During the reporting period (July 21 – July 28, 2026), 118 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 123 plugins & components
WordPress Plugin Vulnerabilities (115)
GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more
critical
Customer Support Ticket System & Helpdesk
critical
MountDev AI MCP Connector for WordPress
critical
SAML Single Sign On – SSO Login
critical
Project Management, Bug and Issue Tracking Plugin
critical
MemberGlut
critical
Masteriyo LMS
critical
微信二维码登陆
critical
Realtyna Organic IDX plugin + WPL Real Estate
critical
FacturaONE para WooCommerce con VeriFactu
critical
MapSVG
high
Ninja Forms
high
WP Foodbakery
high
Product Addons and Product Options With Custom Fields
high
Events Manager
high
FormCraft
high
SUMO Reward Points
high
Praison AI SEO
high
security-ninja-premium
high
ARforms
high
Lumise Product Designer for WooCommerce
high
MDJM Event Management
high
WPO365 | Login
high
Wpify Woo
high
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content
high
CAFEHAUS API
high
WowOptin: Next-Gen Popup Maker
high
EventON Action User
high
VikBooking Hotel Booking Engine & PMS
high
Easy Appointments
high
WPForms Pro
high
Fluent Forms Pro Add On Pack
high
Printcart Web to Print Product Designer for WooCommerce
high
MainWP Child
high
Clover Payment Gateway by Zaytech for WooCommerce
high
Custom Fields Account Registration For Woocommerce
high
MPG
high
Download Manager
high
bookingpress-appointment-booking-pro
high
Demi – One Click Demo Import, WP Backup & Site Migration
high
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
high
WCPOS – Point of Sale (POS) plugin for WooCommerce
medium
Essential Addons for Elementor – Popular Elementor Templates & Widgets
medium
Tutor LMS Elementor Addons
medium
Ninja Forms
medium
Ninja Forms
medium
Timetics
medium
Ultimate Addons for Elementor
medium
The Contact Form 7 – Dynamic Text Extension
medium
WP Compress
medium
Post Status Notifier Lite
medium
WP Shortcode by MyThemeShop
medium
Webpushr Push Notifications
medium
AI Copilot – Content Generator
medium
Registrations For The Events Calendar
medium
Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance
medium
Premium Packages – Sell Digital Products Securely
medium
Header Footer Script Adder – Insert Code in Header, Body & Footer
medium
Lpagery
medium
Tickera – Sell Tickets & Manage Events
medium
Brands for WooCommerce
medium
Brands for WooCommerce
medium
Tickera – Sell Tickets & Manage Events
medium
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan
medium
Grid/List View for WooCommerce
medium
GutenKit Blocks
medium
Premium Packages – Sell Digital Products Securely
medium
WCPOS – Point of Sale (POS) plugin for WooCommerce
medium
MapSVG
medium
Participants Database
medium
Kirki – Freeform Page Builder, Website Builder & Customizer
medium
Post Grid Gutenberg Blocks – PostX
medium
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
medium
Firelight Lightbox
medium
ProfileGrid
medium
ProfileGrid
medium
Payment Plugins for Stripe WooCommerce
medium
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
medium
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
medium
WP Hotel Booking
medium
Brands for WooCommerce
medium
Visualizer – Tables & Charts Manager with Built-in AI Generator
medium
Fluent Support – Helpdesk & Customer Support Ticket System
medium
Open User Map – Interactive Leaflet Maps
medium
VikBooking Hotel Booking Engine & PMS
medium
Rich Showcase for Google Reviews
medium
SureDash – Community, Courses & Member Dashboard
medium
Ninja Forms – The Contact Form Builder That Grows With You
medium
Checkout Field Editor for WooCommerce (Pro)
medium
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
medium
Advanced Ads
medium
Document Gallery
medium
Events Calendar
medium
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments
medium
Sina Extension for Elementor
medium
Smart Manager
medium
Contact Form 7
medium
User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration
medium
Quiz and Survey Master (QSM)
medium
Calendar
medium
PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
medium
TrueBooker
medium
Event Tickets and Registration
medium
Quiz and Survey Master (QSM)
medium
Database for Contact Form 7, WPforms, Elementor forms
medium
Tablesome Table
medium
FluentCart A New Era of eCommerce
medium
Demi – One Click Demo Import, WP Backup & Site Migration
medium
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
medium
Advanced Form Integration — Connect Forms to 200+ Apps
medium
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
medium
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
medium
Chaty Pro
medium
ProfileGrid
low
WPBot
low
WordPress Theme Vulnerabilities (3)
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education
high
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education
high
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: July 29 – August 5, 2026
284 WordPress vulnerabilities disclosed between July 29 – August 5, 2026. 24 critical, 54 high severity. 4 patched, 280 unpatched.
WordPress Vulnerability Report: July 28 – August 4, 2026
296 WordPress vulnerabilities disclosed between July 28 – August 4, 2026. 19 critical, 61 high severity. 2 patched, 294 unpatched.
WordPress Vulnerability Report: July 27 – August 3, 2026
287 WordPress vulnerabilities disclosed between July 27 – August 3, 2026. 14 critical, 55 high severity. 2 patched, 285 unpatched.