Wordfence Weekly Vulnerability Report: 87 New Vulnerabilities in WordPress Plugins and Themes
Check the Wordfence Intelligence vulnerability feed for the 87 newly disclosed vulnerabilities and update any affected plugins or themes.
Patch any affected plugins or themes by updating to the latest versions, and enable the new firewall rules WAF‑RULE‑909 and WAF‑RULE‑910 on your Wordfence Premium or Care installation.
Summary
Wordfence Intelligence released its latest weekly vulnerability report, detailing 87 newly disclosed vulnerabilities across 198 WordPress plugins and 5 themes. The report highlights contributions from 61 researchers, underscoring the active security research community. Wordfence offers a free vulnerability data feed, webhook integration, and CLI scanner to help site owners stay protected.
The report also notes that 84 of the disclosed vulnerabilities have been patched, leaving only 3 unpatched issues. Severity counts show 50 medium, 34 high, and 3 critical vulnerabilities, with the most common CWE types being XSS (30), missing authorization (19), and SQL injection (10). Wordfence rolled out new firewall rules (WAF‑RULE‑909 and WAF‑RULE‑910) for Premium, Care, and Response customers to mitigate these risks in real time.
Key changes
- 87 new vulnerabilities disclosed in 198 plugins and 5 themes
- 61 researchers contributed to WordPress security last week
- Wordfence offers free API, webhook, and CLI scanner for vulnerability data
- 84 vulnerabilities patched, 3 remain unpatched
- Severity distribution: 50 medium, 34 high, 3 critical
- New firewall rules WAF‑RULE‑909 and WAF‑RULE‑910 deployed for Premium customers