Wordfence Intelligence Reports 319 WordPress Vulnerabilities in One Week
Wordfence Intelligence has detailed 319 vulnerabilities across 222 WordPress plugins reported between September 21-27, 2026, with immediate firewall protection deployed for premium users against several critical flaws.

Wordfence Intelligence has released its weekly vulnerability report, cataloging a significant surge of 319 vulnerabilities discovered in 222 distinct WordPress plugins during the week of September 21st to September 27th, 2026. This comprehensive report underscores the ongoing security challenges within the vast WordPress ecosystem, highlighting the critical need for continuous vigilance and timely patching.
The report details common vulnerability types, with Cross-Site Scripting (XSS) being the most prevalent, accounting for 96 instances. Missing Authorization vulnerabilities followed closely with 59 reported cases, alongside other significant threats such as Authorization Bypass, SQL Injection, and Exposure of Sensitive Information. These common weaknesses, if left unaddressed, can pave the way for attackers to deface websites, steal user data, or gain unauthorized access.
Wordfence's Threat Intelligence Team has been actively working to protect its users by deploying enhanced firewall rules for several high-impact vulnerabilities. Notably, immediate protection was provided to Wordfence Premium, Care, and Response customers for an Unauthenticated Local File Inclusion vulnerability found in WordPress Core versions up to 7.1.1, specifically via the locate_template() function. Free version users will receive this protection after a 30-day delay, emphasizing the benefits of premium subscriptions for rapid security.
Out of the total vulnerabilities reported, 305 have already been patched by plugin developers, indicating a proactive response from the community. However, 14 vulnerabilities remain unpatched, posing an ongoing risk to sites that do not update their plugins promptly. The severity distribution shows 14 Critical, 79 High, and 226 Medium severity vulnerabilities, with the majority of critical flaws being addressed.
The report also acknowledges the contributions of 156 vulnerability researchers who contributed to WordPress security during the same period. Prominent researchers like Ananda Dhakal, Karthik Ramakrishnan, and Intrudify are highlighted for their significant findings, underscoring the collaborative effort in securing the WordPress platform.
Wordfence emphasizes its commitment to making vulnerability information accessible through its free Intelligence database, API, and webhook integrations. This initiative aims to empower site owners, hosting providers, and enterprises with the data needed to implement robust, layered security strategies, aligning with their mission of 'defense in depth' for WordPress.
Site owners are strongly encouraged to review the full list of vulnerabilities and ensure their WordPress plugins are up-to-date. The continuous discovery of new vulnerabilities, even in widely used platforms like WordPress, necessitates a proactive security posture, including regular scanning, timely updates, and the use of a reputable security plugin like Wordfence.
The sheer volume of vulnerabilities reported weekly highlights the dynamic and often challenging nature of web application security. As attackers constantly probe for weaknesses, the WordPress community's ongoing efforts in vulnerability disclosure and patching, supported by security firms like Wordfence, remain crucial for maintaining the integrity and safety of millions of websites worldwide.