During the reporting period (May 17 – May 24, 2026), 81 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 86 plugins & components
WordPress Plugin Vulnerabilities (80)
Piotnet Addons for Elementor Pro
critical
Piotnet Forms
critical
ProSolution WP Client
critical
Easy Elements for Elementor – Addons & Website Templates
critical
Boost
critical
Avada Builder (fusion-builder)
critical
Divi Form Builder
critical
BookingPress Pro
critical
Wishlist Member
high
AI Engine – The Chatbot, AI Framework & MCP for WordPress
high
Autoptimize
high
WP Photo Album Plus
high
WP Maps
high
Ajax Load More
high
Fortis for WooCommerce
high
Contest Gallery
high
Kirki – Freeform Page Builder, Website Builder & Customizer
high
Creative Mail – Easier WordPress & WooCommerce Email Marketing
high
Account Switcher
high
Read More & Accordion
high
Boost
high
Advanced Database Cleaner – Premium
high
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
high
Cost of Goods by PixelYourSite
high
WP ERP Pro
high
Easy Elements for Elementor – Addons & Website Templates
high
AudioIgniter
high
Ditty – Responsive News Tickers, Sliders, and Lists
high
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
medium
Simple Fields 0.2 through 0.3.5
medium
Feeds for YouTube (YouTube video, channel, and gallery plugin)
medium
Kirki – Freeform Page Builder, Website Builder & Customizer
medium
診断ジェネレータ作成プラグイン (Diagnosis Generator)
medium
Oliver POS – A WooCommerce Point of Sale (POS)
medium
Sentence To SEO (keywords, description and tags)
medium
Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
medium
Word 2 Cash
medium
Sticky
medium
General Options
medium
Child Height Predictor by Ostheimer
medium
Bottom Bar
medium
Anomify AI – Anomaly Detection and Alerting
medium
Bigfishgames Syndicate
medium
Logo Manager For Enamad
medium
VatanSMS WP SMS
medium
Read More & Accordion
medium
Faces of Users
medium
Games Catalog
medium
Amazon Scraper
medium
BLOGCHAT Chat System
medium
JaviBola Custom Theme Test
medium
Remove Yellow BGBOX
medium
TypeSquare Webfonts for ConoHa
medium
LJ comments import: reloaded
medium
SponsorMe
medium
Correct Prices
medium
Infility Global
medium
Xpro Addons — 140+ Widgets for Elementor
medium
All in One SEO
medium
AI Chatbot & Workflow Automation by AIWU
medium
Email Encoder
medium
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
medium
Decent Comments
medium
Anomify AI – Anomaly Detection and Alerting
medium
Slider Revolution
medium
Broadstreet
medium
WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons
medium
Avada (Fusion) Builder
medium
GSheet For Woo Importer
medium
WP Blockade
medium
Alfie – Feed Plugin
medium
CBX 5 Star Rating & Review
medium
Location Weather
medium
KIA Subtitle
medium
Draft List
medium
Widget Context
medium
Slider by Soliloquy – Responsive Image Slider for WordPress
medium
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
medium
MotoPress Hotel Booking
medium
Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder
medium
WordPress Theme Vulnerabilities (1)
FastX
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 9 – May 16, 2026
104 WordPress vulnerabilities disclosed between May 9 – May 16, 2026. 6 critical, 23 high severity. 1 patched, 103 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.
WordPress Vulnerability Report: April 15 – April 16, 2026
24 WordPress vulnerabilities disclosed between April 15 – April 16, 2026. 2 critical, 4 high severity. 0 patched, 24 unpatched.