During the reporting period (April 8 – April 15, 2026), 106 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 111 plugins & components
WordPress Plugin Vulnerabilities (106)
Everest Forms
critical
Users manager – PN
critical
DSGVO Google Web Fonts GDPR
critical
ProSolution WP Client
critical
Quick Playground
critical
LearnPress
critical
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
high
ActivityPub
high
Gerador de Certificados – DevApps
high
Broken Link Checker
high
Advanced Members for ACF
high
MW WP Form
high
Vertex Addons for Elementor
high
Tutor LMS – eLearning and online course solution
high
Perfmatters
high
Gravity SMTP
high
BuddyPress Groupblog
high
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
high
wpForo Forum
high
Product Filter for WooCommerce by WBW
high
JetEngine
high
Form Maker by 10Web
high
BackWPup
high
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
high
Hustle – Email Marketing, Lead Generation, Optins, Popups
medium
Gravity Forms
medium
Download Monitor
medium
Gravity Forms
medium
Elementor Website Builder – More Than Just a Page Builder
medium
Blubrry PowerPress
medium
LightPress Lightbox
medium
Strong Testimonials
medium
TableOn – WordPress Posts Table Filterable
medium
Investi
medium
LTL Freight Quotes – R+L Carriers Edition
medium
MainWP Child Reports
medium
LearnPress – WordPress LMS Plugin
medium
Prime Slider – Addons for Elementor
medium
LatePoint – Calendar Booking Plugin for Appointments and Events
medium
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
medium
AM LottiePlayer
medium
Whole Enquiry Cart for WooCommerce
medium
Pinterest Site Verification plugin using Meta Tag
medium
PZ Frontend Manager
medium
WP Blockade
medium
Riaxe Product Customizer
medium
Columns by BestWebSoft
medium
Attendance Manager
medium
Quran Translations
medium
Sports Club Management
medium
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
medium
Inquiry Form to Posts or Pages
medium
Wavr
medium
WowPress
medium
Blog2Social: Social Media Auto Post & Scheduler
medium
Awesome Support – WordPress HelpDesk & Support Plugin
medium
Element Pack Addons for Elementor
medium
Magic Conversation For Gravity Forms
medium
JW Player
medium
PrivateContent Free
medium
pdfl.io
medium
Robo Gallery
medium
WP Visitor Statistics (Real Time Traffic)
medium
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
medium
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
medium
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
medium
Beaver Builder Page Builder – Drag and Drop Website Builder
medium
Page Builder: Pagelayer
medium
Advanced Contact form 7 DB
medium
Advanced Contact form 7 DB
medium
Extensions for Leaflet Map
medium
Post Blocks & Tools
medium
MStore API
medium
Experto Dashboard for WooCommerce
medium
Ziggeo
medium
OSM – OpenStreetMap
medium
Download Manager
medium
Ultimate FAQ Accordion
medium
UsersWP
medium
Online Scheduling and Appointment Booking System – Bookly
medium
List category posts
medium
Webling
medium
Aruba HiSpeed Cache
medium
WP-Optimize
medium
Download Manager
medium
Royal WordPress Backup & Restore Plugin
medium
Customer Reviews for WooCommerce
medium
UsersWP – Front-end login form, User Registration, User Profile & Members Directory
medium
AddFunc Head & Footer Code
medium
YML for Yandex Market
medium
YITH WooCommerce Wishlist
medium
Tutor LMS – eLearning and online course solution
medium
Tutor LMS – eLearning and online course solution
medium
BlockArt Blocks
medium
GreenShift - Animation and Page Builder Blocks
medium
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
medium
LifterLMS
medium
Optimole – Optimize Images in Real Time
medium
Form Maker by 10Web
medium
User Registration & Membership
medium
Surbma | Booking.com Shortcode
medium
ShopLentor
medium
WholeSale Products Dynamic Pricing Management WooCommerce
medium
The Germanized for WooCommerce
medium
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
medium
Nexi XPay
medium
WordPress Theme Vulnerabilities (0)
No vulnerabilities reported in this category this week.
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.