Wordfence Reports 223 WordPress Vulnerabilities in Late July 2026
Wordfence Intelligence tracked 223 vulnerabilities in WordPress plugins and themes between July 20-26, 2026, including a critical RCE in Admin and Site Enhancements Pro.
Wordfence Intelligence has released its weekly vulnerability report, detailing 223 security flaws discovered in WordPress plugins and themes during the week of July 20-26, 2026. Of these, 155 vulnerabilities have been patched by developers, while 68 remain unpatched, posing a continued risk to websites.
The report highlights a critical Unauthenticated Remote Code Execution (RCE) vulnerability in the Admin and Site Enhancements Pro plugin (versions up to 8.9.0). This flaw, stemming from PHP Code Injection via the cfgroup[input] Repeater Row Key, could allow attackers to execute arbitrary code on vulnerable systems without authentication. Wordfence's firewall rules provided immediate protection to its Premium, Care, and Response customers, with free users receiving protection after a 30-day delay.
Across the reported vulnerabilities, the most common Common Weakness Enumeration (CWE) types include Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) with 70 instances, Missing Authorization with 59 instances, and Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) with 25 instances. Other notable CWEs include Exposure of Sensitive Information, Cross-Site Request Forgery, and Path Traversal.
The vulnerabilities were identified across 175 WordPress plugins and 6 themes. The severity breakdown shows 172 medium-severity flaws, 42 high-severity flaws, and 9 critical-severity flaws, underscoring the significant risk landscape for WordPress users. The report also acknowledges the contributions of 88 security researchers who identified these vulnerabilities.
Wordfence emphasizes its commitment to making vulnerability information accessible through its free vulnerability database, API, and CLI scanner. This weekly report aims to equip site owners, hosting providers, and enterprises with the data needed to implement robust security measures and defense-in-depth strategies.
Users are strongly encouraged to review the reported vulnerabilities and ensure their WordPress sites are updated to the latest patched versions. For those running the free version of Wordfence, staying informed about delayed protections is crucial. The report also serves as a call to action for researchers to responsibly disclose their findings to Wordfence for potential bounties and recognition.
The sheer volume of reported vulnerabilities, particularly the critical RCE in Admin and Site Enhancements Pro, serves as a stark reminder of the ongoing need for vigilance in the WordPress ecosystem. Proactive patching and robust security tooling remain essential for mitigating the risks posed by these discovered flaws.