VYPR
advisoryPublished Aug 21, 2026· 1 source

Wordfence Reports 259 WordPress Vulnerabilities in Weekly Roundup

Wordfence Intelligence's latest weekly report details 259 vulnerabilities across 199 WordPress plugins and 5 themes, including critical flaws in Pods and Wishlist Member X.

Wordfence Intelligence has published its weekly WordPress vulnerability report, detailing a significant number of security flaws discovered and disclosed between August 10th and August 16th, 2026. The report highlights a total of 259 vulnerabilities affecting 199 distinct WordPress plugins and 5 themes, underscoring the ongoing security challenges within the vast WordPress ecosystem.

The vulnerabilities cataloged range in severity, with 28 critical, 74 high, and 157 medium-severity issues identified. Common vulnerability types include Cross-Site Scripting (XSS), Missing Authorization, SQL Injection, Authorization Bypass, and Exposure of Sensitive Information. These flaws, if exploited, could lead to a wide array of malicious activities, from unauthorized data access and modification to complete website takeovers.

Among the specific vulnerabilities called out are an unauthenticated privilege escalation in Pods version 3.3.9 and earlier, and an unauthenticated account takeover vulnerability in Wishlist Member X version 3.34.1. These particular flaws are of high concern due to their potential for immediate and severe impact on affected sites.

In response to these discoveries, the Wordfence Threat Intelligence Team has deployed enhanced protection via firewall rules. Premium, Care, and Response customers received immediate protection against these and other undisclosed vulnerabilities. Free users of Wordfence will receive similar protection, but with a 30-day delay, a standard practice to allow vendors time to patch before widespread exploitation knowledge is fully disseminated.

Beyond the specific plugin vulnerabilities, the report also provides a broader overview of the WordPress security landscape. It notes that 204 of the disclosed vulnerabilities have already been patched, while 55 remain unpatched, posing an ongoing risk to users who have not updated their plugins or themes.

The Wordfence Intelligence platform, including its vulnerability database, API, and CLI scanner, remains freely accessible to the public. This initiative aims to empower individuals, hosting providers, and enterprises with the necessary data to implement robust security measures and defend their WordPress sites effectively.

The report also acknowledges the contributions of 142 vulnerability researchers who actively participated in securing the WordPress ecosystem last week. This collaborative effort is crucial in identifying and mitigating threats before they can be widely exploited.

Site owners are strongly advised to review the full list of vulnerabilities and ensure their WordPress installations, including all plugins and themes, are up-to-date. Prompt patching remains the most effective defense against the ever-evolving threat landscape targeting the world's most popular content management system.

Synthesized by Vypr AI