Briefing

Wordfence Weekly Vulnerability Report – 75 New Vulnerabilities Added to 35k Database

security
by Chloe Chamberland · WordPress Wordfence CVE-2025-13618 CVE-2025-62127 CVE-2025-66105 CVE-2025-68049 CVE-2025-68060 CVE-2025-68524 CVE-2025-68604 CVE-2026-1719 CVE-2026-1921 CVE-2026-2306 CVE-2026-25436 CVE-2026-25468 CVE-2026-2729

Run the Wordfence CLI or pull the vulnerability API to scan all sites for the 75 new vulnerabilities and update affected plugins.

What to do now

Execute a Wordfence CLI scan on all managed sites, compare results to the 75 new vulnerabilities, and update any affected plugins immediately.

Summary

Wordfence released its weekly vulnerability report on March 27th, 2026, detailing 75 newly disclosed vulnerabilities across 59 WordPress plugins and 2 themes, and highlighting the contributions of 56 researchers. The report notes that 61 of the vulnerabilities have already been patched while 14 remain unpatched, with severity distribution of 51 medium, 21 high, and 3 critical. The Wordfence Vulnerability Database now contains over 35,000 entries, providing a comprehensive resource for site owners. New firewall rules were deployed for Gravity SMTP <=2.1.4 and Burst Statistics 3.4.0–3.4.1.1, offering immediate protection for Premium, Care, and Response customers, with free users receiving the same rules after a 30‑day delay. Wordfence continues to offer free access to its CLI scanner, vulnerability API, and webhook integration, enabling automated monitoring and real‑time alerts. The report encourages site owners to use these tools to stay ahead of emerging threats and maintain layered security. Wordfence’s commitment to open, free security intelligence is underscored by the weekly updates and the extensive researcher community behind the database.

Key changes

  • 75 new vulnerabilities added across 59 plugins and 2 themes
  • 61 patched, 14 unpatched; 51 medium, 21 high, 3 critical severity
  • Wordfence database now exceeds 35,000 vulnerabilities
  • 56 researchers contributed to the weekly disclosures
  • New firewall rules for Gravity SMTP <=2.1.4 and Burst Statistics 3.4.0–3.4.1.1
  • Free Wordfence users receive firewall rules after a 30‑day delay
  • CLI, API, and webhook integrations are free for all users

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting