Wordfence Intelligence Weekly Report Details 358 WordPress Vulnerabilities
Wordfence Intelligence's latest weekly report, covering September 14-20, 2026, identifies 358 vulnerabilities in 243 WordPress plugins and 4 themes, with a stored XSS in WordPress Core also addressed.

Wordfence Intelligence has released its weekly vulnerability report, detailing a significant number of security flaws discovered in WordPress plugins and themes during the week of September 14-20, 2026. The report highlights a total of 358 vulnerabilities affecting 243 WordPress plugins and 4 themes, which have been added to the Wordfence Intelligence Vulnerability Database. This extensive catalog of vulnerabilities underscores the continuous need for vigilance within the WordPress ecosystem.
In addition to the plugin and theme vulnerabilities, the report also notes that 184 vulnerability researchers contributed to WordPress security during the same period. Wordfence emphasizes its commitment to making this vulnerability information freely accessible through its user interface, API, and webhook integrations, aiming to empower individuals and organizations with the data needed to implement robust security measures and defense-in-depth strategies.
The Wordfence Threat Intelligence Team actively reviews each reported vulnerability to assess its impact, severity, and likelihood of exploitation. Based on these assessments, the team deploys enhanced protection via firewall rules. Last week, specific attention was given to a stored Cross-Site Scripting (XSS) vulnerability in WordPress Core, specifically affecting versions up to and including 7.1, related to its wpautop() blockquote handling. This vulnerability was assigned the identifier WAF-RULE-957.
Protection for this WordPress Core vulnerability was immediately deployed to Wordfence Premium, Care, and Response customers. Users of the free Wordfence version will receive the same enhanced protection, but with a 30-day delay, a common practice to allow users to upgrade to premium services or to provide ample time for patching before widespread exploitation.
Breaking down the reported vulnerabilities by severity, the report indicates that 18 were rated Critical, 74 were High severity, and 262 were Medium severity, with only 4 classified as Low. This distribution highlights a substantial number of high-impact vulnerabilities that could pose significant risks to WordPress websites if left unaddressed.
Common vulnerability types identified include Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) with 94 instances, Missing Authorization with 68 instances, and Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) with 35 instances. Other notable categories include Authorization Bypass, Exposure of Sensitive Information, and Improper Privilege Management, reflecting a diverse range of attack vectors.
The report also lists the top researchers who contributed to WordPress security during the week, with Wordfence PRISM leading the list with 25 reported vulnerabilities, followed by Karthik Ramakrishnan with 17, and Ananda Dhakal with 13. This collaborative effort among researchers is crucial for identifying and mitigating security risks.
Overall, the weekly report from Wordfence Intelligence serves as a critical resource for WordPress site owners, developers, and security professionals, providing timely information on emerging threats and vulnerabilities to help maintain the security and integrity of the WordPress platform.