During the reporting period (February 12 – February 19, 2026), 136 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 141 plugins & components
WordPress Plugin Vulnerabilities (134)
Prime Listing Manager
critical
midi-Synth
critical
Truelysell Core
critical
Spam protection, Anti-Spam, FireWall by CleanTalk
critical
YayMail – WooCommerce Email Customizer
critical
SureForms – Contact Form, Payment Form & Other Custom Form Builder
high
Customer Reviews for WooCommerce
high
Secure Copy Content Protection and Content Locking
high
FastDup – Fastest WordPress Migration & Duplicator
high
Starfish Review Generation & Marketing for WordPress
high
PixelYourSite – Your smart PIXEL (TAG) & API Manager
high
PixelYourSite PRO
high
BlueSnap Payment Gateway for WooCommerce
high
Magic Login Mail or QR Code
high
User Language Switch
high
Super Simple Contact Form
high
Flexi Product Slider and Grid for WooCommerce
high
PhotoStack Gallery
high
Super Page Cache
high
Ecwid by Lightspeed Ecommerce Shopping Cart
high
WowRevenue
high
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
high
Zarinpal Gateway for WooCommerce
high
RSS Aggregator
high
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution
high
Rent Fetch
high
Business Directory Plugin – Easy Listing Directories for WordPress
high
Video Conferencing with Zoom
high
Cart All In One For WooCommerce
high
Product Addons for Woocommerce – Product Options with Custom Fields
high
WPNakama – Team and multi-Client Collaboration, Editorial and Project Management
high
Advanced AJAX Product Filters
high
User Submitted Posts – Enable Users to Submit Posts from the Front End
medium
SureForms – Contact Form, Payment Form & Other Custom Form Builder
medium
LatePoint – Calendar Booking Plugin for Appointments and Events
medium
Converter for Media – Optimize images | Convert WebP & AVIF
medium
Activity Log for WordPress
medium
RegistrationMagic
medium
BFG Tools – Extension Zipper
medium
StickEasy Protected Contact Form
medium
Easy Form Builder
medium
WP Last Modified Info
medium
Easy Voice Mail
medium
personal-authors-category
medium
Simple Wp colorfull Accordion
medium
Citations tools
medium
SEATT: Simple Event Attendance
medium
AMP Enhancer – Compatibility Layer for Official AMP
medium
Appointment Booking Calendar Plugin – Bookr
medium
MDirector Newsletter
medium
LatePoint – Calendar Booking Plugin for Appointments and Events
medium
Link Hopper
medium
One to one user Chat by WPGuppy
medium
WP Data Access
medium
MasterStudy LMS WordPress Plugin – for Online Courses and Education
medium
Allow HTML in Category Descriptions
medium
Accordion and Accordion Slider
medium
User Language Switch
medium
Chatbot for WordPress by Collect.chat
medium
Payment Page | Payment Form for Stripe
medium
Best-wp-google-map
medium
ZoomifyWP Free
medium
MailChimp Campaigns
medium
WP Quick Contact Us
medium
Geo Widget
medium
Address Bar Ads
medium
StyleBidet
medium
QuestionPro Surveys
medium
Ravelry Designs Widget
medium
Sphere Manager
medium
UpMenu – Online ordering for restaurants
medium
Simple Plyr
medium
Percent to Infograph
medium
CallbackKiller service widget
medium
Press3D
medium
Scheduler Widget
medium
Smart Forms
medium
myCred
medium
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
medium
Modula Image Gallery – Photo Grid & Video Gallery
medium
Mail Mint
medium
Essential Addons for Elementor – Popular Elementor Templates & Widgets
medium
Media Library Folders
medium
Element Pack Addons for Elementor
medium
RegistrationMagic
medium
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
medium
EventPrime
medium
Frontend File Manager Plugin
medium
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
medium
WP 404 Auto Redirect to Similar Post
medium
Frontend User Notes
medium
Order Splitter for WooCommerce
medium
Filestack
medium
Display During Conditional Shortcode
medium
URL Shortify
medium
Frontend Post Submission Manager Lite
medium
EmailKit – Email Customizer for WooCommerce & WP
medium
VK All in One Expansion Unit
medium
Popup Box – Easily Create WordPress Popups
medium
Tickera – Sell Tickets & Manage Events
medium
Keybase.io Verification
medium
Taskbuilder – WordPress Project Management & Task Management
medium
PDF Invoices & Packing Slips for WooCommerce
medium
WP Plugin Info Card
medium
Taskbuilder – WordPress Project Management & Task Management
medium
Download Manager
medium
InteractiveCalculator for WordPress
medium
Gutenberg Blocks with AI by Kadence WP
medium
Private Comment
medium
Gutenberg Blocks with AI by Kadence WP
medium
EventPrime
medium
Kali Forms
medium
YayMail – WooCommerce Email Customizer
medium
YayMail – WooCommerce Email Customizer
medium
Dam Spam
medium
Community Events
medium
Business Directory
medium
WP Event Aggregator
medium
SiteOrigin Widgets Bundle
medium
Complianz – GDPR/CCPA Cookie Consent
medium
Video Share VOD – Turnkey Video Site Builder Script
medium
User Submitted Posts – Enable Users to Submit Posts from the Front End
medium
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
medium
Blog2Social: Social Media Auto Post & Scheduler
medium
WP-DownloadManager
medium
Brevo - Email, SMS, Web Push, Chat, and more.
medium
Bookster – WordPress Appointment Booking Plugin
medium
WP Import – Ultimate CSV XML Importer for WordPress
medium
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
medium
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
medium
Booking Calendar
medium
YayMail - WooCommerce Email Customizer
low
WP-DownloadManager
low
WP All Export
low
WordPress Theme Vulnerabilities (2)
AdForest
critical
Context Blog
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.