During the reporting period (March 5 – March 8, 2026), 61 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 66 plugins & components
WordPress Plugin Vulnerabilities (52)
Login with Salesforce
critical
Database for Contact Form 7, WPforms, Elementor forms
critical
PowerPack for LearnDash
critical
Meta Box
high
Fluent Forms Pro
high
Membership Plugin – Restrict Content
high
WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation
high
Drag and Drop Multiple File Upload - Contact Form 7
high
WooCommerce
high
ZIP Code Based Content Protection
high
JS Archive List
high
Easy PHP Settings
high
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams
high
Meta Box
high
WP App Bar
high
Fluent Forms Pro Add On Pack
medium
OoohBoi Steroids for Elementor
medium
Apocalypse Meow
medium
Theater
medium
Builderall Builder
medium
WordPress CTA
medium
Media Library Assistant
medium
Page and Post Clone
medium
Greenshift – animation and page builder blocks
medium
Greenshift – animation and page builder blocks
medium
WP eCommerce
medium
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
medium
WP Frontend Profile
medium
HUMN-1 AI Website Scanner & Human Certification by Winston AI
medium
Greenshift – animation and page builder blocks
medium
MDJM Event Management
medium
Hammas Calendar
medium
Community Events
medium
CM Custom Reports
medium
ProfileGrid – User Profiles, Groups and Communities
medium
ProfileGrid – User Profiles, Groups and Communities
medium
MailArchiver
medium
Stock Ticker
medium
Carta Online
medium
Purchase Button For Affiliate Link
medium
True Ranker
medium
Font Pairing Preview For Landing Pages
medium
Guardian News Feed
medium
Wueen
medium
MyQtip – easy qTip2
medium
DA Media GigList
medium
Media Library Alt Text Editor
medium
Consensus Embed
medium
Infomaniak Connect for OpenID
medium
Show YouTube video
medium
LotekMedia Popup Form
medium
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
medium
WordPress Theme Vulnerabilities (9)
Healer - Doctor, Clinic & Medical
critical
TopScorer - Sports
high
CasaMia | Property Rental Real Estate
medium
AC Services | HVAC, Air Conditioning & Heating Company
medium
Consultor | Consulting, Accounting & Legal Counsel
medium
Chronicle - Lifestyle Magazine & Blog
medium
Buzz Stone | Magazine & Viral Blog
medium
Apollo | Night Club, DJ Event
medium
TopFit - Fitness and Gym
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.