Wordfence Intelligence Weekly WordPress Vulnerability Report (January 26, 2026 to February 1, 2026)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 159 vulnerabilities disclosed in 139 WordPress Plugins and 14 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 63 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

      • WAF-RULE-892 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 96
Unpatched 63


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 125
High Severity 32
Critical Severity 2


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Missing Authorization 61
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 42
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 16
Cross-Site Request Forgery (CSRF) 14
Deserialization of Untrusted Data 5
Exposure of Sensitive Information to an Unauthorized Actor 5
Server-Side Request Forgery (SSRF) 4
Authorization Bypass Through User-Controlled Key 3
Authentication Bypass Using an Alternate Path or Channel 2
URL Redirection to Untrusted Site ('Open Redirect') 2
Improper Access Control 1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
Incorrect Authorization 1
Unrestricted Upload of File with Dangerous Type 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
21
17
9
9
7
7
7
7
5
4
4
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Aardvark aardvark-plugin
aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory adirectory
Adminify – White Label, Admin Menu Editor, Login Customizer adminify
AhaChat Messenger Marketing ahachat-messenger-marketing
AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine
Ajax Load More – Infinite Scroll, Load More, & Lazy Load ajax-load-more
Allmart allmart-core
Appointment Hour Booking – Booking Calendar appointment-hour-booking
Asynchronous Javascript asynchronous-javascript
Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback atarim-visual-collaboration
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder bit-form
Bitcoin Donate Button bitcoin-donate-button
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library blockart-blocks
Booked - Appointment Booking for WordPress booked
Booking Calendar booking
Broken Link Notifier broken-link-notifier
bSlider – Create Responsive Image, Post, Product, and Video Sliders b-slider
Buy Now Plus — Payments with Stripe buy-now-plus
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce cartflows
Change WP URL change-wp-url
CLP Varnish Cache clp-varnish-cache
Conditional CAPTCHA wp-conditional-captcha
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode cookiebot
Crete Core crete-core
Database for Contact Form 7, WPforms, Elementor forms contact-form-entries
DesignThemes Core Features designthemes-core-features
Directorist: AI-Powered Business Directory, Listings & Classified Ads directorist
Document Embedder – let visitors read files without downloading document-emberdder
Easy Hotel – Powerful Hotel Booking easy-hotel
Easy Replace Image easy-replace-image
Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search echo-knowledge-base
eDS Responsive Menu eds-responsive-menu
Educare – Students & Result Management System educare
Electio Core electio-core
ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system
Email Inquiry & Cart Options for WooCommerce woocommerce-email-inquiry-cart-options
Emerce - Multipurpose WooCommerce WordPress Theme emerce-core
Enter Addons – Ultimate Template Builder for Elementor enteraddons
EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management
FeedWordPress Advanced Filters faf
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler fluent-cart
Forms Bridge – Infinite integrations forms-bridge
FormsDB – Save Elementor Forms to Google Sheets & Post Type sb-elementor-contact-form-db
Frontend File Manager Plugin nmedia-user-file-uploader
Gallery PhotoBlocks photoblocks-grid-gallery
Gyan Elements gyan-elements
HAPPY – Helpdesk Support Ticket System happy-helpdesk-support-ticket-system
hCaptcha for WP hcaptcha-for-forms-and-more
ID Arrays id-arrays
imwptip imwptip
Interactions – Animations for Elementor & Gutenberg interactions
iSape isape
Ivory Search – WordPress Search Plugin add-search-to-menu
JAMstack Deployments wp-jamstack-deployments
JobBoard Job listing plugin job-board-light
Kama Thumbnail kama-thumbnail
KiviCare – Clinic & Patient Management System (EHR) kivicare-clinic-management-system
Leadpages leadpages
Link Invoice Payment for WooCommerce invoice-payment-for-woocommerce
MailerLite – Signup forms (official) official-mailerlite-sign-up-forms
Medinik Core medinik-core
Membee Login membees-member-login-widget
MemberHero – Simple User Registration & Login wp-registration
Mizan Demo Importer mizan-demo-importer
ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery
ModelTheme Framework modeltheme-framework
Mopinion Feedback Form mopinion-feedback-form
MyBookTable Bookstore by Stormhill Media mybooktable
Nelio Popups nelio-popups
Nestbyte Core nestbyte-core
New User Approve new-user-approve
News Kit Addons For Elementor news-kit-elementor-addons
NEX-Forms – Ultimate Forms Plugin for WordPress nex-forms-express-wp-form-builder
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder the-plus-addons-for-block-editor
NextMove Lite – Thank You Page for WooCommerce woo-thank-you-page-nextmove-lite
Nova Blocks by Pixelgrade nova-blocks
Order Minimum/Maximum Amount Limits for WooCommerce order-minimum-amount-for-woocommerce
Order Tracking – WordPress Status Tracking Plugin order-tracking
OSM – OpenStreetMap osm
Passster – Password Protect Pages and Content content-protector
Popularis Extra popularis-extra
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups ays-popup-box
Prague prague-plugins
Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages wplegalpages
PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes revisionary
Quick Restaurant Reservations quick-restaurant-reservations
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker quiz-master-next
Recipe Card Blocks Lite recipe-card-blocks-by-wpzoom
Recooty – Job Widget (Old Dashboard) recooty
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login custom-registration-form-builder-with-submission-manager
Revision Manager TMC revision-manager-tmc
rtMedia for WordPress, BuddyPress and bbPress buddypress-media
Rupantorpay rupantorpay
Saasplate Core saasplate-core
Schedula – Smart Appointment Booking schedula-smart-appointment-booking
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links update-urls
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization metasync
Sell BTC by Hayyat Apps — Cryptocurrency Exchange & Ordering sell-btc-by-hayyatapps
Sendy sendy
SEO Links Interlinking seo-links-interlinking
Serious Slider cryout-serious-slider
Shiprocket shiprocket
Simple Archive Generator simple-archive-generator
Simple calendar for Elementor simple-calendar-for-elementor
Simple Folio simple-folio
SlimStat Analytics wp-slimstat
Snow Monkey Forms snow-monkey-forms
Stop Spammers Classic stop-spammer-registrations-plugin
Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers sunshine-photo-cart
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent supportcandy
TableMaster for Elementor – Responsive Data Tables & Comparison Tables tablemaster-for-elementor
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent tablesome
Target Video Easy Publish brid-video-easy-publish
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot telsender
The Grid the-grid
Translate WordPress with ConveyThis – AI Multilingual Plugin conveythis-translate
Travelpayouts travelpayouts
TS Poll – Survey, Versus Poll, Image Poll, Video Poll poll-wp
UpsellWP – Upsell and Related Products Offers for WooCommerce checkout-upsell-and-order-bumps
Uroan Core uroan-core
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP userswp
VidShop – Shoppable Videos for WooCommerce vidshop-for-woocommerce
Vzaar Media Management vzaar-media-management
WebP Conversion webp-conversion
Widget Logic Visual widget-logic-visual
WiserReview Product Reviews for WooCommerce wiser-review
Woodly Core woodly-core
WP FullCalendar wp-fullcalendar
WP Google Ad Manager Plugin wp-google-ad-manager-plugin
WP Job Manager wp-job-manager
WP Recipe Maker wp-recipe-maker
WP Subscribe wp-subscribe
WP Sync for Notion – Notion to WordPress wp-sync-for-notion
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek ai-content-generation
WP-CORS wp-cors
WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor
WPBookit Pro - Appointment Booking Plugin for WordPress wpbookit-pro
Zita Site Library for Elementor zita-site-library
افزونه پیامک حرفه ای فراز اس ام اس farazsms


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Aardvark - Community, Membership, BuddyPress Theme aardvark
Business Roy business-roy
Capella | Restaurant WordPress capella
Fitness FSE fitness-fse
Gauge: Multi-Purpose Review Theme gauge
Grand Photography WordPress grandphotography
Hello FSE hello-fse
Jobster wpjobster
KindlyCare - Senior Care & Medical WordPress Theme kindlycare
Konte - Minimal & Modern WooCommerce Theme konte
Oxygen - WooCommerce WordPress Theme oxygen
Oyster - Photography WordPress Theme oyster
PhotoMe | Photography Portfolio WordPress photome
SOHO - Photography WordPress Theme soho


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jan 29, 2026
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Snow Monkey Forms [snow-monkey-forms]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jan 29, 2026
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jan 27, 2026
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Allmart [allmart-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Crete Core [crete-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Electio Core [electio-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 1, 2026
Affected Software
Gyan Elements [gyan-elements]
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Medinik Core [medinik-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
ModelTheme Addons for WPBakery and Elementor [modeltheme-addons-for-wpbakery]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Nestbyte Core [nestbyte-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Saasplate Core [saasplate-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Uroan Core [uroan-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Woodly Core [woodly-core]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Jobster [wpjobster]
Researcher
CVSS Rating
7.3 (High)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
New User Approve [new-user-approve]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
AhaChat Messenger Marketing [ahachat-messenger-marketing]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jan 28, 2026
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jan 27, 2026
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Membee Login [membees-member-login-widget]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jan 27, 2026
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jan 28, 2026
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Prague [prague-plugins]
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jan 29, 2026
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Feb 1, 2026
Affected Software
KiviCare – Clinic & Patient Management System (EHR) [kivicare-clinic-management-system]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Recipe Card Blocks Lite [recipe-card-blocks-by-wpzoom]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jan 26, 2026
Affected Software
Email Inquiry & Cart Options for WooCommerce [woocommerce-email-inquiry-cart-options]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
Gallery PhotoBlocks [photoblocks-grid-gallery]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 1, 2026
Affected Software
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Simple Folio [simple-folio]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Target Video Easy Publish [brid-video-easy-publish]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
WPBITS Addons For Elementor Page Builder [wpbits-addons-for-elementor]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Asynchronous Javascript [asynchronous-javascript]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
DesignThemes Core Features [designthemes-core-features]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
eDS Responsive Menu [eds-responsive-menu]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 29, 2026
Affected Software
ID Arrays [id-arrays]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
iSape [isape]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Mopinion Feedback Form [mopinion-feedback-form]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Prague [prague-plugins]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
SEO Links Interlinking [seo-links-interlinking]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Simple Archive Generator [simple-archive-generator]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
SlimStat Analytics [wp-slimstat]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Widget Logic Visual [widget-logic-visual]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Jobster [wpjobster]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Aardvark [aardvark-plugin]
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
AhaChat Messenger Marketing [ahachat-messenger-marketing]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
Broken Link Notifier [broken-link-notifier]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
CLP Varnish Cache [clp-varnish-cache]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 31, 2026
Affected Software
Conditional CAPTCHA [wp-conditional-captcha]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 26, 2026
Affected Software
WP FullCalendar [wp-fullcalendar]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
HAPPY – Helpdesk Support Ticket System [happy-helpdesk-support-ticket-system]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
hCaptcha for WP [hcaptcha-for-forms-and-more]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
JobBoard Job listing plugin [job-board-light]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Leadpages [leadpages]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
ModelTheme Framework [modeltheme-framework]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
Affected Software
NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
NextMove Lite – Thank You Page for WooCommerce [woo-thank-you-page-nextmove-lite]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 31, 2026
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 26, 2026
Affected Software
Quick Restaurant Reservations [quick-restaurant-reservations]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 1, 2026
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Rupantorpay [rupantorpay]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
Schedula – Smart Appointment Booking [schedula-smart-appointment-booking]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
Sendy [sendy]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Simple calendar for Elementor [simple-calendar-for-elementor]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
The Grid [the-grid]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Vzaar Media Management [vzaar-media-management]
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 26, 2026
Affected Software
WebP Conversion [webp-conversion]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
WP Job Manager [wp-job-manager]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jan 28, 2026
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
WP Google Ad Manager Plugin [wp-google-ad-manager-plugin]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Bitcoin Donate Button [bitcoin-donate-button]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 30, 2026
Affected Software
Business Roy [business-roy]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Change WP URL [change-wp-url]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 29, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Easy Replace Image [easy-replace-image]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
ELEX WordPress HelpDesk & Customer Ticketing System [elex-helpdesk-customer-support-ticket-system]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 30, 2026
Affected Software
Fitness FSE [fitness-fse]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Feb 1, 2026
Affected Software
Grand Photography WordPress [grandphotography]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 30, 2026
Affected Software
Hello FSE [hello-fse]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
imwptip [imwptip]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
JAMstack Deployments [wp-jamstack-deployments]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 26, 2026
Affected Software
Kama Thumbnail [kama-thumbnail]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
Affected Software
Mizan Demo Importer [mizan-demo-importer]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
Nelio Popups [nelio-popups]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
News Kit Addons For Elementor [news-kit-elementor-addons]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 29, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Popularis Extra [popularis-extra]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
WP Recipe Maker [wp-recipe-maker]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 27, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
Revision Manager TMC [revision-manager-tmc]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
Affected Software
Serious Slider [cryout-serious-slider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 29, 2026
Affected Software
Shiprocket [shiprocket]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 27, 2026
Affected Software
Stop Spammers Classic [stop-spammer-registrations-plugin]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 26, 2026
Affected Software
WP Subscribe [wp-subscribe]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 29, 2026
Affected Software
Travelpayouts [travelpayouts]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 26, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 30, 2026
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jan 28, 2026
Affected Software
WP-CORS [wp-cors]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jan 28, 2026
Affected Software
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments