During the reporting period (January 1 – January 8, 2026), 122 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 127 plugins & components
WordPress Plugin Vulnerabilities (119)
Branda
critical
AS Password Field In Default Registration Form
critical
FS Registration Password
critical
Optional Email
critical
Team
high
Download Manager
high
BuddyPress Xprofile Custom Field Types
high
Premium Age Verification / Restriction
high
MoneySpace
high
Latest Registered Users
high
Yoco Payments
high
Reviewify
high
Frontend File Manager Plugin
high
WP Photo Album Plus
high
WP Enable WebP
high
iPaymu Payment Gateway for WooCommerce
high
PhotoFade
medium
Comments
medium
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements
medium
WP Import – Ultimate CSV XML Importer for WordPress
medium
Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend
medium
WPBookit
medium
Logo Slider
medium
ShopBuilder
medium
Ninja Forms
medium
Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel
medium
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
medium
Form Vibes – Database Manager for Forms
medium
CBX Bookmark & Favorite
medium
ForumWP – Forum & Discussion Board
medium
ilGhera Support System for WooCommerce
medium
Page Expire Popup/Redirection for WordPress
medium
FastDup – Fastest WordPress Migration & Duplicator
medium
URL Image Importer
medium
Xagio SEO – AI Powered SEO
medium
Popupkit
medium
Shortcodes and extra features for Phlox theme
medium
Table Field Add-on for ACF and SCF
medium
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
medium
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI
medium
MasterStudy LMS WordPress Plugin – for Online Courses and Education
medium
LearnPress – WordPress LMS Plugin
medium
Appointment Booking and Scheduling Calendar Plugin – WP Timetics
medium
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
medium
MediaPress
medium
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
medium
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
medium
Theater
medium
ACF to REST API
medium
aBlocks – WordPress Gutenberg Blocks
medium
ShareThis Dashboard for Google Analytics
medium
WP-Members Membership
medium
Premmerce WooCommerce Customers Manager
medium
Responsive Pricing Table
medium
Guest posting / Frontend Posting / Front Editor – WP Front User Submit
medium
Moosend Landing Pages
medium
Recras WordPress
medium
SVG Map Plugin
medium
MTCaptcha WordPress
medium
WP Status Notifier
medium
xShare
medium
Unify
medium
Stylish Order Form Builder
medium
HelpDesk contact form
medium
WP Recipe Manager
medium
AA Block Country
medium
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
medium
Smart App Banners
medium
PhotoFade
medium
STM Gallery 1.9
medium
Cool YT Player
medium
AI BotKit – AI Chatbot & Live Support for WordPress
medium
Email Customizer for WooCommerce
medium
Mamurjor Employee Info
medium
Contact Us Simple Form
medium
Wish To Go
medium
Multi-column Tag Map
medium
EmailKit
medium
Simcast
medium
AH Shortcodes
medium
WP Js List Pages Shortcodes
medium
Snillrik Restaurant
medium
Viitor Button Shortcodes
medium
1180px Shortcodes
medium
Starred Review
medium
EDD Download Info
medium
AD Sliding FAQ
medium
Testimonial Master
medium
Stumble! for WordPress
medium
Post Like Dislike
medium
WP Widget Changer
medium
Mstoic Shortcodes
medium
Niche Hero | Beautifully-designed blocks in seconds
medium
Easy GitHub Gist Shortcodes
medium
Awesome Hotel Booking
medium
Quote Comments
medium
My Album Gallery
medium
Piraeus Bank WooCommerce Payment Gateway
medium
Sticky Action Buttons
medium
AMP for WP – Accelerated Mobile Pages
medium
QR Code for WooCommerce order emails, PDF invoices, packing slips
medium
Relevanssi
medium
Key Figures
medium
My Album Gallery
medium
LearnPress – WordPress LMS
medium
Drag and Drop Multiple File Upload – Contact Form 7
medium
NS IE Compatibility Fixer
medium
Flashcard
medium
HBLPAY Payment Gateway for WooCommerce
medium
twinklesmtp – Email Service Provider For WordPress
medium
Simple User Meta Editor
medium
Customer Reviews for WooCommerce
medium
Bit Form – Contact Form Plugin
medium
Newsletter Email Subscribe
medium
Latest Tabs
medium
Page Keys
medium
Responsive Pricing Table
medium
FlexTable
low
Rankology SEO and Analytics Tool
low
WordPress Theme Vulnerabilities (3)
Themify Sidepane
critical
Phlox
medium
Plant - Gardening & Houseplants
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.