During the reporting period (August 27 – September 3, 2026), 177 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 182 plugins & components
WordPress Plugin Vulnerabilities (174)
Tutor LMS
critical
WPMU DEV Dashboard
critical
Uix UserCenter
critical
Total processing card payments for WooCommerce
critical
爱采集数据采集和发布插件
critical
Sigma Forms Pro
critical
Custom User Registration Fields for WooCommerce
critical
MyHome Core
critical
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
critical
Booking for Appointments and Events Calendar – Amelia (Premium)
critical
SigmaForms Pro – AI Generated Forms
critical
Developer Tools
critical
Embed HTML5 Game
critical
WatchMan-Site7
critical
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
high
LiteSpeed Cache
high
One User Avatar | User Profile Picture
high
TranslatePress – Translate Multilingual sites with AI Translation
high
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
high
User Frontend
high
shared-files-pro
high
Ultimate Member
high
wpForo Forum
high
Booking for Appointments and Events Calendar – Amelia
high
User Registration & Membership
high
WP Rocket
high
Customer Reviews for WooCommerce
high
Rest Routes
high
SmartAIPress
high
User Profile Builder
high
Appointment Booking Calendar Plugin and Scheduling Plugin
high
HEL Online Classroom: AI-powered Online Classrooms
high
SAML Single Sign On – SSO Login
high
geotargetingwp
high
Customer Reviews for WooCommerce
high
Groundhogg — CRM, Newsletters, and Marketing Automation
high
ProfilePress
high
Affiliate Super Assistent
high
Listdom: AI-powered Business Directory with Classifieds Ads Listings
high
Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System
high
Frontend Admin by DynamiApps
high
Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits
high
Welcart e-Commerce
high
Gravity Forms
high
FS-Poster
high
WP File Download
high
Advanced Custom Fields: Extended
high
Photo Gallery by 10Web
high
DevKit Pro
high
User Frontend
high
JetBackup
high
Social Media Share Buttons & Social Sharing Icons
high
RegistrationMagic
high
Advanced Custom Fields: Extended
high
FAQ Builder AYS
high
Simple Ajax Chat
high
OAuth Single Sign On
high
Broken Link Checker
high
Auto x LINE
high
Smart Slider 3
medium
Avada (Fusion) Builder
medium
Tutor LMS – eLearning and online course solution
medium
LiteSpeed Cache
medium
Shared Files
medium
Shared Files
medium
User Frontend
medium
ElementsKit Pro
medium
WCFM Marketplace
medium
Breeze Cache
medium
User Registration & Membership
medium
GiveWP – Donation Plugin and Fundraising Platform
medium
All-in-One WP Migration Unlimited Extension
medium
Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce
medium
Envira Gallery
medium
Everest Forms
medium
MemberHero
medium
Newsletters
medium
Newsletters
medium
MStore API
medium
MStore API
medium
Catfolders Document Gallery Pro
medium
User Profile Builder
medium
User Profile Builder
medium
HEL Online Classroom: AI-powered Online Classrooms
medium
HEL Online Classroom: AI-powered Online Classrooms
medium
Rank Math SEO
medium
Stripe Payment Forms by WP Full Pay
medium
WP Ultimate CSV Importer
medium
MasterStudy LMS
medium
MasterStudy LMS
medium
Frontend Admin by DynamiApps
medium
SOGO Add Script to Individual Pages Header Footer
medium
WPvivid — Backup, Migration & Staging
medium
Really Simple Security
medium
爱采集数据采集和发布插件
medium
Frontend Admin by DynamiApps
medium
Live Composer – Free WordPress Website Builder
medium
Live Composer – Free WordPress Website Builder
medium
Shopping Cart & eCommerce Store
medium
Persistent Login
medium
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
medium
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
medium
Photo Gallery by Ays – Responsive Image Gallery
medium
LearnPress
medium
Blocksy Companion
medium
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
medium
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot
medium
Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)
medium
KiviCare
medium
WP Fastest Cache
medium
MW WP Form
medium
WPBakery Page Builder
medium
Live Composer – Free WordPress Website Builder
medium
Live Composer – Free WordPress Website Builder
medium
Simple Membership
medium
WP Recipe Maker Premium
medium
Ultimate Before After Image Slider & Gallery
medium
Ultimate Before After Image Slider & Gallery
medium
Booking for Appointments and Events Calendar
medium
MotoPress Appointment Booking
medium
Solace Extra
medium
Gutentor
medium
Ultimate Member
medium
Comments
medium
Social Media Share Buttons & Social Sharing Icons
medium
MultiVendorX
medium
GamiPress
medium
Rank Math SEO
medium
Rank Math SEO
medium
FormLayer
medium
CatalogX
medium
MasterStudy LMS
medium
MasterStudy LMS
medium
MasterStudy LMS
medium
MasterStudy LMS
medium
WC Vendors
medium
WC Vendors
medium
WC Vendors
medium
JetStyleManager for Gutenberg
medium
My Login
medium
WPvivid — Backup, Migration & Staging
medium
Easy Waveform Player
medium
LiveJournal Shortcode
medium
Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS
medium
Notification Bar for
medium
Passster
medium
Passster
medium
Wp Edit Password Protected
medium
Yoast SEO Premium
medium
User Frontend
medium
HIPAA FORMS
medium
Ajaxify Comments
medium
RegistrationMagic
medium
RegistrationMagic
medium
Restrict User Access
medium
Brave
medium
All in One SEO
medium
WP Express Checkout
medium
Xpro Addons
medium
Simple Membership MailChimp Integration
medium
Quiz and Survey Master (QSM)
low
Booking for Appointments and Events Calendar
low
MasterStudy LMS
low
MW WP Form
low
Rank Math SEO
low
Rank Math SEO
low
Rank Math SEO
low
Rank Math SEO
low
MasterStudy LMS
low
MasterStudy LMS
low
Weaver Show Posts
low
Icegram Express
low
Timetics
low
GutenKit
low
WordPress Theme Vulnerabilities (3)
Nokri - Job Board WordPress
critical
Divi
medium
Divi
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: August 26 – September 2, 2026
177 WordPress vulnerabilities disclosed between August 26 – September 2, 2026. 14 critical, 44 high severity. 0 patched, 177 unpatched.
WordPress Vulnerability Report: August 25 – September 1, 2026
171 WordPress vulnerabilities disclosed between August 25 – September 1, 2026. 15 critical, 57 high severity. 0 patched, 171 unpatched.
WordPress Vulnerability Report: August 24 – August 31, 2026
171 WordPress vulnerabilities disclosed between August 24 – August 31, 2026. 15 critical, 50 high severity. 0 patched, 171 unpatched.