During the reporting period (February 19 – February 26, 2026), 106 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 111 plugins & components
WordPress Plugin Vulnerabilities (96)
Clasifico Listing
critical
Lizza LMS Pro
critical
Buyent Classified
critical
Prodigy Commerce
critical
Slider Future
critical
s2Member
critical
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
critical
GDPR Cookie Consent
high
Library Management System
high
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
high
CTX Feed – WooCommerce Product Feed Manager
high
WP AUDIO GALLERY
high
WP Customer Reviews
high
BackWPup – WordPress Backup & Restore Plugin
high
IDonate – Blood Donation, Request And Donor Management System
high
Toret Manager
high
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
high
Sales Countdown Timer for WooCommerce and WordPress
high
wpForo Forum
high
Product Table and List Builder for WooCommerce Lite
high
Responsive Lightbox & Gallery
high
WPGSI: Spreadsheet Integration
high
Advanced Woo Labels
high
Geo Mashup
high
ListingPro Plugin
medium
WPZOOM Addons for Elementor – Starter Templates & Widgets
medium
Aruba HiSpeed Cache
medium
Aruba HiSpeed Cache
medium
Mesmerize Companion
medium
ACF Photo Gallery Field
medium
Mailchimp List Subscribe Form
medium
Printful Integration for WooCommerce
medium
Smartsupp – live chat, AI shopping assistant and chatbots
medium
Easy SVG Support
medium
Checkout Field Manager (Checkout Manager) for WooCommerce
medium
Advanced Ads – Ad Manager & AdSense
medium
StatCounter – Free Real Time Visitor Stats
medium
Popup Builder – Create highly converting, mobile friendly marketing popups.
medium
Web Accessibility by accessiBe
medium
Country Blocker for AdSense
medium
Page Title, Description & Open Graph Updater
medium
Two Factor (2FA) Authentication via Email
medium
Album and Image Gallery plus Lightbox
medium
Apollo13 Framework Extensions
medium
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
medium
Easy Table of Contents
medium
Breadcrumb NavXT
medium
Breeze - WordPress Cache Plugin
medium
Checkout Field Manager (Checkout Manager) for WooCommerce
medium
iXML – Google XML sitemap generator
medium
Remove Post Type Slug
medium
Razorpay for WooCommerce
medium
SEO Plugin by Squirrly SEO
medium
Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches
medium
Image Hotspot by DevVN
medium
YaMaps for WordPress
medium
Virusdie - One-click website security
medium
Advanced Custom Fields: Font Awesome Field
medium
Groups
medium
XO Event Calendar
medium
Shield Security
medium
Shield Security
medium
PostmarkApp Email Integrator
medium
Tennis Court Bookings
medium
salavat counter Plugin
medium
TalkJS
medium
Easy Author Image
medium
Whatsiplus Scheduled Notification for Woocommerce
medium
Advance Block Extend
medium
Slidorion
medium
News Element Elementor Blog Magazine
medium
xmlrpc attacks blocker
medium
Dealia – Request a quote
medium
rtMedia for WordPress, BuddyPress and bbPress
medium
Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress
medium
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
medium
Simple Membership
medium
Client Testimonial Slider
medium
Dealia – Request a Quote
medium
Quiz Maker
medium
Master Addons For Elementor
medium
GA4WP: Google Analytics
medium
ELEX WordPress HelpDesk & Customer Ticketing System
medium
weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation
medium
LearnPress Export Import – WordPress extension for LearnPress
medium
Conditional CAPTCHA
medium
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
medium
Aruba HiSpeed Cache
medium
Rise Blocks – A Complete Gutenberg Page Builder
medium
Responsive Lightbox & Gallery
medium
WP Recipe Maker
medium
Post Duplicator
medium
Secure Copy Content Protection and Content Locking
medium
Disable Admin Notices – Hide Dashboard Notifications
medium
The Events Calendar
medium
OneClick Chat to Order
low
WordPress Theme Vulnerabilities (10)
NewsBlogger
high
Oyster - Photography
high
SOHO - Photography
high
PawFriends - Pet Shop and Veterinary
high
Drift
medium
Renden
medium
Shopire
medium
Mega Store Woocommerce
medium
Cartify - WooCommerce Gutenberg
medium
PawFriends - Pet Shop and Veterinary
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.