> Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)
[AUTHOR: Chloe Chamberland]
[DATE: 23/07/2026 20:42]
[LANGUAGE: EN]
Last week, there were 75 vulnerabilities disclosed in WordPress Core, 68 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
Super Forms <= 6.3.313 – Unauthenticated Arbitrary File Upload via ‘data’ Parameter (datauristring / value)
WordPress Core < 7.0.2 – Unauthenticated Remote Code Execution
WAF-RULE-930 – Data redacted while we work with the vendor on a patch.
WAF-RULE-931 – Data redacted while we work with the vendor on a patch.
WAF-RULE-933 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status
Number of Vulnerabilities
Patched
71
Unpatched
4
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating
Number of Vulnerabilities
Medium Severity
48
High Severity
21
Critical Severity
6
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE
Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
14
Missing Authorization
13
Exposure of Sensitive Information to an Unauthorized Actor
4
Improper Privilege Management
4
Authorization Bypass Through User-Controlled Key
3
Cross-Site Request Forgery (CSRF)
3
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
3
Always-Incorrect Control Flow Implementation
1
Deserialization of Untrusted Data
1
Improper Input Validation
1
Improper Verification of Cryptographic Signature
1
Incorrect Privilege Assignment
1
Unrestricted Upload of File with Dangerous Type
1
Researchers That Contributed to WordPress Security Last Week
Researcher Name
Number of Vulnerabilities
Wordfence PRISM
25
Chu Thao Mai
3
h0xilo
2
dutafi
2
daroo
2
Kacper Rybczyński
2
skyv3il
2
Chirita Catalin-Andrei (CC99IE) (CC99IE)
2
Civitasmass
1
lucsob
1
Legion Hunter
1
Adam Kues
1
ickogz
1
sorawautsukushiii
1
Averon Averenkov
1
mikemyers
1
valent1
1
Salih Utku Telis
1
Niyht
1
Nabil Irawan
1
Nguyen Dinh Hai (HaiND)
1
Bao Le
1
Zbigniew Piotrak
1
Daniel Wade
1
anhcd05
1
theviper17y
1
Eason
1
Joshua Provoste
1
Supakiad S. (m3ez)
1
Romain Deperne (ang3L)
1
Jakub Herman
1
M.Fahad Khan
1
Yuvraj Tomar
1
F0DH1L
1
hhhai
1
swat
1
Tin Pham (TF1T)
1
Trong Pham (dtro)
1
haongo
1
FeDEX
1
AmonRa
1
MrProperCTF
1
yangsori
1
zaim
1
0xd4rk5id3
1
HieuPenguinnn
1
dodoh4t
1
이성민
1
lhking
1
Talal Nasraddeen
1
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name
Software Slug
Academy LMS
academy
Advance Product Search- Voice & Ajax Search for WooCommerce
th-advance-product-search
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit
aimogen-pro
Autopay dla WooCommerce
pay-wp
Avada (Fusion) Builder
fusion-builder
Booking for Appointments and Events Calendar – Amelia
ameliabooking
Breakdance
breakdance
Bricksforge
bricksforge
Catch Themes Demo Import
catch-themes-demo-import
ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form
chat-help
Digits: WordPress Mobile Number Signup and Login
digits
Download Monitor - WPForms Lock
dlm-wpforms-lock
Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ
easy-accordion-free
Easy Appointments
easy-appointments
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce
erp
Fense Proxy & VPN Blocker
fense-block-vpn-proxy
FoodBook Lite – Online Food Ordering System
foodbook-light-online-food-ordering-system
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database
form-vibes
GiveWP – Donation Plugin and Fundraising Platform
give
Gravity Forms
gravityforms
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
Kali Forms — Contact Form & Drag-and-Drop Builder
kali-forms
Kirki – Freeform Page Builder, Website Builder & Customizer
kirki
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
page-builder-add
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
List category posts
list-category-posts
Loco Translate
loco-translate
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
dc-woocommerce-multi-vendor
MxChat – AI Chatbot & Content Generation for WordPress
mxchat-basic
News Kit Addons For Elementor
news-kit-elementor-addons
Ninja Forms - Excel Export
ninja-forms-excel-export
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist
woocommerce-product-stock-alert
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
pCloud WP Backup
pcloud-wp-backup
Podlove Podcast Publisher
podlove-podcasting-plugin-for-wordpress
Premium Packages – Sell Digital Products Securely
wpdm-premium-packages
Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces
best-woocommerce-feed
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker
quiz-master-next
RPB Chessboard
rpb-chessboard
SAML Single Sign On – SSO Login
miniorange-saml-20-single-sign-on
SEO Booster
seo-booster
Smart Custom Fields
smart-custom-fields
Smart Slider 3
smart-slider-3
Sprout Clients – CRM and Lead Management
sprout-clients
SysBasics Customize My Account for WooCommerce – Live My Account Customizer
customize-my-account-for-woocommerce
The Cache Purger
the-cache-purger
Themify Builder
themify-builder
Tickera – Sell Tickets & Manage Events
tickera-event-ticketing-system
TrueBooker – Appointment Booking and Scheduler System
truebooker-appointment-booking
Tutor LMS – eLearning and online course solution
tutor
Ultimate Auction Pro
ultimate-woocommerce-auction-pro
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
uncanny-automator
W3SC Elementor to Zoho CRM
w3sc-elementor-to-zoho
WooCommerce Placetopay Gateway
https://github.com/placetopay/woocommerce-gateway-placetopay
WooCommerce Placetopay Gateway Belice
woocommerce-gateway-placetopay-belice
WooCommerce Placetopay Gateway Colombia
woocommerce-gateway-placetopay-colombia
WooCommerce Placetopay Gateway Ecuador
woocommerce-gateway-placetopay-ecuador
WooCommerce Placetopay Gateway Honduras
woocommerce-gateway-placetopay-honduras
WooCommerce Placetopay Gateway Uruguay
woocommerce-gateway-placetopay-uruguay
WP Bulk Delete
wp-bulk-delete
WP Customer Area
customer-area
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)
delicious-recipes
WP Hotel Booking
wp-hotel-booking
WP TripAdvisor Review Slider
wp-tripadvisor-review-slider
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
chatbot
wpForo Forum
wpforo
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
wpfunnels
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-15982
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit [aimogen-pro]
Researcher
Bao Le
More Details >
Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-14956
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Bricksforge [bricksforge]
Researcher
0xd4rk5id3
More Details >
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-13001
Patch Status
Patched
Published
Jul 14, 2026
Affected Software
Podlove Podcast Publisher [podlove-podcasting-plugin-for-wordpress]
Researcher
Talal Nasraddeen
More Details >
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-15013
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on]
Researcher
lhking
More Details >
TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-61951
Patch Status
Patched
Published
Jul 17, 2026
Affected Software
TrueBooker – Appointment Booking and Scheduler System [truebooker-appointment-booking]
Researcher
yangsori
More Details >
WordPress Core 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-63030
Patch Status
Patched
Published
Jul 17, 2026
Affected Software
WordPress [wordpress]
Researcher
Adam Kues
More Details >
Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-13741
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Digits: WordPress Mobile Number Signup and Login [digits]
Researcher
h0xilo
More Details >
Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-15005
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Loco Translate [loco-translate]
Researcher
mikemyers
More Details >
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-13352
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar]
Researchers
skyv3ilChirita Catalin-Andrei (CC99IE) (CC99IE)
More Details >
WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-15103
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell [wpfunnels]
Researcher
Wordfence PRISM
More Details >
Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-15008
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator]
Researcher
daroo
More Details >
Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-12753
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search]
Researcher
Wordfence PRISM
More Details >
Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-12997
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Gravity Forms [gravityforms]
Researcher
daroo
More Details >
LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-13765
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress]
Researcher
이성민
More Details >
Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-61949
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool]
Researcher
dodoh4t
More Details >
Premium Packages – Sell Digital Products Securely <= 6.2.0 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-61948
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Premium Packages – Sell Digital Products Securely [wpdm-premium-packages]
Researcher
HieuPenguinnn
More Details >
TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-61950
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
TrueBooker – Appointment Booking and Scheduler System [truebooker-appointment-booking]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
WordPress Core 6.8 - 7.0.1 - Unauthenticated SQL Injection via author__not_in Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-60137
Patch Status
Patched
Published
Jul 17, 2026
Affected Software
WordPress [wordpress]
Researchers
Tin Pham (TF1T)Trong Pham (dtro)haongo
More Details >
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-7543
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Breakdance [breakdance]
Researcher
h0xilo
More Details >
Download Monitor - WPForms Lock <= 1.0.4 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57427
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Download Monitor - WPForms Lock [dlm-wpforms-lock]
Researcher
dutafi
More Details >
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-61947
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database [form-vibes]
Researcher
hhhai
More Details >
Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-15395
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Kali Forms — Contact Form & Drag-and-Drop Builder [kali-forms]
Researcher
Wordfence PRISM
More Details >
Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-61944
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool]
Researcher
ickogz
More Details >
RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-13042
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
RPB Chessboard [rpb-chessboard]
Researcher
theviper17y
More Details >
Sprout Clients – CRM and Lead Management <= 3.2.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57428
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Sprout Clients – CRM and Lead Management [sprout-clients]
Researcher
dutafi
More Details >
Ultimate Auction Pro <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-4110
Patch Status
Unpatched
Published
Jul 13, 2026
Affected Software
Ultimate Auction Pro [ultimate-woocommerce-auction-pro]
Researcher
Kacper Rybczyński
More Details >
Ultimate Auction Pro <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-4259
Patch Status
Unpatched
Published
Jul 13, 2026
Affected Software
Ultimate Auction Pro [ultimate-woocommerce-auction-pro]
Researcher
Kacper Rybczyński
More Details >
MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-12941
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions [dc-woocommerce-multi-vendor]
Researcher
Wordfence PRISM
More Details >
pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-14503
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
pCloud WP Backup [pcloud-wp-backup]
Researcher
Civitasmass
More Details >
Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-13767
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker [quiz-master-next]
Researcher
Wordfence PRISM
More Details >
Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-13754
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system]
Researcher
Wordfence PRISM
More Details >
Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-15022
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Tutor LMS – eLearning and online course solution [tutor]
Researcher
Supakiad S. (m3ez)
More Details >
Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-12536
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
Avada (Fusion) Builder [fusion-builder]
Researcher
Zbigniew Piotrak
More Details >
ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-15759
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form [chat-help]
Researcher
Wordfence PRISM
More Details >
Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-15652
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ [easy-accordion-free]
Researcher
Wordfence PRISM
More Details >
GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-14987
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
GiveWP – Donation Plugin and Fundraising Platform [give]
Researchers
FeDEXskyv3ilChirita Catalin-Andrei (CC99IE) (CC99IE)AmonRaMrProperCTF
More Details >
News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-11390
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
News Kit Addons For Elementor [news-kit-elementor-addons]
Researcher
Romain Deperne (ang3L)
More Details >
Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-15161
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Ninja Forms - Excel Export [ninja-forms-excel-export]
Researcher
Chu Thao Mai
More Details >
Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-2594
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Smart Custom Fields [smart-custom-fields]
Researcher
lucsob
More Details >
Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-13755
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system]
Researcher
Wordfence PRISM
More Details >
WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-7640
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
WP Customer Area [customer-area]
Researcher
zaim
More Details >
WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-15099
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes]
Researcher
Wordfence PRISM
More Details >
wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-15021
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
wpForo Forum [wpforo]
Researcher
valent1
More Details >
Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-15306
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces [best-woocommerce-feed]
Researcher
Wordfence PRISM
More Details >
WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-11324
Patch Status
Unpatched
Published
Jul 16, 2026
Affected Software
WooCommerce Placetopay Gateway [https://github.com/placetopay/woocommerce-gateway-placetopay]WooCommerce Placetopay Gateway Belice [woocommerce-gateway-placetopay-belice]WooCommerce Placetopay Gateway Colombia [woocommerce-gateway-placetopay-colombia]WooCommerce Placetopay Gateway Ecuador [woocommerce-gateway-placetopay-ecuador]WooCommerce Placetopay Gateway Honduras [woocommerce-gateway-placetopay-honduras]WooCommerce Placetopay Gateway Uruguay [woocommerce-gateway-placetopay-uruguay]
Researcher
Joshua Provoste
More Details >
WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-15094
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
WP Hotel Booking [wp-hotel-booking]
Researcher
Wordfence PRISM
More Details >
Autopay dla WooCommerce <= 2.2.27 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57425
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Autopay dla WooCommerce [pay-wp]
Researcher
Averon Averenkov
More Details >
Easy Appointments <= 3.12.27 - Unauthenticated Insecure Direct Object Reference
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-61946
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Easy Appointments [easy-appointments]
Researcher
Daniel Wade
More Details >
Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-8616
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Fense Proxy & VPN Blocker [fense-block-vpn-proxy]
Researcher
Legion Hunter
More Details >
FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-11802
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
FoodBook Lite – Online Food Ordering System [foodbook-light-online-food-ordering-system]
Researcher
Eason
More Details >
Premium Packages – Sell Digital Products Securely <= 6.2.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-61943
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Premium Packages – Sell Digital Products Securely [wpdm-premium-packages]
Researcher
Nabil Irawan
More Details >
WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-15106
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot]
Researcher
Wordfence PRISM
More Details >
Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-14782
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Booking for Appointments and Events Calendar – Amelia [ameliabooking]
Researcher
F0DH1L
More Details >
Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-15457
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki]
Researcher
Wordfence PRISM
More Details >
SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-15445
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
SEO Booster [seo-booster]
Researcher
Wordfence PRISM
More Details >
SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-15458
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
SEO Booster [seo-booster]
Researcher
Wordfence PRISM
More Details >
WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-15727
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
WP Bulk Delete [wp-bulk-delete]
Researcher
Wordfence PRISM
More Details >
WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-15651
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
WP TripAdvisor Review Slider [wp-tripadvisor-review-slider]
Researcher
Wordfence PRISM
More Details >
MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-13005
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
MxChat – AI Chatbot & Content Generation for WordPress [mxchat-basic]
Researcher
Wordfence PRISM
More Details >
SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-15324
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
SysBasics Customize My Account for WooCommerce – Live My Account Customizer [customize-my-account-for-woocommerce]
Researcher
Wordfence PRISM
More Details >
Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9341
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
Academy LMS [academy]
Researcher
sorawautsukushiii
More Details >
Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15336
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Catch Themes Demo Import [catch-themes-demo-import]
Researcher
Wordfence PRISM
More Details >
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.5 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-59522
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce [erp]
Researcher(s): Unknown
More Details >
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15349
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce [erp]
Researcher
Wordfence PRISM
More Details >
HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9656
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin]
Researcher
anhcd05
More Details >
Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12409
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add]
Researcher
M.Fahad Khan
More Details >
List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12434
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
List category posts [list-category-posts]
Researchers
Salih Utku TelisNiyht
More Details >
Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15159
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Ninja Forms - Excel Export [ninja-forms-excel-export]
Researcher
Chu Thao Mai
More Details >
Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15160
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Ninja Forms - Excel Export [ninja-forms-excel-export]
Researcher
Chu Thao Mai
More Details >
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist <= 3.0.6 - Authenticated (Subscriber+) Sensitive Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-61945
Patch Status
Patched
Published
Jul 16, 2026
Affected Software
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist [woocommerce-product-stock-alert]
Researcher
Jakub Herman
More Details >
Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12385
Patch Status
Patched
Published
Jul 13, 2026
Affected Software
Smart Slider 3 [smart-slider-3]
Researcher
Yuvraj Tomar
More Details >
The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15350
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
The Cache Purger [the-cache-purger]
Researcher
Wordfence PRISM
More Details >
Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15407
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
Themify Builder [themify-builder]
Researcher
Wordfence PRISM
More Details >
W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9734
Patch Status
Unpatched
Published
Jul 17, 2026
Affected Software
W3SC Elementor to Zoho CRM [w3sc-elementor-to-zoho]
Researcher
swat
More Details >
WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-15610
Patch Status
Patched
Published
Jul 15, 2026
Affected Software
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot]
Researcher
Wordfence PRISM
More Details >
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026) appeared first on Wordfence.