(647) 243-4688

Last week, there were 54 vulnerabilities disclosed in 49 WordPress Plugins that have been added to the Wordfence Intelligence Vulnerability Database, and there were 36 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

      • WAF-RULE-906 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 52
Unpatched 2

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 35
High Severity 14
Critical Severity 5

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 23
Missing Authorization 7
Improper Control of Generation of Code (‘Code Injection’) 5
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 4
Exposure of Sensitive Information to an Unauthorized Actor 3
Authorization Bypass Through User-Controlled Key 2
Server-Side Request Forgery (SSRF) 2
Unrestricted Upload of File with Dangerous Type 2
Cross-Site Request Forgery (CSRF) 1
Improper Authorization 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 1
Reliance on Cookies without Validation and Integrity Checking 1
Use of Hard-coded Credentials 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
4
4
4
3
3
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Auto Post Scheduler auto-post-scheduler
Booking for Appointments and Events Calendar – Amelia ameliabooking
Contact Form by Supsystic contact-form-by-supsystic
Database for Contact Form 7, WPforms, Elementor forms contact-form-entries
Debugger & Troubleshooter debugger-troubleshooter
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor elementskit-lite
Everest Forms Pro everest-forms-pro
Export All URLs export-all-urls
Extensions for Leaflet Map extensions-leaflet-map
Gravity SMTP gravitysmtp
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem gutenverse
Ibtana – WordPress Website Builder ibtana-visual-editor
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor kadence-blocks
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder king-addons
Kubio AI Page Builder kubio
LeadConnector leadconnector
Listeo-Core – Directory Plugin by Purethemes listeo-core
Loco Translate loco-translate
Minify HTML minify-html-markup
MSTW League Manager mstw-league-manager
MW WP Form mw-wp-form
Order Notification for WooCommerce – Get Audio Alert on new Orders woc-order-alert
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress wp-user-avatar
Perfmatters perfmatters
Pie Register – User Registration, Profiles & Content Restriction pie-register
Query Monitor query-monitor
Responsive Plus – Elementor Templates & Starter Sites responsive-add-ons
Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons
Shared Files – Frontend File Upload Form & Secure File Sharing shared-files
Simple Membership simple-membership
Simple Shopping Cart wordpress-simple-paypal-shopping-cart
Text to Speech – TTSWP text-to-speech-tts
ThemeREX Addons trx_addons
TrueBooker – Appointment Booking and Scheduler System truebooker-appointment-booking
Ultimate Addons for WPBakery Ultimate_VC_Addons
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor profile-builder
Visitor Traffic Real Time Statistics visitors-traffic-real-time-statistics
W3 Total Cache w3-total-cache
WCFM – Frontend Manager for WooCommerce wc-frontend-manager
Webmention webmention
Widgets for Social Photo Feed social-photo-feed-widget
WooPayments: Integrated WooCommerce Payments woocommerce-payments
WP Lightbox 2 wp-lightbox-2
WP Shortcodes Plugin — Shortcodes Ultimate shortcodes-ultimate
WP Travel Engine – Tour Booking Plugin – Tour Operator Software wp-travel-engine
wpForo Forum wpforo
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell wpfunnels
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Contact Form by Supsystic [contact-form-by-supsystic]

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Everest Forms Pro [everest-forms-pro]

Researcher

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

ThemeREX Addons [trx_addons]

Researcher

CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Debugger & Troubleshooter [debugger-troubleshooter]

Researcher

CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

wpForo Forum [wpforo]

CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Apr 1, 2026

Affected Software

MW WP Form [mw-wp-form]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Apr 2, 2026

Affected Software

Perfmatters [perfmatters]

Researcher

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Apr 2, 2026

Affected Software

Export All URLs [export-all-urls]

Researcher

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Gravity SMTP [gravitysmtp]

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

Text to Speech – TTSWP [text-to-speech-tts]

Researcher

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Apr 1, 2026

Affected Software

W3 Total Cache [w3-total-cache]

Researcher

CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Query Monitor [query-monitor]

Researcher

CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics]

Researcher

CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Apr 1, 2026

Affected Software

Webmention [webmention]

Researcher

CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

Widgets for Social Photo Feed [social-photo-feed-widget]

Researcher

CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Mar 31, 2026

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 2, 2026

Affected Software

Extensions for Leaflet Map [extensions-leaflet-map]

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Mar 31, 2026

Affected Software

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Apr 2, 2026

Affected Software

MSTW League Manager [mstw-league-manager]

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

Simple Shopping Cart [wordpress-simple-paypal-shopping-cart]

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 1, 2026

Affected Software

Ultimate Addons for WPBakery [Ultimate_VC_Addons]

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 1, 2026

Affected Software

Webmention [webmention]

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

Researcher

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Mar 30, 2026

Affected Software

Auto Post Scheduler [auto-post-scheduler]

CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Loco Translate [loco-translate]

Researcher

CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Minify HTML [minify-html-markup]

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

LeadConnector [leadconnector]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 3, 2026

Affected Software

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Mar 31, 2026

Affected Software

Simple Membership [simple-membership]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

Researcher

CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Mar 30, 2026

Affected Software

WP Lightbox 2 [wp-lightbox-2]

Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026) appeared first on Wordfence.