During the reporting period (May 1 – May 8, 2026), 96 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 101 plugins & components
WordPress Plugin Vulnerabilities (92)
Temporary Login
critical
User Registration Advanced Fields
critical
User Verification by PickPlugins
critical
MoreConvert Pro
critical
Mentoring
critical
Geeky Bot
critical
WP Business Intelligence Lite
high
WP Editor
high
WP Mail Gateway
high
Import and export users and customers
high
Gravity Forms
high
Gravity Forms
high
Gravity Forms
high
Gravity Forms
high
Gravity Forms
high
PixelYourSite Pro – Your smart PIXEL (TAG) Manager
high
Profile Builder Pro
high
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
high
Royal Elementor Addons
high
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
high
Brizy – Page Builder
high
Geo Mashup
high
Geo Mashup
high
Geo Mashup
high
Paid Memberships Pro
high
Salon Booking System – Free Version
high
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
high
NEX-Forms – Ultimate Forms
high
Conditional Fields for Contact Form 7
high
AWP Classifieds
high
GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation
high
Royal Elementor Addons
high
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
high
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
high
WeePie Cookie Allow
high
LatePoint – Calendar Booking Plugin for Appointments and Events
high
Gravity Bookings Premium
high
BetterDocs Pro
high
Slider Revolution
high
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
high
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
medium
WP Business Intelligence Lite
medium
Elementor Website Builder
medium
Ultimate Dashboard
medium
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
medium
Maxi Blocks
medium
Simple Link Directory
medium
App Builder – Create Native Android & iOS Apps On The Flight
medium
Widgets for Social Photo Feed
medium
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
medium
My Social Feeds – Social Feeds Embedder
medium
Call for Price for WooCommerce
medium
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
medium
FundPress – WordPress Donation
medium
Booking for Appointments and Events Calendar – Amelia
medium
Geo Mashup
medium
Royal Addons for Elementor
medium
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
medium
Quiz Maker by AYS
medium
NextMove Lite – Thank You Page for WooCommerce
medium
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution
medium
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin
medium
Magic Export & Import
medium
Loco Translate
medium
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem
medium
Subscribe To Comments Reloaded
medium
Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website
medium
Schedule Post Changes With PublishPress Future
medium
WP-Clippy
medium
Simple Owl Shortcodes
medium
Zingaya Click-to-Call
medium
DX Sources
medium
addfreespace
medium
Publish 2 Ping.fm
medium
Blog Settings
medium
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem
medium
WP Carousel Free
medium
Royal Addons for Elementor
medium
EmailKit
medium
ElementsKit Elementor Addons
medium
Forminator
medium
GenerateBlocks
medium
User Registration & Membership
medium
Mercado Pago payments for WooCommerce
medium
All-in-One WP Migration Unlimited Extension
medium
Ninja Tables – Easy Data Table Builder
medium
Fluent Forms
medium
Affiliate Program Suite — SliceWP Affiliates
medium
LatePoint
medium
Forminator Forms
medium
Appointment Booking Calendar
medium
Forminator Forms
medium
WordPress Theme Vulnerabilities (4)
Betheme
high
Ona
medium
Total
medium
Betheme
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: April 15 – April 16, 2026
24 WordPress vulnerabilities disclosed between April 15 – April 16, 2026. 2 critical, 4 high severity. 0 patched, 24 unpatched.