Wordfence Intelligence Weekly Report Details 260 WordPress Plugin Vulnerabilities
Wordfence Intelligence's latest weekly report, covering September 7-13, 2026, identifies 260 vulnerabilities across 207 WordPress plugins, with a majority rated medium severity.

Wordfence Intelligence has released its weekly vulnerability report, detailing 260 security flaws discovered in 207 distinct WordPress plugins during the period of September 7 to September 13, 2026. This comprehensive analysis highlights the ongoing challenges in securing the vast WordPress ecosystem, which powers a significant portion of the internet.
The majority of the reported vulnerabilities were classified as medium severity, accounting for 184 instances. However, the report also flagged 66 high-severity vulnerabilities and 10 critical ones, underscoring the potential for significant impact on affected websites. These critical and high-severity flaws demand immediate attention from site administrators and developers to prevent exploitation.
Analysis of the Common Weakness Enumeration (CWE) types reveals that Cross-Site Scripting (XSS) remains a prevalent issue, with 66 instances identified. This is closely followed by Missing Authorization flaws, numbering 58, and Sensitive Information Exposure, with 21 occurrences. Other notable vulnerability types include SQL Injection, Improper Privilege Management, and Path Traversal, indicating a diverse range of attack vectors that threat actors could leverage.
Of the total vulnerabilities reported, 217 have been patched by plugin developers, demonstrating a proactive response from the community. However, 42 vulnerabilities remain unpatched, posing an immediate risk to users who have not updated their plugins. One vulnerability was noted as partially patched, suggesting that even updated versions may not fully address the security risk.
Wordfence emphasizes its commitment to making vulnerability data accessible to the public. The Wordfence Intelligence vulnerability database, API, and webhook integrations are freely available for both personal and commercial use. This initiative aims to empower individuals, hosting providers, and enterprises with the information needed to implement robust, layered security strategies for their WordPress sites.
The report also acknowledges the contributions of 147 vulnerability researchers who actively participated in securing the WordPress platform during the reported week. Prominent researchers and teams, including Wordfence PRISM, Artus KG, and Ananda Dhakal, were highlighted for their significant contributions to identifying and disclosing these vulnerabilities.
Site owners are urged to review the reported vulnerabilities and ensure their installed plugins are up-to-date. Proactive patching and diligent monitoring of plugin security are crucial steps in maintaining a secure online presence and protecting against potential cyber threats. Wordfence continues to provide resources and tools to aid the WordPress community in its defense-in-depth security efforts.