During the reporting period (April 1 – April 8, 2026), 40 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 45 plugins & components
WordPress Plugin Vulnerabilities (40)
Order Notification for WooCommerce
critical
Ninja Forms - File Uploads
critical
Spam Protect for Contact Form 7
high
MW WP Form
high
Webmention
high
W3 Total Cache
high
Perfmatters
high
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
high
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
high
Widgets for Social Photo Feed
high
Text to Speech for WP (AI Voices by Mementor)
high
Visitor Traffic Real Time Statistics
high
wpForo Forum
high
Booking for Appointments and Events Calendar – Amelia
high
Booking for Appointments and Events Calendar - Amelia
medium
Database for Contact Form 7, WPforms, Elementor forms
medium
Export All URLs
medium
King Addons for Elementor
medium
Webmention
medium
Pie Register – User Registration, Profiles & Content Restriction
medium
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem
medium
Xpro Addons — 140+ Widgets for Elementor
medium
Xpro Addons — 140+ Widgets for Elementor
medium
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
medium
Simple Shopping Cart
medium
Royal Addons for Elementor
medium
WP Shortcodes Plugin - Shortcodes Ultimate
medium
WP Shortcodes Plugin - Shortcodes Ultimate
medium
ElementsKit Elementor Addons and Templates
medium
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
medium
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
medium
Listeo Core
medium
WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales
medium
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
medium
Popup Box
medium
Link Whisper Free
medium
SQL Chart Builder
medium
Charitable – Donation
medium
Backup Migration
medium
Smart Slider 3
medium
WordPress Theme Vulnerabilities (0)
No vulnerabilities reported in this category this week.
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.