Briefing

Wordfence Weekly Vulnerability Report: 146 Vulnerabilities in 127 Plugins and 1 Theme

security
by Chloe Chamberland · WordPress Wordfence CVE-2025-68045 CVE-2026-10023 CVE-2026-10029 CVE-2026-10034 CVE-2026-10093 CVE-2026-10623 CVE-2026-10736 CVE-2026-10779 CVE-2026-10780 CVE-2026-11357 CVE-2026-11358 CVE-2026-11360 CVE-2026-11395

Patch the 7 unpatched vulnerabilities, including the 7 critical ones, as soon as possible and run the Wordfence CLI scanner to verify all sites are secure.

What to do now

Patch the 7 unpatched vulnerabilities, especially the 7 critical ones, and run the Wordfence CLI scanner to confirm all sites are secure.

Summary

Wordfence released its latest weekly vulnerability report, revealing 146 new vulnerabilities across 127 WordPress plugins and a single theme. The report lists 85 researchers who contributed, with daroo leading at 14 findings, followed by Nguyen Ba Khanh (8), Chloe Chamberland (7), PRISM (7), dodoh4t (6), and endy (4). Of the disclosed issues, 139 have been patched while 7 remain unpatched, including 7 critical, 48 high, 90 medium, and 1 low severity cases. The most common CWE categories are Missing Authorization (36), SQL Injection (31), Cross‑Site Scripting (26), Exposure of Sensitive Information (10), Authorization Bypass (7), Path Traversal (7), Incorrect Privilege Assignment (5), and several others totaling 18 distinct types. Wordfence’s free tools—UI, API, webhook, and CLI scanner—enable site owners to ingest the full database of over 35,000 vulnerabilities and run regular scans. The report urges enterprises, hosting providers, and individuals to use the CLI scanner or API to stay ahead of new threats in real time. Wordfence’s mission to provide defense‑in‑depth security remains central, with the database updated weekly and notifications available via email. The article also highlights the importance of timely patching and continuous monitoring for all WordPress sites.

Key changes

  • 146 new vulnerabilities disclosed across 127 plugins and 1 theme
  • 85 researchers contributed, with daroo (14), Nguyen Ba Khanh (8), Chloe Chamberland (7), PRISM (7), dodoh4t (6), endy (4) leading
  • 139 vulnerabilities patched, 7 remain unpatched (7 critical, 48 high, 90 medium, 1 low)
  • Severity distribution: Low 1, Medium 90, High 48, Critical 7
  • CWE distribution: Missing Authorization 36, SQL Injection 31, XSS 26, Exposure of Sensitive Information 10, Authorization Bypass 7, Path Traversal 7, Incorrect Privilege Assignment 5, CSRF 3, Deserialization 3, PHP Remote File Inclusion 3, Code Injection 3, SSRF 3, Unrestricted Upload 3, Improper Privilege Management 2, Embedded Malicious Code 1, External Control of File Name or Path 1, Incorrect Authorization 1, Weak Password Recovery 1
  • Wordfence offers free UI, API, webhook, and CLI scanner for vulnerability ingestion and scanning
  • Database contains over 35,000 vulnerabilities, updated weekly
  • Wordfence encourages regular scans and real‑time webhook notifications for new vulnerabilities

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting