VYPR
advisoryPublished Jul 23, 2026· 1 source

Wordfence Reports 139 WordPress Vulnerabilities in Mid-July 2026

Wordfence Intelligence tracked 139 vulnerabilities in WordPress Core and plugins between July 13-19, 2026, including critical flaws like an unauthenticated file upload and an RCE in WordPress Core.

Wordfence Intelligence has released its weekly report, detailing a significant number of vulnerabilities discovered in the WordPress ecosystem between July 13 and July 19, 2026. During this period, 73 vulnerabilities were disclosed in WordPress Core, and an additional 66 vulnerabilities were found in various WordPress plugins. No vulnerabilities were reported for WordPress themes during this specific week.

The report highlights two particularly concerning disclosures: an unauthenticated arbitrary file upload vulnerability in Super Forms (versions up to 6.3.313) and an unauthenticated remote code execution (RCE) vulnerability in WordPress Core (versions prior to 7.0.2). These types of vulnerabilities pose a significant risk to website security, potentially allowing attackers to upload malicious files or execute arbitrary code on a compromised server.

The Wordfence Threat Intelligence Team has been actively reviewing these disclosures to assess their impact and severity. Consequently, enhanced protection via firewall rules has been deployed in real-time for Wordfence Premium, Care, and Response customers. This includes specific rules for the Super Forms vulnerability and the WordPress Core RCE, as well as for three other undisclosed vulnerabilities for which patches are pending.

While premium customers received immediate protection, users of the free Wordfence plugin will receive similar enhanced protection after a 30-day delay. This tiered rollout strategy is standard practice to allow vendors time to develop and distribute patches before making exploit details widely available.

Overall, the week saw 69 vulnerabilities patched and 4 vulnerabilities remaining unpatched. The disclosed vulnerabilities spanned various severity levels, with 46 classified as Medium, 21 as High, and 6 as Critical. Common vulnerability types included Cross-Site Scripting (XSS), SQL Injection, and Missing Authorization, underscoring the persistent challenges in securing web applications.

Wordfence continues to emphasize the importance of proactive security measures, offering free access to its vulnerability database, API, and CLI scanner. This initiative aims to empower individuals and organizations to implement robust security strategies and stay ahead of emerging threats within the vast WordPress ecosystem.

The report also acknowledges the contributions of 48 security researchers who contributed to WordPress security during that week, highlighting the collaborative effort required to maintain the platform's integrity. The detailed breakdown of vulnerabilities by CWE type and researcher contributions provides valuable insights into the evolving threat landscape and the ongoing efforts to secure WordPress sites globally.

Synthesized by Vypr AI