WordPress Incidents

When the WordPress ecosystem breaks, businesses end up paying the price.

Every day a plugin breaks, an update upends functionality, and real-world impact hits businesses that rely on WordPress. Here are stories that show the cost of depending on themes, plugins, and hosting add-ons for core infrastructure.

Free Audit

Vulnerabilities in 2025

10,784

2026 (so far)

1,127

Last 30 days

580

Plugin vulnerabilities

539

Theme vulnerabilities

41

Core vulnerabilities

0

Live Feed

Recent Critical & High Severity Vulnerabilities

Latest incidents from the daily tracker feed.

highCVSS 8.8

Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access CVSS 8.8

Ecwid by Lightspeed Ecommerce Shopping Cart

First seen Feb 17, 2026
criticalCVSS 9.8

Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation CVSS 9.8

Spam protection, Honeypot, Anti-Spam by CleanTalk

First seen Feb 17, 2026
criticalCVSS 9.8

Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration CVSS 9.8

Truelysell Core

First seen Feb 17, 2026
highCVSS 7.2

Super Page Cache <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting via Activity Log CVSS 7.2

Super Page Cache

First seen Feb 17, 2026
criticalCVSS 9.8

midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action CVSS 9.8

midi-Synth

First seen Feb 17, 2026
highCVSS 7.2

User Language Switch <= 1.6.10 - Authenticated (Administrator+) Server-Side Request Forgery via 'info_language' Parameter CVSS 7.2

User Language Switch

First seen Feb 17, 2026
highCVSS 7.2

Super Simple Contact Form <= 1.6.2 - Reflected Cross-Site Scripting via 'sscf_name' Parameter CVSS 7.2

Super Simple Contact Form

First seen Feb 17, 2026
highCVSS 7.5

Flexi Product Slider and Grid for WooCommerce <= 1.0.5 - Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute CVSS 7.5

Flexi Product Slider and Grid for WooCommerce

First seen Feb 17, 2026
highCVSS 7.5

SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation CVSS 7.5

SureForms – Contact Form, Payment Form & Other Custom Form Builder

First seen Feb 17, 2026
highCVSS 7.5

PhotoStack Gallery <= 0.4.1 - Unauthenticated SQL Injection via 'postid' Parameter CVSS 7.5

PhotoStack Gallery

First seen Feb 17, 2026
highCVSS 8.8

JAY Login & Register <= 2.6.03 - Authenticated (Subscriber+) Privilege Escalation via jay_panel_ajax_update_profile CVSS 8.8

JAY Login & Register

First seen Feb 10, 2026
criticalCVSS 9.8

JAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user CVSS 9.8

JAY Login & Register

First seen Feb 10, 2026
criticalCVSS 9.8

WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJAX Action CVSS 9.8

WP Duplicate – WordPress Migration Plugin

First seen Feb 10, 2026
highCVSS 7.2

All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-proxy Endpoint CVSS 7.2

All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink

First seen Feb 10, 2026
highCVSS 8.2

Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API Endpoints CVSS 8.2

Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

First seen Feb 10, 2026
highCVSS 8.8

SportsPress <= 2.7.26 - Authenticated (Contributor+) Local File Inclusion via Shortcode CVSS 8.8

SportsPress – Sports Club & League Manager

First seen Feb 10, 2026
highCVSS 7.5

Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass CVSS 7.5

Infility Global

First seen Feb 10, 2026
highCVSS 7.5

SEO Flow by LupsOnline <= 2.2.1 - Unauthenticated Arbitrary Post/Category Modification CVSS 7.5

SEO Flow by LupsOnline

First seen Feb 10, 2026
highCVSS 8.8

WP FOFT Loader <= 2.1.39 - Authenticated (Author+) Arbitrary File Upload CVSS 8.8

WP FOFT Loader

First seen Feb 10, 2026
highCVSS 8.8

OS DataHub Maps <= 1.8.3 - Authenticated (Author+) Arbitrary File Upload CVSS 8.8

OS DataHub Maps

First seen Feb 10, 2026

Sources:

WPScan, Wordfence, NVD. Updated daily. Updated daily.
Updated daily.

Updated Feb 16, 2026, 06:28 AM (14 days ago).

Disclaimer: This page aggregates third-party reporting and vulnerability feeds for informational purposes only. Data may be delayed, incomplete, or corrected over time, and we do not verify, warrant, or guarantee its accuracy, completeness, or timeliness. Links are provided as a convenience and do not imply endorsement of any publication, vendor, plugin, theme, hosting provider, or security service. We are not responsible for the content, availability, or security of external websites. Nothing on this page constitutes professional security, legal, or compliance advice. Always evaluate your own environment and consult qualified professionals before making security or platform decisions.