During the reporting period (April 15 – April 16, 2026), 24 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 29 plugins & components
WordPress Plugin Vulnerabilities (22)
Visa Acceptance Solutions
critical
Age Verification & Identity Verification by Token of Trust
high
Accessibly
high
Login as User
high
Quick Interest Slider
high
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
medium
Avada (Fusion) Builder
medium
Avada (Fusion) Builder
medium
List View Google Calendar
medium
Advanced Custom Fields (ACF)
medium
Inquiry Form to Posts or Pages
medium
MetForm Pro
medium
e-shot™ form builder
medium
Katalogportal PDF Sync
medium
WP Circliful
medium
WM JqMath
medium
Petje.af
medium
Coachific Shortcode
medium
Power Charts Lite
medium
OPEN-BRAIN
medium
VI: Include Post By
medium
Product Pricing Table by WooBeWoo
medium
WordPress Theme Vulnerabilities (2)
WebStack
critical
Eleganzo
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.