VYPR
advisoryPublished Sep 3, 2026· 1 source

Wordfence Reports 246 WordPress Vulnerabilities in Latest Weekly Roundup

Wordfence Intelligence's latest weekly report details 246 vulnerabilities across 174 WordPress plugins and 5 themes disclosed between August 24-30, 2026, with several critical flaws.

Wordfence Intelligence has cataloged a significant number of security weaknesses, reporting 246 vulnerabilities across 174 WordPress plugins and 5 themes during the week of August 24-30, 2026. This influx of disclosed flaws underscores the ongoing security challenges within the vast WordPress ecosystem, where even popular extensions can harbor critical security holes.

Among the notable vulnerabilities detailed are privilege escalation flaws affecting InfusedWoo Pro, WPeMatico RSS Feed Fetcher, and WPMU DEV Dashboard. These issues, if exploited, could allow authenticated users with minimal privileges to gain administrative access to a WordPress site, potentially leading to complete system compromise. Additionally, WPLP Cookie Consent was found to have authentication bypass and arbitrary file upload vulnerabilities, enabling unauthenticated attackers to upload malicious files or bypass security controls.

The Wordfence Threat Intelligence Team has been actively developing and deploying firewall rules to protect against these emerging threats. Premium, Care, and Response customers of Wordfence received immediate protection through enhanced firewall rules for several of these vulnerabilities. Free version users will receive similar protection after a 30-day delay, a common practice to allow vendors time to patch before widespread exploitation becomes easier.

Specific vulnerabilities addressed by firewall rules include an authenticated privilege escalation in InfusedWoo Pro (<= 5.1.18) via password reset link disclosure, and another in WPeMatico RSS Feed Fetcher (<= 2.8.24) through arbitrary option updates. WPMU DEV Dashboard (<= 5.0.1) suffered from an authentication bypass due to SSO HMAC canonicalization confusion, while WPLP Cookie Consent (<= 4.4.1) had an unauthenticated arbitrary file upload vulnerability via its REST API.

Out of the 246 total vulnerabilities, 234 have been patched by vendors, leaving 12 unpatched at the time of the report. The severity distribution shows a concerning number of high and critical rated vulnerabilities, with 73 rated high and 18 rated critical, alongside 153 medium severity flaws. This indicates a substantial risk to sites running outdated or unpatched plugins.

Common vulnerability types identified include Cross-Site Scripting (XSS) with 57 instances, Missing Authorization with 46, and SQL Injection with 22. Other prevalent issues involve authorization bypass, exposure of sensitive information, path traversal, and improper privilege management, highlighting a broad spectrum of attack vectors available to threat actors.

Wordfence continues to emphasize its commitment to securing the WordPress ecosystem through its free intelligence database, API, and scanner tools. The organization encourages site owners and developers to regularly review disclosed vulnerabilities and apply necessary patches to maintain a robust security posture. The weekly reports aim to provide timely and actionable information to the community, fostering a proactive approach to WordPress security.

The report also acknowledges the contributions of 121 vulnerability researchers who identified and reported these flaws, underscoring the collaborative effort required to maintain the security of the WordPress platform and its vast plugin and theme ecosystem.

Synthesized by Vypr AI