Wordfence Weekly Vulnerability Report – 75 New Vulnerabilities Added to 35k Database
Run the Wordfence CLI or pull the vulnerability API to scan all sites for the 75 new vulnerabilities and update affected plugins.
Execute a Wordfence CLI scan on all managed sites, compare results to the 75 new vulnerabilities, and update any affected plugins immediately.
Summary
Wordfence released its weekly vulnerability report on March 27th, 2026, detailing 75 newly disclosed vulnerabilities across 59 WordPress plugins and 2 themes, and highlighting the contributions of 56 researchers. The report notes that 61 of the vulnerabilities have already been patched while 14 remain unpatched, with severity distribution of 51 medium, 21 high, and 3 critical. The Wordfence Vulnerability Database now contains over 35,000 entries, providing a comprehensive resource for site owners. New firewall rules were deployed for Gravity SMTP <=2.1.4 and Burst Statistics 3.4.0–3.4.1.1, offering immediate protection for Premium, Care, and Response customers, with free users receiving the same rules after a 30‑day delay. Wordfence continues to offer free access to its CLI scanner, vulnerability API, and webhook integration, enabling automated monitoring and real‑time alerts. The report encourages site owners to use these tools to stay ahead of emerging threats and maintain layered security. Wordfence’s commitment to open, free security intelligence is underscored by the weekly updates and the extensive researcher community behind the database.
Key changes
- 75 new vulnerabilities added across 59 plugins and 2 themes
- 61 patched, 14 unpatched; 51 medium, 21 high, 3 critical severity
- Wordfence database now exceeds 35,000 vulnerabilities
- 56 researchers contributed to the weekly disclosures
- New firewall rules for Gravity SMTP <=2.1.4 and Burst Statistics 3.4.0–3.4.1.1
- Free Wordfence users receive firewall rules after a 30‑day delay
- CLI, API, and webhook integrations are free for all users