Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wordfence says it added 319 vulnerabilities affecting 222 WordPress plugins to its Intelligence Vulnerability Database for September 21–27, 2026, with contributions from 156 vulnerability researchers. Those totals are a reason to check your site’s installed plugins—not evidence that every site is affected. Match each installed plugin and version against the report’s individual entries, then follow the plugin maintainer’s guidance for any confirmed match.

The report was published October 2, 2026. The findings below are attributed to Wordfence as reproduced in a syndicated copy; confirm individual entries and current patch status against Wordfence’s canonical report or vulnerability records before taking remediation action.

What the report covers

Wordfence’s weekly roundup covers disclosures during September 21–27, 2026. Its aggregate summary reports 319 vulnerabilities affecting 222 plugins and contributions from 156 researchers. It does not report themes in that aggregate summary. The individual listings include vulnerability names, CVE identifiers where assigned, CVSS scores where stated, affected plugin and version information, patch status, publication dates, and researcher attribution.

The examples below illustrate the types of issues in the roundup; they are not a complete inventory of its 319 entries. A plugin category or name alone does not establish that a particular installation is vulnerable: the installed version must match the affected-version details in the relevant entry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Notable examples in the reproduced report

Plugin or product Finding described Severity or access requirement stated Patch status in the copy
Meta Box AIO and standalone Meta Box extensions CVE-2026-13355: unauthenticated privilege escalation to administrator CVSS 9.8, Critical Marked patched; exact affected and fixed versions are not stated in the reproduced summary.
MasterStudy LMS Local file inclusion, alongside additional authorization-related entries Authenticated Contributor+ access is stated for the local file inclusion Not stated in the reproduced summary.
Modula Image Gallery Missing authorization that can expose private gallery images Not stated in the reproduced summary Not stated in the reproduced summary.
Bookly Missing authorization and an unauthenticated authorization bypass involving verification-code parameter type juggling Unauthenticated is stated for the bypass; the access requirement for the other finding is not stated in the reproduced summary Not stated in the reproduced summary.

The roundup also includes findings involving membership and payment plugins, event scheduling, backups, SVG uploads, image handling, and WooCommerce. These broad categories are not enough to identify exposure; use each entry’s exact plugin name and affected versions.

How to check whether your WordPress site matches an entry

  1. Inventory installed plugins. In the WordPress dashboard, open Plugins > Installed Plugins. Record each plugin’s exact name and installed version, including plugins that are inactive. If you manage multiple sites, make a separate inventory for each one.
  2. Compare exact names and versions. For each possible match, check the full vulnerability entry—not just its title—for the affected product and version range. A listing for a plugin family or standalone extension may not apply to every product or release from that developer.
  3. Check the entry’s status and details. Look for whether a fix is available, which versions are affected, what an attacker must be able to do, and what the reported impact is. Confirm those details and the current patch state in Wordfence’s canonical report or vulnerability record; the syndicated copy’s summary does not establish exact affected or fixed versions for the examples above.
  4. Apply the maintainer’s fix when your version is affected. Follow the plugin maintainer’s update instructions, and make a backup before changing production software. Where your normal change process allows, test the update on a staging site and check the affected feature afterward.
  5. If no fix is identified, reduce exposure. Consult the maintainer’s current guidance. If the plugin is not essential, disabling it may be a temporary risk-reduction measure; removal is preferable when it is no longer needed. Do not assume that a firewall or a report’s general status label substitutes for a software fix.
  6. Recheck after action. Verify the installed version after updating or disabling the plugin, and review the entry again for changes to patch status. Keep the site’s backup and update process in place for future disclosures.

How to prioritize confirmed matches

For each confirmed version match, use the vulnerability details to judge urgency rather than relying on the weekly roundup’s inclusion alone. Consider whether a fixed version is available, the stated severity, the access an attacker needs, and the potential impact. An unauthenticated path or privilege escalation can warrant prompt attention, but a CVSS score or appearance in a roundup does not by itself show that an issue is being actively exploited or that your site has been compromised.

Wordfence’s reproduced copy says its Intelligence interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are free for personal and commercial use. It also says Wordfence Premium, Care, and Response customers received real-time enhanced firewall protection for covered vulnerabilities. These are distinct offerings: a firewall may be part of a response strategy, while matching and updating affected software remains a site-specific task. Check Wordfence’s current service details before relying on a particular feature or coverage.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this report does—and does not—tell a site owner

The roundup is an alert and index of reported plugin vulnerabilities, not an inspection of your WordPress installation. It does not show which plugins your site runs, whether your installed versions fall within an affected range, or whether an attacker accessed your site. The available reproduction also does not independently establish the current status of every listed issue. Use the canonical Wordfence entry and the plugin maintainer’s guidance to make version-specific decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.