Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities Wordfence

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)

The report details a critical, unauthenticated remote code execution vulnerability in WordPress Core (CVE-2026-13001, CVSS 9.8) affecting versions prior to 7.0.2, which has been patched in WordPress Core 7.0.2. It also highlights an unauthenticated arbitrary file upload vulnerability in the Super Forms plugin (CVE-2026-14956, CVSS 9.8) for versions up to and including 6.3.313. Wordfence Premium, Care, and Response customers received immediate firewall rule protection, while free version users receive the rules after a 30-day delay.
Read Full Article →

Last week, there were 75 vulnerabilities disclosed in WordPress Core, 68 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , webhook integration , and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium , Care , and Response customers last week: Super Forms <= 6.3.313 – Unauthenticated Arbitrary File Upload via ‘data’ Parameter (datauristring / value) WordPress Core < 7.0.2 – Unauthenticated Remote Code Execution WAF-RULE-930 – Data redacted while we work with the vendor on a patch. WAF-RULE-931 – Data redacted while we work with the vendor on a patch. WAF-RULE-933 – Data redacted while we work with the vendor on a patch. Wordfence Premium , Care , and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 71 Unpatched 4 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Medium Severity 48 High Severity 21 Critical Severity 6 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 25 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 14 Missing Authorization 13 Exposure of Sensitive Information to an Unauthorized Actor 4 Improper Privilege Management 4 Authorization Bypass Through User-Controlled Key 3 Cross-Site Request Forgery (CSRF) 3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3 Always-Incorrect Control Flow Implementation 1 Deserialization of Untrusted Data 1 Improper Input Validation 1 Improper Verification of Cryptographic Signature 1 Incorrect Privilege Assignment 1 Unrestricted Upload of File with Dangerous Type 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Wordfence PRISM 25 Chu Thao Mai 3 h0xilo 2 dutafi 2 daroo 2 Kacper Rybczyński 2 skyv3il 2 Chirita Catalin-Andrei (CC99IE) (CC99IE) 2 Civitasmass 1 lucsob 1 Legion Hunter 1 Adam Kues 1 ickogz 1 sorawautsukushiii 1 Averon Averenkov 1 mikemyers 1 valent1 1 Salih Utku Telis 1 Niyht 1 Nabil Irawan 1 Nguyen Dinh Hai (HaiND) 1 Bao Le 1 Zbigniew Piotrak 1 Daniel Wade 1 anhcd05 1 theviper17y 1 Eason 1 Joshua Provoste 1 Supakiad S. (m3ez) 1 Romain Deperne (ang3L) 1 Jakub Herman 1 M.Fahad Khan 1 Yuvraj Tomar 1 F0DH1L 1 hhhai 1 swat 1 Tin Pham (TF1T) 1 Trong Pham (dtro) 1 haongo 1 FeDEX 1 AmonRa 1 MrProperCTF 1 yangsori 1 zaim 1 0xd4rk5id3 1 HieuPenguinnn 1 dodoh4t 1 이성민 1 lhking 1 Talal Nasraddeen 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug Academy LMS academy Advance Product Search- Voice & Ajax Search for WooCommerce th-advance-product-search Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit aimogen-pro Autopay dla WooCommerce pay-wp Avada (Fusion) Builder fusion-builder Booking for Appointments and Events Calendar – Amelia ameliabooking Breakdance breakdance Bricksforge bricksforge Catch Themes Demo Import catch-themes-demo-import ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form chat-help Digits: WordPress Mobile Number Signup and Login digits Download Monitor - WPForms Lock dlm-wpforms-lock Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ easy-accordion-free Easy Appointments easy-appointments ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce erp Fense Proxy & VPN Blocker fense-block-vpn-proxy FoodBook Lite – Online Food Ordering System foodbook-light-online-food-ordering-system Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database form-vibes GiveWP – Donation Plugin and Fundraising Platform give Gravity Forms gravityforms HubSpot All-In-One Marketing – Forms, Popups, Live Chat leadin Kali Forms — Contact Form & Drag-and-Drop Builder kali-forms Kirki – Freeform Page Builder, Website Builder & Customizer kirki Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages page-builder-add LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress List category posts list-category-posts Loco Translate loco-translate MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions dc-woocommerce-multi-vendor MxChat – AI Chatbot & Content Generation for WordPress mxchat-basic News Kit Addons For Elementor news-kit-elementor-addons Ninja Forms - Excel Export ninja-forms-excel-export Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist woocommerce-product-stock-alert Online Scheduling and Appointment Booking System – Bookly bookly-responsive-appointment-booking-tool Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress wp-user-avatar pCloud WP Backup pcloud-wp-backup Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress Premium Packages – Sell Digital Products Securely wpdm-premium-packages Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces best-woocommerce-feed Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker quiz-master-next RPB Chessboard rpb-chessboard SAML Single Sign On – SSO Login miniorange-saml-20-single-sign-on SEO Booster seo-booster Smart Custom Fields smart-custom-fields Smart Slider 3 smart-slider-3 Sprout Clients – CRM and Lead Management sprout-clients SysBasics Customize My Account for WooCommerce – Live My Account Customizer customize-my-account-for-woocommerce The Cache Purger the-cache-purger Themify Builder themify-builder Tickera – Sell Tickets & Manage Events tickera-event-ticketing-system TrueBooker – Appointment Booking and Scheduler System truebooker-appointment-booking Tutor LMS – eLearning and online course solution tutor Ultimate Auction Pro ultimate-woocommerce-auction-pro Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator W3SC Elementor to Zoho CRM w3sc-elementor-to-zoho WooCommerce Placetopay Gateway https://github.com/placetopay/woocommerce-gateway-placetopay WooCommerce Placetopay Gateway Belice woocommerce-gateway-placetopay-belice WooCommerce Placetopay Gateway Colombia woocommerce-gateway-placetopay-colombia WooCommerce Placetopay Gateway Ecuador woocommerce-gateway-placetopay-ecuador WooCommerce Placetopay Gateway Honduras woocommerce-gateway-placetopay-honduras WooCommerce Placetopay Gateway Uruguay woocommerce-gateway-placetopay-uruguay WP Bulk Delete wp-bulk-delete WP Customer Area customer-area WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) delicious-recipes WP Hotel Booking wp-hotel-booking WP TripAdvisor Review Slider wp-tripadvisor-review-slider WPBot – AI ChatBot for Live Support, Lead Generation, AI Services chatbot wpForo Forum wpforo WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell wpfunnels Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function' 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15982 Patch Status Patched Published Jul 13, 2026 Affected Software Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit [aimogen-pro] Researcher Bao Le More Details > Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-14956 Patch Status Patched Published Jul 16, 2026 Affected Software Bricksforge [bricksforge] Researcher 0xd4rk5id3 More Details > Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-13001 Patch Status Patched Published Jul 14, 2026 Affected Software Podlove Podcast Publisher [podlove-podcasting-plugin-for-wordpress] Researcher Talal Nasraddeen More Details > SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15013 Patch Status Patched Published Jul 15, 2026 Affected Software SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] Researcher lhking More Details > TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-61951 Patch Status Patched Published Jul 17, 2026 Affected Software TrueBooker – Appointment Booking and Scheduler System [truebooker-appointment-booking] Researcher yangsori More Details > WordPress Core 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-63030 Patch Status Patched Published Jul 17, 2026 Affected Software WordPress [wordpress] Researcher Adam Kues More Details > Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-13741 Patch Status Patched Published Jul 15, 2026 Affected Software Digits: WordPress Mobile Number Signup and Login [digits] Researcher h0xilo More Details > Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-15005 Patch Status Patched Published Jul 15, 2026 Affected Software Loco Translate [loco-translate] Researcher mikemyers More Details > Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-13352 Patch Status Patched Published Jul 16, 2026 Affected Software Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar] Researchers skyv3il Chirita Catalin-Andrei (CC99IE) (CC99IE) More Details > WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-15103 Patch Status Patched Published Jul 15, 2026 Affected Software WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell [wpfunnels] Researcher Wordfence PRISM More Details > Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-15008 Patch Status Patched Published Jul 15, 2026 Affected Software Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] Researcher daroo More Details > Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-12753 Patch Status Patched Published Jul 15, 2026 Affected Software Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] Researcher Wordfence PRISM More Details > Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-12997 Patch Status Patched Published Jul 15, 2026 Affected Software Gravity Forms [gravityforms] Researcher daroo More Details > LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-13765 Patch Status Patched Published Jul 16, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researcher 이성민 More Details > Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-61949 Patch Status Patched Published Jul 16, 2026 Affected Software Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] Researcher dodoh4t More Details > Premium Packages – Sell Digital Products Securely <= 6.2.0 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-61948 Patch Status Patched Published Jul 16, 2026 Affected Software Premium Packages – Sell Digital Products Securely [wpdm-premium-packages] Researcher HieuPenguinnn More Details > TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-61950 Patch Status Patched Published Jul 16, 2026 Affected Software TrueBooker – Appointment Booking and Scheduler System [truebooker-appointment-booking] Researcher Nguyen Dinh Hai (HaiND) More Details > WordPress Core 6.8 - 7.0.1 - Unauthenticated SQL Injection via author__not_in Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-60137 Patch Status Patched Published Jul 17, 2026 Affected Software WordPress [wordpress] Researchers Tin Pham (TF1T) Trong Pham (dtro) haongo More Details > Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-7543 Patch Status Patched Published Jul 15, 2026 Affected Software Breakdance [breakdance] Researcher h0xilo More Details > Download Monitor - WPForms Lock <= 1.0.4 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57427 Patch Status Patched Published Jul 16, 2026 Affected Software Download Monitor - WPForms Lock [dlm-wpforms-lock] Researcher dutafi More Details > Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-61947 Patch Status Patched Published Jul 16, 2026 Affected Software Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database [form-vibes] Researcher hhhai More Details > Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-15395 Patch Status Patched Published Jul 16, 2026 Affected Software Kali Forms — Contact Form & Drag-and-Drop Builder [kali-forms] Researcher Wordfence PRISM More Details > Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-61944 Patch Status Patched Published Jul 16, 2026 Affected Software Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] Researcher ickogz More Details > RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-13042 Patch Status Patched Published Jul 15, 2026 Affected Software RPB Chessboard [rpb-chessboard] Researcher theviper17y More Details > Sprout Clients – CRM and Lead Management <= 3.2.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57428 Patch Status Patched Published Jul 16, 2026 Affected Software Sprout Clients – CRM and Lead Management [sprout-clients] Researcher dutafi More Details > Ultimate Auction Pro <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-4110 Patch Status Unpatched Published Jul 13, 2026 Affected Software Ultimate Auction Pro [ultimate-woocommerce-auction-pro] Researcher Kacper Rybczyński More Details > Ultimate Auction Pro <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-4259 Patch Status Unpatched Published Jul 13, 2026 Affected Software Ultimate Auction Pro [ultimate-woocommerce-auction-pro] Researcher Kacper Rybczyński More Details > MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-12941 Patch Status Patched Published Jul 15, 2026 Affected Software MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions [dc-woocommerce-multi-vendor] Researcher Wordfence PRISM More Details > pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-14503 Patch Status Patched Published Jul 16, 2026 Affected Software pCloud WP Backup [pcloud-wp-backup] Researcher Civitasmass More Details > Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13767 Patch Status Patched Published Jul 15, 2026 Affected Software Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker [quiz-master-next] Researcher Wordfence PRISM More Details > Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13754 Patch Status Patched Published Jul 15, 2026 Affected Software Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system] Researcher Wordfence PRISM More Details > Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-15022 Patch Status Patched Published Jul 15, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher Supakiad S. (m3ez) More Details > Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12536 Patch Status Patched Published Jul 13, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher Zbigniew Piotrak More Details > ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15759 Patch Status Patched Published Jul 16, 2026 Affected Software ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form [chat-help] Researcher Wordfence PRISM More Details > Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15652 Patch Status Patched Published Jul 15, 2026 Affected Software Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ [easy-accordion-free] Researcher Wordfence PRISM More Details > GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-14987 Patch Status Patched Published Jul 15, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researchers FeDEX skyv3il Chirita Catalin-Andrei (CC99IE) (CC99IE) AmonRa MrProperCTF More Details > News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11390 Patch Status Patched Published Jul 13, 2026 Affected Software News Kit Addons For Elementor [news-kit-elementor-addons] Researcher Romain Deperne (ang3L) More Details > Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15161 Patch Status Patched Published Jul 16, 2026 Affected Software Ninja Forms - Excel Export [ninja-forms-excel-export] Researcher Chu Thao Mai More Details > Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2594 Patch Status Patched Published Jul 16, 2026 Affected Software Smart Custom Fields [smart-custom-fields] Researcher lucsob More Details > Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13755 Patch Status Patched Published Jul 15, 2026 Affected Software Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system] Researcher Wordfence PRISM More Details > WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-7640 Patch Status Patched Published Jul 13, 2026 Affected Software WP Customer Area [customer-area] Researcher zaim More Details > WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15099 Patch Status Patched Published Jul 15, 2026 Affected Software WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] Researcher Wordfence PRISM More Details > wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15021 Patch Status Patched Published Jul 15, 2026 Affected Software wpForo Forum [wpforo] Researcher valent1 More Details > Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-15306 Patch Status Patched Published Jul 15, 2026 Affected Software Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces [best-woocommerce-feed] Researcher Wordfence PRISM More Details > WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url' 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-11324 Patch Status Unpatched Published Jul 16, 2026 Affected Software WooCommerce Placetopay Gateway [https://github.com/placetopay/woocommerce-gateway-placetopay] WooCommerce Placetopay Gateway Belice [woocommerce-gateway-placetopay-belice] WooCommerce Placetopay Gateway Colombia [woocommerce-gateway-placetopay-colombia] WooCommerce Placetopay Gateway Ecuador [woocommerce-gateway-placetopay-ecuador] WooCommerce Placetopay Gateway Honduras [woocommerce-gateway-placetopay-honduras] WooCommerce Placetopay Gateway Uruguay [woocommerce-gateway-placetopay-uruguay] Researcher Joshua Provoste More Details > WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-15094 Patch Status Patched Published Jul 16, 2026 Affected Software WP Hotel Booking [wp-hotel-booking] Researcher Wordfence PRISM More Details > Autopay dla WooCommerce <= 2.2.27 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57425 Patch Status Patched Published Jul 16, 2026 Affected Software Autopay dla WooCommerce [pay-wp] Researcher Averon Averenkov More Details > Easy Appointments <= 3.12.27 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-61946 Patch Status Patched Published Jul 16, 2026 Affected Software Easy Appointments [easy-appointments] Researcher Daniel Wade More Details > Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8616 Patch Status Patched Published Jul 16, 2026 Affected Software Fense Proxy & VPN Blocker [fense-block-vpn-proxy] Researcher Legion Hunter More Details > FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-11802 Patch Status Patched Published Jul 13, 2026 Affected Software FoodBook Lite – Online Food Ordering System [foodbook-light-online-food-ordering-system] Researcher Eason More Details > Premium Packages – Sell Digital Products Securely <= 6.2.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-61943 Patch Status Patched Published Jul 16, 2026 Affected Software Premium Packages – Sell Digital Products Securely [wpdm-premium-packages] Researcher Nabil Irawan More Details > WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-15106 Patch Status Patched Published Jul 15, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot] Researcher Wordfence PRISM More Details > Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-14782 Patch Status Patched Published Jul 16, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher F0DH1L More Details > Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15457 Patch Status Patched Published Jul 16, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Wordfence PRISM More Details > SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15445 Patch Status Patched Published Jul 15, 2026 Affected Software SEO Booster [seo-booster] Researcher Wordfence PRISM More Details > SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15458 Patch Status Patched Published Jul 15, 2026 Affected Software SEO Booster [seo-booster] Researcher Wordfence PRISM More Details > WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15727 Patch Status Patched Published Jul 15, 2026 Affected Software WP Bulk Delete [wp-bulk-delete] Researcher Wordfence PRISM More Details > WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15651 Patch Status Patched Published Jul 15, 2026 Affected Software WP TripAdvisor Review Slider [wp-tripadvisor-review-slider] Researcher Wordfence PRISM More Details > MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-13005 Patch Status Patched Published Jul 15, 2026 Affected Software MxChat – AI Chatbot & Content Generation for WordPress [mxchat-basic] Researcher Wordfence PRISM More Details > SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-15324 Patch Status Patched Published Jul 15, 2026 Affected Software SysBasics Customize My Account for WooCommerce – Live My Account Customizer [customize-my-account-for-woocommerce] Researcher Wordfence PRISM More Details > Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9341 Patch Status Patched Published Jul 13, 2026 Affected Software Academy LMS [academy] Researcher sorawautsukushiii More Details > Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15336 Patch Status Patched Published Jul 15, 2026 Affected Software Catch Themes Demo Import [catch-themes-demo-import] Researcher Wordfence PRISM More Details > ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.5 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-59522 Patch Status Patched Published Jul 15, 2026 Affected Software ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce [erp] Researcher(s): Unknown More Details > ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15349 Patch Status Patched Published Jul 16, 2026 Affected Software ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce [erp] Researcher Wordfence PRISM More Details > HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9656 Patch Status Patched Published Jul 16, 2026 Affected Software HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] Researcher anhcd05 More Details > Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12409 Patch Status Patched Published Jul 15, 2026 Affected Software Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] Researcher M.Fahad Khan More Details > List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12434 Patch Status Patched Published Jul 15, 2026 Affected Software List category posts [list-category-posts] Researchers Salih Utku Telis Niyht More Details > Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15159 Patch Status Patched Published Jul 16, 2026 Affected Software Ninja Forms - Excel Export [ninja-forms-excel-export] Researcher Chu Thao Mai More Details > Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15160 Patch Status Patched Published Jul 16, 2026 Affected Software Ninja Forms - Excel Export [ninja-forms-excel-export] Researcher Chu Thao Mai More Details > Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist <= 3.0.6 - Authenticated (Subscriber+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-61945 Patch Status Patched Published Jul 16, 2026 Affected Software Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist [woocommerce-product-stock-alert] Researcher Jakub Herman More Details > Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12385 Patch Status Patched Published Jul 13, 2026 Affected Software Smart Slider 3 [smart-slider-3] Researcher Yuvraj Tomar More Details > The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15350 Patch Status Patched Published Jul 15, 2026 Affected Software The Cache Purger [the-cache-purger] Researcher Wordfence PRISM More Details > Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15407 Patch Status Patched Published Jul 15, 2026 Affected Software Themify Builder [themify-builder] Researcher Wordfence PRISM More Details > W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9734 Patch Status Unpatched Published Jul 17, 2026 Affected Software W3SC Elementor to Zoho CRM [w3sc-elementor-to-zoho] Researcher swat More Details > WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15610 Patch Status Patched Published Jul 15, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot] Researcher Wordfence PRISM More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026) appeared first on Wordfence .

Share this article