS 26, Exposure of Sensitive Information 10, Authorization Bypass 7, Path Traversal 7, Incorrect Privilege Assignment 5, CSRF 3, Deserialization 3, PHP Remote File Inclusion 3, Code Injection 3, SSRF 3, Unrestricted Upload 3, Improper Privilege Management 2, Embedded Malicious Code 1, External Control of File Name or Path 1, Incorrect Authorization 1, Weak Password Recovery 1
- Wordfence offers free UI, API, webhook, and CLI scanner for vulnerability ingestion and scanning
- Database contains over 35,000 vulnerabilities, updated weekly
- Wordfence encourages regular scans and real‑time webhook notifications for new vulnerabilities