On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an…
Category: Blog – Wordfence
600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more…
40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin
On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000…
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Wordfence Bug Bounty Program Monthly Report – April 2026
In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working to…
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced…
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by…
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)
Last week, there were disclosed in WordPress Core, and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to…
A New Threat Landscape Meets A New Kind of Defender
PRISM, our autonomous AI researcher, is now our #1 vulnerability researcher. A look at AI’s new threat landscape — and the new kind of defender it demands. The post A New Threat Landscape Meets A New Kind of Defender appeared…
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026. See who’s affected, the exploitation timeline, and what to do now. The post wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade…
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
