During the reporting period (February 5 – February 12, 2026), 82 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 87 plugins & components
WordPress Plugin Vulnerabilities (82)
WP Duplicate
critical
JAY Login & Register
critical
Migration, Backup, Staging – WPvivid Backup & Migration
critical
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
high
All In One Image Viewer Block
high
JAY Login & Register
high
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
high
Name Directory
high
Ninja Forms
high
Lucky Wheel Giveaway
high
iONE360 configurator
high
Custom Block Builder – Lazy Blocks
high
'Videospirecore Theme Plugin'
high
wpForo Forum
high
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
medium
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
medium
Sudoku Shortcode
medium
Sudoku Shortcode
medium
Essential Widgets
medium
ShortPixel Image Optimizer
medium
Dynamic Widget Content
medium
ProfileGrid – User Profiles, Groups and Communities
medium
Robin Image Optimizer – Unlimited Image Optimization & WebP Converter
medium
ELEX WordPress HelpDesk & Customer Ticketing System
medium
ProfileGrid – User Profiles, Groups and Communities
medium
Peter's Date Countdown
medium
Greenshift – animation and page builder blocks
medium
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)
medium
OAuth Single Sign On – SSO (OAuth Client)
medium
Tune Library
medium
Orange Confort+ accessibility toolbar for WordPress
medium
Docus – YouTube Video Playlist
medium
WaveSurfer-WP
medium
Employee Directory
medium
Events Listing Widget
medium
Code Snippets
medium
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
medium
Bold Page Builder
medium
Bold Page Builder
medium
Bold Page Builder
medium
Bold Page Builder
medium
Post Slides
medium
The Bucketlister
medium
Bucketlister
medium
Premmerce
medium
TITLE ANIMATOR
medium
Simple Bible Verse via Shortcode
medium
OMIGO
medium
Video Onclick
medium
Wikiloops Track Player
medium
Wonka Slide
medium
Subitem AL Slider
medium
MP-Ukagaka
medium
Advanced Country Blocker
medium
Fluent Forms Pro Add On Pack
medium
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace
medium
Fluent Forms
medium
WCFM Marketplace – Multivendor Marketplace for WooCommerce
medium
PopupKit
medium
The Events Calendar Shortcode & Block
medium
SlimStat Analytics
medium
Gallery by FooGallery
medium
Beaver Builder Page Builder – Drag and Drop Website Builder
medium
Orbisius Random Name Generator
medium
Pix para Woocommerce
medium
WP eCommerce
medium
WPlyr Media Block
medium
Category Image
medium
MMA Call Tracking
medium
Invoct – PDF Invoices & Billing for WooCommerce
medium
Twitter posts to Blog
medium
WDES Responsive Popup
medium
HTML Tag Shortcodes
medium
Microtango
medium
OpenPOS Lite – Point of Sale for WooCommerce
medium
Flask Micro code-editor
medium
WaMate Confirm – Order Confirmation
medium
BuddyHolis ListSearch
medium
Slideshow Wp
medium
WPZOOM Addons for Elementor – Starter Templates & Widgets
medium
Yoast Duplicate-Post
medium
Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium)
medium
WordPress Theme Vulnerabilities (0)
No vulnerabilities reported in this category this week.
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.