Briefing

Wordfence Weekly Vulnerability Report – 99 New Vulnerabilities Disclosed

security
by Chloe Chamberland · WordPress Wordfence CVE-2025-15369 CVE-2026-1543 CVE-2026-1881 CVE-2026-24573 CVE-2026-24637 CVE-2026-2518 CVE-2026-27349 CVE-2026-27393 CVE-2026-27405 CVE-2026-27424 CVE-2026-2955 CVE-2026-3481 CVE-2026-3985

Check the Wordfence Intelligence database for the 99 new vulnerabilities and update any affected plugins or themes immediately.

What to do now

Patch any affected plugins or themes, run Wordfence CLI scans, and monitor the webhook for new vulnerabilities.

Summary

Wordfence released its weekly vulnerability report, detailing 99 newly disclosed vulnerabilities across 87 WordPress plugins and 1 theme. The report highlights contributions from 68 security researchers and shows that 63 vulnerabilities have already been patched while 36 remain unpatched. Severity distribution is 65 medium, 24 high, and 10 critical. A new firewall rule, WAF‑R‑915, was deployed for Premium, Care, and Response customers to block exploitation in real time. Wordfence offers free access to its vulnerability API, webhook notifications, and a CLI scanner for continuous monitoring.

The report underscores the importance of staying up‑to‑date with plugin patches and leveraging Wordfence’s real‑time protection to mitigate emerging threats.

Key changes

  • 99 new vulnerabilities disclosed across 87 plugins and 1 theme
  • 68 security researchers contributed to the report
  • 63 vulnerabilities patched, 36 remain unpatched
  • Severity distribution: 65 medium, 24 high, 10 critical
  • New firewall rule WAF‑R‑915 deployed for Premium/Care/Response customers
  • Wordfence provides free vulnerability API, webhook, CLI scanner for real‑time monitoring

Affects

wp-customers

Source angles · 2 perspectives

Wordfence Blog
Security angle

Wordfence Intelligence Weekly WordPress Vulnerability Report (May 18, 2026 to May 24, 2026)

Open
Wordfence Blog
Security angle

15,000 WordPress Sites Affected by Administrator Account Creation Vulnerability in WP Maps Pro WordPress Plugin

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting