During the reporting period (January 15 – January 22, 2026), 71 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 76 plugins & components
WordPress Plugin Vulnerabilities (70)
RegistrationMagic
critical
Registration & Login with Mobile Phone Number for WooCommerce
critical
Advanced Custom Fields: Extended
critical
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
critical
Quiz, Poll & Survey Maker by Opinion Stage
high
Supreme Modules Lite
high
All-in-One Video Gallery
high
Membership Plugin – Restrict Content
high
Demo Importer Plus
high
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
high
Creator LMS – The LMS for Creators, Coaches, and Trainers
high
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
high
Nexter Extension – Site Enhancements Toolkit
high
Fraud Prevention For WooCommerce and EDD
medium
WP-Members Membership Plugin
medium
AffiliateX – Amazon Affiliate Plugin
medium
Uploadify
medium
Awesome Support - WordPress HelpDesk & Support
medium
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
medium
Booking Calendar
medium
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches
medium
Fancy Product Designer
medium
WP Recipe Maker
medium
MailerLite - WooCommerce integration
medium
DK PDF – WordPress PDF Generator
medium
LEAV Last Email Address Validator
medium
Related Posts by Taxonomy
medium
Rede Itaú for WooCommerce
medium
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
medium
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
medium
GetGenie
medium
Cost Calculator Builder
medium
User Submitted Posts – Enable Users to Submit Posts from the Front End
medium
Essential Addons for Elementor
medium
Poll, Survey & Quiz Maker Plugin by Opinion Stage
medium
Feeds for YouTube Pro
medium
Quick Contact Form
medium
WP Hotel Booking
medium
Wallet System for WooCommerce
medium
Filr – Secure document library
medium
Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor
medium
Payment Button for PayPal
medium
RepairBuddy – Repair Shop CRM & Booking
medium
Phrase TMS Integration for WordPress
medium
User Registration Using Contact Form 7
medium
Community Events
medium
Advanced Ads – Ad Manager & AdSense
medium
CM E-Mail Blacklist – Simple email filtering for safer registration
medium
Spin Wheel
medium
Team Section Block
medium
CubeWP – All-in-One Dynamic Content Framework
medium
PAYGENT for WooCommerce
medium
CubeWP
medium
Integrate Dynamics 365 CRM
medium
Image Photo Gallery Final Tiles Grid
medium
PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net)
medium
Newsletter – Send awesome emails from WordPress
medium
Custom Fonts – Host Your Fonts Locally
medium
LearnPress – WordPress LMS
medium
weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation
medium
Bookingor
medium
WP Hello Bar
medium
Viet contact
medium
The Events Calendar
medium
Tutor LMS – eLearning and online course solution
medium
NotificationX
medium
Head Meta Data
medium
FlatPM – Ad Manager, AdSense and Custom Code
medium
Drag and Drop Multiple File Upload for Contact Form 7
low
Church Admin
low
WordPress Theme Vulnerabilities (1)
Kalium 3 | Creative WordPress & WooCommerce Theme
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.