Security Blog

WordPress Security Blog

Weekly vulnerability reports, security tips, and WordPress security news to keep your site safe.

74 articlesPage 5 of 8
Filtered by tag:vulnerabilities
Vulnerability ReportJuly 23, 2026

WordPress Vulnerability Report: July 16 – July 23, 2026

92 WordPress vulnerabilities disclosed between July 16 – July 23, 2026. 5 critical, 25 high severity. 1 patched, 91 unpatched.

By WPSentry
Vulnerability ReportJuly 22, 2026

WordPress Vulnerability Report: July 15 – July 22, 2026

111 WordPress vulnerabilities disclosed between July 15 – July 22, 2026. 7 critical, 27 high severity. 1 patched, 110 unpatched.

By WPSentry
Vulnerability ReportJuly 21, 2026

WordPress Vulnerability Report: July 14 – July 21, 2026

107 WordPress vulnerabilities disclosed between July 14 – July 21, 2026. 8 critical, 23 high severity. 1 patched, 106 unpatched.

By WPSentry
Vulnerability ReportJuly 20, 2026

WordPress Vulnerability Report: July 13 – July 20, 2026

110 WordPress vulnerabilities disclosed between July 13 – July 20, 2026. 7 critical, 23 high severity. 1 patched, 109 unpatched.

By WPSentry
Vulnerability ReportJuly 19, 2026

WordPress Vulnerability Report: July 12 – July 19, 2026

103 WordPress vulnerabilities disclosed between July 12 – July 19, 2026. 8 critical, 26 high severity. 1 patched, 102 unpatched.

By WPSentry
Vulnerability ReportJuly 18, 2026

WordPress Vulnerability Report: July 11 – July 18, 2026

103 WordPress vulnerabilities disclosed between July 11 – July 18, 2026. 8 critical, 27 high severity. 1 patched, 102 unpatched.

By WPSentry
Vulnerability ReportJuly 17, 2026

WordPress Vulnerability Report: July 10 – July 17, 2026

178 WordPress vulnerabilities disclosed between July 10 – July 17, 2026. 8 critical, 42 high severity. 1 patched, 177 unpatched.

By WPSentry
Security TipsJuly 16, 2026

Zero-Day Plugin Exploits on WordPress: Attacks Before a Patch Exists

A zero-day plugin exploit attacks a flaw before the developer has a fix. Learn what makes them dangerous and how to reduce your exposure to the unknown.

By WPSentry Team
Security TipsJuly 16, 2026

Server-Side Request Forgery (SSRF) on WordPress: Turning Your Server Into a Weapon

SSRF tricks your WordPress server into making requests on an attacker's behalf, reaching internal systems and cloud metadata. Learn how it works and how to block it.

By WPSentry Team
Security TipsJuly 16, 2026

Privilege Escalation on WordPress: How a Low-Level Account Becomes an Admin

Privilege escalation lets an attacker turn a subscriber account or a plugin bug into full admin control. Learn how it happens and how to prevent it.

By WPSentry Team
PreviousPage 5 of 8Next