During the reporting period (January 8 – January 15, 2026), 109 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 114 plugins & components
WordPress Plugin Vulnerabilities (107)
WP Cost Estimation
critical
Frontend Admin by DynamiApps
critical
Frontend Admin by DynamiApps
critical
E-xact | Hosted Payment |
critical
Integration Opvius AI for WooCommerce
critical
News and Blog Designer Bundle
critical
WP-BusinessDirectory
high
Brevo for WooCommerce
high
SlimStat Analytics
high
SlimStat Analytics
high
Eventin – Event Manager, Events Calendar, Event Tickets and Registrations
high
Frontend Admin by DynamiApps
high
WooCommerce Square
high
GetContentFromURL
high
DASHBOARD BUILDER – WordPress plugin for Charts and Graphs
high
GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation
high
Name Directory
high
AJS Footnotes
high
Shipping Rate By Cities
high
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
high
WP Cost Estimation
medium
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
medium
Jeg Elementor Kit
medium
Tutor LMS – eLearning and online course solution
medium
Gutenverse Form
medium
Famous - Responsive Image And Video Grid Gallery WordPress Plugin
medium
Campaign Monitor
medium
Bulk Landing Page Creator for WordPress LPagery
medium
GA4WP: Google Analytics
medium
Japanized for WooCommerce
medium
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
medium
NEX-Forms
medium
weDocs
medium
Schedule Post Changes With PublishPress Future
medium
Booking for Appointments and Events Calendar – Amelia
medium
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
medium
IndieWeb
medium
BetterDocs
medium
BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce
medium
WP Google Street View (with 360° virtual tour) & Google maps + Local SEO
medium
Tutor LMS – eLearning and online course solution
medium
WP Table Builder – Drag & Drop Table Builder
medium
Tutor LMS – eLearning and online course solution
medium
Tutor LMS – eLearning and online course solution
medium
Booking Calendar
medium
AMP for WP
medium
Entry Views
medium
Nearby Now Reviews
medium
Top Position Google Finance
medium
WP Popup Magic
medium
Header and Footer Scripts
medium
Shabat Keeper
medium
Autogen Headers Menu
medium
Contact Form vCard Generator
medium
Debt.com Business in a Box
medium
Curved Text
medium
Menu Card
medium
MG AdvancedOptions
medium
Lesson Plan Book
medium
Client Testimonial Slider
medium
PullQuote
medium
The Tooltip
medium
Woodpecker for WordPress
medium
WP Page Permalink Extension
medium
AccessAlly
medium
Blog2Social: Social Media Auto Post & Scheduler
medium
miniOrange OTP Verification and SMS Notification for WooCommerce
medium
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin
medium
Templately
medium
ConvertForce Popup Builder
medium
Countdown Timer – Widget Countdown
medium
Shortcodes and extra features for Phlox theme
medium
Featured Image from URL (FIFU)
medium
Quiz Maker
medium
WP Duplicate Page
medium
EventPrime - Events Calendar, Bookings and Tickets
medium
CP Image Store with Slideshow
medium
SpiceForms Form Builder
medium
Makesweat
medium
Testimonials Creator
medium
WPBlogSyn
medium
PDF Resume Parser
medium
Crush.pics Image Optimizer - Image Compression and Optimization
medium
Internal Link Builder
medium
WP-CRM System
medium
Netcash WooCommerce Payment Gateway
medium
Gotham Block Extra Light
medium
Gotham Block Extra Light
medium
Sosh Share Buttons
medium
Kunze Law
medium
List Site Contributors
medium
Responsive Accordion Slider
medium
Flat Shipping Rate by City for WooCommerce
medium
Real Post Slider Lite
medium
SearchWiz
medium
LottieFiles – Lottie block for Gutenberg
medium
Perfit WooCommerce
medium
SocialChamp with WordPress
medium
Stopwords for comments
medium
PayHere Payment Gateway Plugin for WooCommerce
medium
Aplazo Payment Gateway
medium
Float Payment Gateway
medium
WP Allowed Hosts
medium
WMF Mobile Redirector
medium
Electric Studio Download Counter
medium
LinkedIn SC
medium
Short Link
medium
WordPress Theme Vulnerabilities (2)
Dreamer Blog
critical
Dreamer Blog
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.