During the reporting period (January 29 – February 5, 2026), 43 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 48 plugins & components
WordPress Plugin Vulnerabilities (43)
User Profile Builder
critical
CMSMasters Content Composer
high
Custom Login Page Customizer
high
Sell BTC - Cryptocurrency Selling Calculator
high
Library Viewer
high
LatePoint – Calendar Booking Plugin for Appointments and Events
high
Form Maker
high
Form Maker by 10Web
high
Tutor LMS – eLearning and online course solution
high
OS DataHub Maps
high
WP FOFT Loader
high
Infility Global
high
SEO Flow by LupsOnline
high
SportsPress
high
NEX-Forms – Ultimate Forms
medium
Ajax Load More – Infinite Scroll, Load More, & Lazy Load
medium
Booking Calendar
medium
SupportCandy – Helpdesk & Customer Support Ticket System
medium
SupportCandy – Helpdesk & Customer Support Ticket System
medium
Popup Box
medium
Stripe Green Downloads
medium
Five Star Restaurant Reservations
medium
WP ULike
medium
Unlimited Elements for Elementor
medium
Spectra Gutenberg Blocks – Website Builder for the Block Editor
medium
Happy Addons for Elementor
medium
Mail Mint
medium
Tutor LMS – eLearning and online course solution
medium
Hustle
medium
Menu Icons by ThemeIsle
medium
Xendit Payment
medium
MyRewards – Loyalty Points and Rewards for WooCommerce
medium
Chapa Payment Gateway Plugin for WooCommerce
medium
Code Explorer
medium
Magic Import Document Extractor
medium
Magic Import Document Extractor
medium
WebPurify Profanity Filter
medium
Fortis for WooCommerce
medium
Extended Random Number Generator
medium
Smart Appointment & Booking
medium
WP Content Permission
medium
All push notification for WP
medium
SIBS woocommerce payment gateway
medium
WordPress Theme Vulnerabilities (0)
No vulnerabilities reported in this category this week.
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.