During the reporting period (January 22 – January 29, 2026), 106 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 111 plugins & components
WordPress Plugin Vulnerabilities (104)
LA-Studio Element Kit for Elementor
critical
Kalrav AI Agent
critical
Snow Monkey Forms
critical
amr cron manager
high
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot
high
The BuddyPress
high
Melapress Role Editor
high
Frontis Blocks
high
Administrative Shortcodes
high
User Submitted Posts – Enable Users to Submit Posts from the Front End
high
Hustle – Email Marketing, Lead Generation, Optins, Popups
high
AhaChat Messenger Marketing
high
TableMaster for Elementor
high
New User Approve
high
VidShop – Shoppable Videos for WooCommerce
high
AI Engine – The Chatbot and AI Framework for WordPress
high
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
high
Simple User Registration
high
Frontend File Manager
high
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
medium
Magic Responsive Slider and Carousel WordPress
medium
WordPress Photo Gallery
medium
Electrician - Electrical Service WordPress
medium
Wordpress Movies Bulk Importer
medium
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
medium
Schema & Structured Data for WP & AMP
medium
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
medium
KiviCare – Clinic & Patient Management System (EHR)
medium
WP DSGVO Tools (GDPR)
medium
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
medium
Related Posts Thumbnails Plugin
medium
Trusona
medium
All-in-One Video Gallery
medium
VK Google Job Posting Manager
medium
JustClick registration
medium
Wise Analytics
medium
Alchemist Ajax Upload
medium
Same Category Posts
medium
Wizit Gateway for WooCommerce
medium
Simple Crypto Shortcodes
medium
WP Youtube Video Gallery
medium
GZSEO
medium
Alpha Blocks
medium
WP-ClanWars
medium
Alex User Counter
medium
ZT Captcha
medium
Star Review Manager
medium
Set Bulk Post Categories
medium
Cookie consent for developers
medium
Login Page Editor
medium
Canto Testimonials
medium
ThemeRuby Multi Authors – Assign Multiple Writers to Posts
medium
Administrative Shortcodes
medium
AIKTP
medium
SurveyJS: Drag & Drop WordPress Form Builder
medium
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity
medium
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity
medium
AdminQuickbar
medium
Moderate Selected Posts
medium
All-in-One Video Gallery
medium
Meta-box GalleryMeta
medium
CM CSS Columns
medium
Timeline Event History
medium
LeadBI
medium
JavaScript Notifier
medium
Friendly Functions for Welcart
medium
Postalicious
medium
Responsive Header
medium
Meta-box GalleryMeta
medium
WP Directory Kit
medium
Save as PDF Plugin by PDFCrowd
medium
WP Go Maps (formerly WP Google Maps)
medium
CubeWP – All-in-One Dynamic Content Framework
medium
Recipe Card Blocks Lite
medium
Link Invoice Payment for WooCommerce
medium
AI Engine
medium
User Activity Log
medium
Target Video Easy Publish
medium
Appointment Hour Booking – Booking Calendar
medium
Easy Replace Image
medium
Interactions – Create Interactive Experiences in the Block Editor
medium
Simple Folio
medium
WPBITS Addons For Elementor
medium
Database for Contact Form 7, WPforms, Elementor forms
medium
Forms Bridge – Infinite integrations
medium
Buy Now Plus – Buy Now buttons for Stripe
medium
Simple calendar for Elementor
medium
RegistrationMagic
medium
Document Embedder – Embed PDFs, Word, Excel, and Other Files
medium
Ivory Search – WordPress Search Plugin
medium
Order Minimum/Maximum Amount Limits for WooCommerce
medium
SEO Links Interlinking
medium
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library
medium
Recooty – Job Widget (Old Dashboard)
medium
Rupantorpay
medium
imwptip
medium
Bitcoin Donate Button
medium
Vzaar Media Management
medium
Change WP URL
medium
WP Google Ad Manager Plugin
medium
Passster – Password Protect Pages and Content
medium
Stop Spammers Classic
medium
WP Adminify
medium
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
low
WordPress Theme Vulnerabilities (2)
Bajaar - Highly Customizable WooCommerce
high
PawFriends - Pet Shop and Veterinary
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.