Wordfence Reports 249 WordPress Vulnerabilities in One Week
Wordfence Intelligence disclosed 249 vulnerabilities across 197 WordPress plugins and 2 themes between August 3-9, 2026, including critical flaws in WordPress Core and a malware-induced authentication bypass.

Wordfence Intelligence has published its weekly vulnerability report, detailing a significant surge in security flaws affecting the WordPress ecosystem. During the week of August 3rd to August 9th, 2026, a total of 249 vulnerabilities were identified and cataloged within 197 distinct WordPress plugins and 2 themes. This influx highlights the ongoing challenges in maintaining the security of the widely used content management system.
Among the most critical disclosures were an unauthenticated reflected cross-site scripting (XSS) vulnerability in WordPress Core itself, affecting versions up to and including 7.0.2. This flaw, present in the emer-run.php file, could allow attackers to inject malicious scripts into web pages viewed by other users without requiring any authentication. Additionally, a separate vulnerability was identified that enables an authentication bypass through the presence of malware, posing a severe risk to sites.
The Wordfence Threat Intelligence Team has been actively reviewing these vulnerabilities to assess their severity and the likelihood of exploitation. For the most pressing issues, including the WordPress Core XSS and the malware-induced authentication bypass, enhanced protection via firewall rules has already been deployed. Premium, Care, and Response customers of Wordfence received immediate protection, while users of the free version will gain access to these protective measures after a 30-day delay, a standard practice to allow vendors time to patch.
Analysis of the disclosed vulnerabilities reveals a diverse range of threats. Out of the 249 total, 210 have been patched by vendors, while 39 remain unpatched, demanding immediate attention from site administrators. The severity distribution shows 13 critical, 62 high, and 174 medium severity vulnerabilities. Common vulnerability types include Cross-Site Scripting (79 instances), Missing Authorization (54 instances), and SQL Injection (31 instances), underscoring persistent weaknesses in input validation and access control mechanisms.
Several researchers contributed to the discovery and reporting of these vulnerabilities. Wordfence PRISM led the contributions with 49 identified flaws, followed by Ananda Dhakal with 26. The report lists numerous other researchers who collectively identified the remaining vulnerabilities, showcasing a vibrant community effort in uncovering security weaknesses within the WordPress ecosystem.
Wordfence emphasizes its commitment to making vulnerability information accessible through its free Intelligence database, API, and CLI scanner. This transparency aims to empower site owners, hosting providers, and developers to implement robust security measures and a defense-in-depth strategy. The weekly reports serve as a crucial tool for staying informed about emerging threats and ensuring timely remediation.
The sheer volume of vulnerabilities reported in a single week underscores the dynamic and often challenging nature of WordPress security. Site owners are strongly advised to regularly update their plugins, themes, and core WordPress installations, and to employ a reputable security plugin like Wordfence to provide an additional layer of defense against known and emerging threats.