During the reporting period (August 23 – August 30, 2026), 170 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 175 plugins & components
WordPress Plugin Vulnerabilities (165)
Total Donations
critical
Total Donations
critical
TranslatePress – Translate Multilingual sites with AI Translation
critical
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce
critical
Workeera
critical
Tutor LMS
critical
WPMU DEV Dashboard
critical
Uix UserCenter
critical
Total processing card payments for WooCommerce
critical
爱采集数据采集和发布插件
critical
Sigma Forms Pro
critical
Custom User Registration Fields for WooCommerce
critical
MyHome Core
critical
InfusedWoo Pro
high
CM Map Locations – Visualize and share your locations in a few clicks
high
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
high
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
high
Verdure Core
high
NotificationX Pro
high
Kalles Addons
high
Readabler
high
All-in-One WP Migration and Backup
high
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
high
WP Fastest Cache
high
BlogVault Backup & Staging
high
WP Fastest Cache – WordPress Cache Plugin
high
Pods
high
Project Manager
high
AI Engine
high
Order Tip for WooCommerce
high
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More
high
WooCommerce Lottery
high
Mang Board WP
high
Classified Listing - Mobile Number Verification
high
Formidable Charts
high
CMP
high
Smush
high
WP OAuth Server ( Login with WordPress )
high
Workeera
high
Workeera
high
StoreGrowth
high
12 Step Meeting List
high
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
high
LiteSpeed Cache
high
One User Avatar | User Profile Picture
high
TranslatePress – Translate Multilingual sites with AI Translation
high
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
high
User Frontend
high
shared-files-pro
high
Ultimate Member
high
wpForo Forum
high
Booking for Appointments and Events Calendar – Amelia
high
User Registration & Membership
high
WP Rocket
high
Customer Reviews for WooCommerce
high
Rest Routes
high
SmartAIPress
high
User Profile Builder
high
Appointment Booking Calendar Plugin and Scheduling Plugin
high
HEL Online Classroom: AI-powered Online Classrooms
high
SAML Single Sign On – SSO Login
high
Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals
medium
WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses
medium
Events Manager – Calendar, Bookings, Tickets, and more!
medium
BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP
medium
PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin
medium
Events Manager – Calendar, Bookings, Tickets, and more!
medium
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
medium
LearnPress
medium
Events Manager – Calendar, Bookings, Tickets, and more!
medium
Events Manager – Calendar, Bookings, Tickets, and more!
medium
Gutenverse – WordPress Blocks, Page Builder & Site Editor
medium
FundEngine – Donation and Crowdfunding Platform
medium
FundEngine – Donation and Crowdfunding Platform
medium
tagDiv Composer
medium
Fluent Boards Pro
medium
Fluent Support Pro
medium
WP Project Manager Pro
medium
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
medium
TranslatePress – Translate Multilingual sites with AI Translation
medium
eCommerce Product Catalog
medium
My Agile Privacy® – CMP, Cookie Consent & Privacy Tools
medium
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
medium
Newsletters
medium
Media Sweep – WordPress Media Cleaner
medium
FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
medium
Eventin
medium
Royal Addons for Elementor
medium
Royal Addons for Elementor
medium
Booking for Appointments and Events Calendar
medium
Booking for Appointments and Events Calendar
medium
WPCafe
medium
Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates
medium
Booking Package
medium
Tutor LMS
medium
Royal Addons for Elementor
medium
Project Manager
medium
Project Manager
medium
AI Engine
medium
Eventin
medium
Return Refund and Exchange For WooCommerce
medium
Kirki
medium
Directorist: AI-Powered Business Directory, Listings & Classified Ads
medium
Stripe Payment Forms by WP Full Pay
medium
Stripe Payment Forms by WP Full Pay
medium
RegistrationMagic
medium
Simple Newsletter Plugin
medium
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem
medium
Reviews and Rating – Google Reviews
medium
WP Data Access
medium
Greenshift – animation and page builder blocks
medium
CMP
medium
Document Embedder
medium
Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce
medium
Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce
medium
Defender Security
medium
JetBackup
medium
UpdraftPlus: WP Backup & Migration Plugin
medium
LearnPress
medium
Finale Lite
medium
Notifima
medium
Smart Slider 3
medium
Avada (Fusion) Builder
medium
Tutor LMS – eLearning and online course solution
medium
LiteSpeed Cache
medium
Shared Files
medium
Shared Files
medium
User Frontend
medium
ElementsKit Pro
medium
WCFM Marketplace
medium
Breeze Cache
medium
User Registration & Membership
medium
GiveWP – Donation Plugin and Fundraising Platform
medium
All-in-One WP Migration Unlimited Extension
medium
Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce
medium
Envira Gallery
medium
Everest Forms
medium
MemberHero
medium
Newsletters
medium
Newsletters
medium
MStore API
medium
MStore API
medium
Catfolders Document Gallery Pro
medium
User Profile Builder
medium
User Profile Builder
medium
HEL Online Classroom: AI-powered Online Classrooms
medium
HEL Online Classroom: AI-powered Online Classrooms
medium
Rank Math SEO
medium
Stripe Payment Forms by WP Full Pay
medium
WP Ultimate CSV Importer
medium
MasterStudy LMS
medium
MasterStudy LMS
medium
Frontend Admin by DynamiApps
medium
geotargetingwp
medium
SOGO Add Script to Individual Pages Header Footer
medium
WPvivid — Backup, Migration & Staging
medium
Customer Reviews for WooCommerce
medium
MW WP Form
medium
Groundhogg — CRM, Newsletters, and Marketing Automation
medium
Really Simple Security
medium
Forminator Forms
low
CMP
low
Quiz and Survey Master (QSM)
low
Booking for Appointments and Events Calendar
low
MasterStudy LMS
low
WordPress Theme Vulnerabilities (5)
Jawn
critical
Avada
critical
Mane
high
Shuffle
high
Betheme
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: August 25 – September 1, 2026
171 WordPress vulnerabilities disclosed between August 25 – September 1, 2026. 15 critical, 57 high severity. 0 patched, 171 unpatched.
WordPress Vulnerability Report: August 24 – August 31, 2026
171 WordPress vulnerabilities disclosed between August 24 – August 31, 2026. 15 critical, 50 high severity. 0 patched, 171 unpatched.
WordPress Vulnerability Report: August 22 – August 29, 2026
174 WordPress vulnerabilities disclosed between August 22 – August 29, 2026. 12 critical, 47 high severity. 0 patched, 174 unpatched.