During the reporting period (May 9 – May 16, 2026), 104 WordPress security vulnerabilities were disclosed across plugins, themes, and core. This report aggregates data from the NIST National Vulnerability Database, Wordfence Intelligence, and our own scanning database.
Summary
Table of Contents 109 plugins & components
WordPress Plugin Vulnerabilities (103)
Career Section
critical
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
critical
Career Section
critical
InfusedWoo Pro
critical
InfusedWoo Pro
critical
Form Notify
critical
Custom css-js-php
high
AI Chatbot & Workflow Automation by AIWU
high
LifePress
high
Court Reservation – Manage Your Court Bookings Online
high
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
high
coreActivity: Activity Logging for WordPress
high
JoomSport – for Sports: Team & League, Football, Hockey & more
high
Avada Builder
high
RTMKit Addons for Elementor
high
Custom Twitter Feeds
high
ProfileGrid – User Profiles, Groups and Communities
high
Fluent Forms
high
ManageWP Worker
high
Motors – Car Dealership & Classified Listings Plugin
high
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
high
InfusedWoo Pro
high
InfusedWoo Pro
high
Database Backup for WordPress
high
Database Backup for WordPress
high
Database Backup for WordPress
high
FOX – Currency Switcher Professional for WooCommerce
high
Frontend Admin by DynamiApps
high
Quick Playground
high
LatePoint
medium
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
medium
BJ Lazy Load
medium
WP SEO Structured Data Schema
medium
Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings
medium
SP Blog Designer
medium
Next Date
medium
Eight Day Week Print Workflow
medium
Fancy Image Show
medium
Smart Appointment & Booking
medium
Voyage Plus
medium
Quick Table
medium
scratchblocks for WP
medium
Credits Shortcode
medium
GWD Connect
medium
HEL Online Classroom: AI-powered Online Classrooms
medium
Coinbase Commerce for Contact Form 7
medium
Skysa Text Ticker App
medium
Pricing Tables for WP
medium
Shortcodely
medium
Woo Commerce Minimum Weight
medium
Forms Rb
medium
AzonPost
medium
WP Google Maps Integration
medium
Tm – WordPress Redirection
medium
WP-Redirection
medium
Zawgyi Embed
medium
Slek Gateway for WooCommerce
medium
Advanced Social Media Icons
medium
Bootstrap Shortcode
medium
Motors – Car Dealership & Classified Listings
medium
FastBots
medium
Continually
medium
The Advanced Custom Fields: Extended
medium
Cost Calculator Builder
medium
Broadstreet
medium
Broadstreet
medium
Broadstreet
medium
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
medium
Cost of Goods: Product Cost & Profit Calculator for WooCommerce
medium
Blog2Social: Social Media Auto Post & Scheduler
medium
Charitable – Donation
medium
ilGhera Support System for WooCommerce
medium
Tutor LMS – eLearning and online course solution
medium
WPC Badge Management for WooCommerce
medium
Snow Monkey Blocks
medium
Hostinger Reach – AI-Powered Email Marketing for WordPress
medium
Avada Builder
medium
RTMKit Addons for Elementor
medium
ProfileGrid – User Profiles, Groups and Communities
medium
ProfileGrid – User Profiles, Groups and Communities
medium
Unlimited Elements for Elementor
medium
Envira Gallery Lite
medium
My Calendar – Accessible Event Manager
medium
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
medium
MapGeo – Interactive Geo Maps
medium
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan
medium
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
medium
GLS Shipping for WooCommerce
medium
Bold Page Builder
medium
Essential Addons for Elementor – Popular Elementor Templates & Widgets
medium
LatePoint
medium
Taskbuilder – Project Management & Task Management Tool With Kanban Board
medium
Meta Field Block
medium
Media Sync
medium
User Registration & Membership
medium
CC Child Pages
medium
MW WP Form
medium
Royal Elementor Addons and Templates
medium
Smartcat Translator for WPML
medium
Advanced Custom Fields: Font Awesome
medium
NEX-Forms – Ultimate Forms
medium
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
medium
Notify Odoo
medium
WordPress Theme Vulnerabilities (1)
The7
medium
WordPress Core Vulnerabilities (0)
No vulnerabilities reported in this category this week.
Recommendations
Install the latest versions of all plugins, themes, and WordPress core.
Turn on automatic updates for minor WordPress releases and plugins where possible.
Deactivate and delete any plugins or themes you no longer use.
Use our free WordPress security scanner to check your site for known vulnerabilities.
Set up uptime monitoring and periodic security scans to catch issues early.
Methodology
This report is compiled automatically from multiple trusted sources:
Tags
Related Posts
WordPress Vulnerability Report: May 17 – May 24, 2026
81 WordPress vulnerabilities disclosed between May 17 – May 24, 2026. 8 critical, 20 high severity. 2 patched, 79 unpatched.
WordPress Vulnerability Report: May 1 – May 8, 2026
96 WordPress vulnerabilities disclosed between May 1 – May 8, 2026. 6 critical, 35 high severity. 1 patched, 95 unpatched.
WordPress Vulnerability Report: April 15 – April 16, 2026
24 WordPress vulnerabilities disclosed between April 15 – April 16, 2026. 2 critical, 4 high severity. 0 patched, 24 unpatched.