CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5809

As cited

Copy frozen at (site build).

vulnerabilities

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)

Between August 24 and August 30, 2026, Wordfence documented 246 vulnerabilities across 174 WordPress plugins and 5 themes, with 234 patches released and 12 remaining unpatched. Critical severity issues dominated the week, including 18 critical flaws and 73 high-severity vulnerabilities, with cross-site scripting and missing authorization representing the most common vulnerability types.

Why it matters: WordPress site operators must immediately patch critical remote code execution vulnerabilities in Avada, Kirki, ManageWP Worker, and other widely used plugins to prevent site compromise; the 30-day delay for free Wordfence users to receive firewall protection creates a window of exposure for unpatched sites.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)

Between August 24 and August 30, 2026, Wordfence documented 246 vulnerabilities across 174 WordPress plugins and 5 themes, with 234 patches released and 12 remaining unpatched. Critical severity issues dominated the week, including 18 critical flaws and 73 high-severity vulnerabilities, with cross-site scripting and missing authorization representing the most common vulnerability types.

Why it matters: WordPress site operators must immediately patch critical remote code execution vulnerabilities in Avada, Kirki, ManageWP Worker, and other widely used plugins to prevent site compromise; the 30-day delay for free Wordfence users to receive firewall protection creates a window of exposure for unpatched sites.

CVEsCVE-2025-9878CVE-2026-10627CVE-2026-10630CVE-2026-12513CVE-2026-12514CVE-2026-12561CVE-2026-13172CVE-2026-13176CVE-2026-13404CVE-2026-13406CVE-2026-13414CVE-2026-13415CVE-2026-13416CVE-2026-13598CVE-2026-13611CVE-2026-13736CVE-2026-14212CVE-2026-14216CVE-2026-14280CVE-2026-14307CVE-2026-14325CVE-2026-14494CVE-2026-14550CVE-2026-14558CVE-2026-14567CVE-2026-14601CVE-2026-14835CVE-2026-15023CVE-2026-15046CVE-2026-15150CVE-2026-15206CVE-2026-15369CVE-2026-15798CVE-2026-15980CVE-2026-15985CVE-2026-15990CVE-2026-16567CVE-2026-16568CVE-2026-16569CVE-2026-16575CVE-2026-16576CVE-2026-16577CVE-2026-16600CVE-2026-16601CVE-2026-16612CVE-2026-16654CVE-2026-16747CVE-2026-16759CVE-2026-16959CVE-2026-16962CVE-2026-16984CVE-2026-16986CVE-2026-17089CVE-2026-17520CVE-2026-17522CVE-2026-17559CVE-2026-17565CVE-2026-17587CVE-2026-18052CVE-2026-18080CVE-2026-18100CVE-2026-18233CVE-2026-18234CVE-2026-18323CVE-2026-18324CVE-2026-18328CVE-2026-18331CVE-2026-18431CVE-2026-18512CVE-2026-18547CVE-2026-18781CVE-2026-18884CVE-2026-18978CVE-2026-18983CVE-2026-19085CVE-2026-19093CVE-2026-19094CVE-2026-19220CVE-2026-19221CVE-2026-19222CVE-2026-19223CVE-2026-19225CVE-2026-19226CVE-2026-19423CVE-2026-19430CVE-2026-19435CVE-2026-19454CVE-2026-19632CVE-2026-19715CVE-2026-19718CVE-2026-19722CVE-2026-19760CVE-2026-19801CVE-2026-19848CVE-2026-19892CVE-2026-19943CVE-2026-19949CVE-2026-2388CVE-2026-27330CVE-2026-3002CVE-2026-3129CVE-2026-3235CVE-2026-32479CVE-2026-32550CVE-2026-32564CVE-2026-32566CVE-2026-3423CVE-2026-4246CVE-2026-5092CVE-2026-5096CVE-2026-5097CVE-2026-5510CVE-2026-5934CVE-2026-6128CVE-2026-6176CVE-2026-6178CVE-2026-6286CVE-2026-74851CVE-2026-74928CVE-2026-74929CVE-2026-74930CVE-2026-75019CVE-2026-75796CVE-2026-75797CVE-2026-75798CVE-2026-75807CVE-2026-75908CVE-2026-75930CVE-2026-75971CVE-2026-75977CVE-2026-75982CVE-2026-76053CVE-2026-76063CVE-2026-76128CVE-2026-76546CVE-2026-76547CVE-2026-76549CVE-2026-76581CVE-2026-76586CVE-2026-76789CVE-2026-77002CVE-2026-77003CVE-2026-77007CVE-2026-77008CVE-2026-77012CVE-2026-77016CVE-2026-77017CVE-2026-77018CVE-2026-77365CVE-2026-77693CVE-2026-77694CVE-2026-77695CVE-2026-77701CVE-2026-77704CVE-2026-77754CVE-2026-77757CVE-2026-77758CVE-2026-77786CVE-2026-77789CVE-2026-77790CVE-2026-77824CVE-2026-78125CVE-2026-78137CVE-2026-78138CVE-2026-78139CVE-2026-78146CVE-2026-78257CVE-2026-78258CVE-2026-78260CVE-2026-78261CVE-2026-78269CVE-2026-78270CVE-2026-78271CVE-2026-78272CVE-2026-78273CVE-2026-78274CVE-2026-78275CVE-2026-78276CVE-2026-78278CVE-2026-78279CVE-2026-78280CVE-2026-78281CVE-2026-78283CVE-2026-78285CVE-2026-78286CVE-2026-78288CVE-2026-78289CVE-2026-78290CVE-2026-78291CVE-2026-78292CVE-2026-78293CVE-2026-78333CVE-2026-78364CVE-2026-79615CVE-2026-79706CVE-2026-79995CVE-2026-79996CVE-2026-80311CVE-2026-80433CVE-2026-80488CVE-2026-81026CVE-2026-81200CVE-2026-81271CVE-2026-81272CVE-2026-81273CVE-2026-81274CVE-2026-81276CVE-2026-81277CVE-2026-81278CVE-2026-81279CVE-2026-81284CVE-2026-81285CVE-2026-81290CVE-2026-81291CVE-2026-81293CVE-2026-81296CVE-2026-81297CVE-2026-81298CVE-2026-81299CVE-2026-81342CVE-2026-81346CVE-2026-81756CVE-2026-81757CVE-2026-81758CVE-2026-81759CVE-2026-81760CVE-2026-81761CVE-2026-81762CVE-2026-81763CVE-2026-81764CVE-2026-81765CVE-2026-81767CVE-2026-81768CVE-2026-81777CVE-2026-81779CVE-2026-81780CVE-2026-82220CVE-2026-82222CVE-2026-82224CVE-2026-82225CVE-2026-82226CVE-2026-82227CVE-2026-82228CVE-2026-82229
VendorsAppleGoogleSlackWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary