Wordfence: Protege tu WordPress con el informe semanal de vulnerabilidades

Este es un resumen del artículo. Si necesitas contexto adicional, aquí tienes el enlace original: https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-february-23-2026-to-march-1-2026/


🔥🔥🔥 Triple Threat Bug Bounty Challenge 🔥🔥🔥
Hunt High Threat vulnerabilities and earn triple the incentives!

Now through April 6, 2026, earn three stacked bonuses on all valid submissions from our ‘High Threat Vulnerabilities’ list:

  • 💰 2x all high threat vulnerability bounties (excluding 5,000,000+ installs)
  • 📈 +30% bonus for high threat vulnerabilities in software with 30,000+ active installs (excluding 5,000,000+ installs)
  • 🎯 $300 extra for every 3 High Threat vulnerabilities submitted (minimum of 1,000 installs)

Use the Bounty Estimator to see what rewards are possible through the promotion.

Submit through our Bug Bounty Program today to maximize your impact and your payout.


Last week, there were 204 vulnerabilities disclosed in 77 WordPress Plugins and 119 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 39 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 41
Unpatched 163

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 70
High Severity 131
Critical Severity 3

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 99
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 43
Missing Authorization 16
Deserialization of Untrusted Data 10
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 8
Improper Control of Generation of Code ('Code Injection') 4
Unrestricted Upload of File with Dangerous Type 4
Authentication Bypass Using an Alternate Path or Channel 3
Authorization Bypass Through User-Controlled Key 3
Exposure of Sensitive Information to an Unauthorized Actor 3
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
Cross-Site Request Forgery (CSRF) 1
Embedded Malicious Code 1
Improper Access Control 1
Improper Authentication 1
Improper Authorization 1
Improper Privilege Management 1
Insufficient Verification of Data Authenticity 1
Server-Side Request Forgery (SSRF) 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
65
38
30
12
6
4
3
3
3
3
3
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Advanced Woo Labels – Product Labels & Badges for WooCommerce advanced-woo-labels
AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine
AllInOne – Banner Rotator all-in-one-bannerRotator
Bakery Autoresponder Addon vc-autoresponder-addon
Builderall for WordPress builderall-cheetah-for-wp
Classified Listing – AI-Powered Classified ads & Business Directory Plugin classified-listing
Custom Logo custom-logo
designthemes-portfolio designthemes-portfolio
Directory Listings WordPress plugin – uListing ulisting
Directory Pro directory-pro
Disable Admin Notices – Hide Dashboard Notifications disable-admin-notices
DT – Directory WordPress Plugin designthemes-directory-addon
DT Booking – WordPress Ultimate Booking Plugin designthemes-booking-manager
Eagle Booking eagle-booking
Electric Enquiries electric-enquiries
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor elementskit-lite
EM Cost Calculator cost-calculator
Filr – Secure document library filr-protection
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty chaty
Fluent Forms Pro Add On Pack fluentformpro
Frontend Publishing Pro rh-frontend
Geo Mashup geo-mashup
Japanized for WooCommerce woocommerce-for-japan
JetEngine jet-engine
LambertGroup – AllInOne – Banner with Playlist all-in-one-bannerWithPlaylist
LambertGroup – AllInOne – Banner with Thumbnails all-in-one-thumbnailsBanner
LambertGroup – AllInOne – Content Slider all-in-one-contentSlider
Lawyer Directory lawyer-directory
ListingPro Plugin listingpro-plugin
Livemesh Addons for Beaver Builder addons-for-beaver-builder
MailArchiver mailarchiver
My Tickets – Accessible Event Ticketing my-tickets
NextScripts: Social Networks Auto-Poster social-networks-auto-poster-facebook-twitter-g
OVRI Payment moneytigo
Portfolio Awa awa-plugins
Post Duplicator post-duplicator
PowerPress Podcasting plugin by Blubrry powerpress
Profile Builder Pro profile-builder-pro
Really Simple Security Pro really-simple-ssl-pro
Responsive Lightbox & Gallery responsive-lightbox
Responsive Posts Carousel WordPress Plugin responsive-posts-carousel-pro
Responsive Zoom In/Out Slider WordPress Plugin lbg_zoominoutslider
Riode Core riode-core
Rise Blocks – A Complete Gutenberg Page Builder rise-blocks
Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons
Scientific and Interactive Blocks – inseri core inseri-core
Secure Copy Content Protection and Content Locking secure-copy-content-protection
Simple Download Monitor simple-download-monitor
Site Suggest site-suggest
SiteGuard WP Plugin siteguard
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent tablesome
The Events Calendar the-events-calendar
Theater for WordPress theatre
TP2WP Importer tp2wp-importer
Tutor LMS – eLearning and online course solution tutor
UberSlider – Layer Slider WordPress Plugin uberSlider_perpetuummobile
UberSlider – Layer Slider WordPress Plugin uberSlider_mouseinteraction
UberSlider – Layer Slider WordPress Plugin uberSlider_ultra
uberSlider_classic uberSlider_classic
Ultimate Learning Pro indeed-learning-pro
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration wp-user-frontend
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder user-registration
W3 Total Cache w3-total-cache
WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon
WooCommerce Coming Soon Product with Countdown woo-coming-soon-product
WooCommerce License Manager fs-license-manager
WooCommerce Order Details woocommerce-order-details
Worry Proof Backup worry-proof-backup
WP Accessibility wp-accessibility
WP Attractive Donations System – Easy Stripe & Paypal donations WP_AttractiveDonationsSystem
WP Mail Logging wp-mail-logging
WP Recipe Maker wp-recipe-maker
WP Responsive Images wp-responsive-images
WP Social Meta wp-social-meta
WPGSI: Spreadsheet Integration wpgsi
WPZOOM Addons for Elementor – Starter Templates & Widgets wpzoom-elementor-addons
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Accalia | Dermatology Clinic & Cosmetology WordPress Theme + Elementor dermatology-clinic
Alchemists – Sports, eSports & Gaming Club and News WordPress Theme alchemists
Alliance | Intranet & Extranet BuddyPress WordPress Theme alliance
Anderson | Physical Therapy & Orthopedic Clinic WordPress Theme andersonclinic
Aora – Home & Lifestyle Elementor WooCommerce Theme aora
apollo apollo
Aqualots aqualots
Architecturer WordPress for Interior Designer architecturer
Artrium – Creative Agency & Web Studio WP Theme artrium
asia-garden asia-garden
Automotive Car Dealership Business WordPress Theme automotive
Aviana – Elegant Wellness & Spa WordPress Theme aviana
Bassein | Swimming Pool Cleaning & Maintenance WordPress Theme bassein
Bazinga | Viral Blog WordPress Theme bazinga
Beacon | Funeral Services WordPress Theme beacon
Buzz Stone | Magazine & Viral Blog WordPress Theme buzzstone
Celeste – Life Coach & Therapist WordPress Theme celeste
Chronicle chronicle
Claue – Clean, Minimal Elementor WooCommerce Them claue
CloudMe | Cloud Storage & File-Sharing WordPress Theme cloudme
Cocco – Kids Store and Baby Shop WordPress Theme cocco
Coleo coleo
Conquerors | American Football & NFL PSD Template conquerors
Consultor | A Business Financial Advisor PSD Template consultor
Cortex – Agency WordPress Theme cortex
Crown Art | Drawing and Music School WordPress Theme crown-art
Daiquiri daiquiri
Dentario – Dentist & Medical Elementor Template Kit dentario
Dixon & Lamber dixon
Dolcino – Pastry and Cake Shop WordPress Theme dolcino
Dr.Patterson | Medical & Healthcare Doctor WordPress Theme dr-patterson
Edge Decor edge-decor
Eject eject
Ekoterra – NonProfit & Ecology Theme ekoterra
ElectroServ | Electrical Repair Service WordPress Theme electroserv
Eona – Fashion WordPress Theme eona
Evently – Conference & Meetup WordPress Theme evently
Filmax | Cinema & Movie News Magazine WordPress Theme filmax
Fiorello – Florist and Flower Shop WordPress Theme fiorello
FixTeam | Electronics & Mobile Devices Repair WordPress Theme fixteam
fleur fleur
gamezone gamezone
Gecko 6.0 – Responsive Shopify Theme – RTL support gecko
Good Energy – Ecology & Renewable Energy WordPress Theme goodenergy
GoTravel – Travel Agency WordPress Theme gotravel
grandnews grandnews
Great Lotus | Buddhist Temple WordPress Theme + RTL great-lotus
Green Planet | Environmental Non-Profit WordPress Theme green-planet
Guff – Blog & Magazine Ghost Theme guff
Happy Baby | Nanny & Babysitting Services Children WordPress Theme happy-baby
Helvig – Creative Portfolio WordPress Theme helvig
Holmes – Digital Agency WordPress Theme holmes
Honor | Shooting Club & Weapon and Gun Store Theme honor
horizon horizon
Innovio – Multipurpose Landing Page WordPress Theme innovio
Justicia – Lawyer WordPress Theme justicia
Kingler kingler
Le Truffe letruffe
Legal Stone | Lawyers & Attorneys WordPress Theme legal-stone
LeGrand | Modern Business WordPress Theme legrand
Listee listee
Little Birdies | Multipurpose Children PSD Template little-birdies
M.Williamson | Lawyer & Legal Adviser WordPress Theme williamson
Mahogany mahogany
Malgré – Creative Agency WordPress Theme malgre
Mandala – Responsive Ecommerce WordPress Theme mandala
Marcell – Personal Blog & Magazine WordPress Theme marcell
Marra – Beauty WordPress Theme marra
MCKinney's Politics mckinney-politics
MediCenter – Health Medical Clinic WordPress Theme medicenter
metro metro
Midi – Sound & Music WordPress Theme midi
Miller | Personal Assistant & Administrative Services WordPress Theme christine-miller
Molla – eCommerce HTML5 Template molla
Music WordPress musico
Muzicon – Music Festival & Concert WordPress Theme muzicon
Nirvana nirvana
Notarius – Legal Advisor WordPress Theme notarius
Overton – Creative WordPress Theme for Agencies and Freelancers overton
Ozisti | Augmented Reality WooCommerce Theme ozisti
Peter Mason | Custom Tailoring and Clothing Store WordPress Theme petermason
photography photography
Pizza House – Restaurant / Cafe / Bistro WordPress Theme pizzahouse
Playa | Beach & Pool Club WordPress Theme playa
Police Department – Fire & Security WordPress Theme police-department
porto porto
quantum quantum
RexCoin – Cryptocurrency & Coin ICO WordPress rexcoin
Run Gran run-gran
Rythmo rhythmo
Save Life | Non-Profit, Charity & Donations WordPress Theme save-life
SetSail – Travel Agency WordPress Theme setsail
Shaha | Islamic Centre & Mosque Theme + RTL shaha
SmartSEO | SEO & Marketing HTML Theme smartseo
Sounder | Internet Radio & Streaming Elementor Template Kit sounder
Starto | Software AI Startup WordPress starto
Sweet Date sweetdate
Sweet Jane – Delightful Cake Shop Theme sweetjane
Tennis SportClub – Tennis Sports Events WordPress Theme tennis-sportclub
The Issue – Versatile Magazine WordPress Theme theissue
The Mounty | Hiking Campground & Children Camping WordPress Theme the-mounty
Tiger Claw tiger-claw
Tooth Fairy – Dentist & Dental Clinic WordPress Theme tooth-fairy
TopFit – Fitness and Gym WordPress Theme topfit
TopScorer – Sports WordPress Theme topscorer
tribe tribe
uDesign – Responsive WordPress Theme u-design
Vapester | Cigarette Store & Vape Shop WooCommerce Theme vapester
Veil – Wedding & Photographer WordPress Theme veil
Verdure – Organic Tea Shop WordPress Theme verdure
Verse – Music, Radio & Concert WordPress Theme verse
wabi-sabi wabi-sabi
WealthCo wealthco
Welldone – Sports Store WordPress Theme welldone
Windsor – Apartment Complex Single Property WordPress Theme windsor
Wolmart | Multi-Vendor Marketplace WooCommerce Theme wolmart
Woopy – Multipurpose Store WooCommerce WordPress Shop Theme woopy
Yacht Rental – Boat Services WordPress Theme yacht-rental
Zentrum – Property & Apartment Showcase WordPress Theme zentrum

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

Listee [listee]

Researcher

CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

W3 Total Cache [w3-total-cache]

Researcher

CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon]

Researcher

CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Builderall for WordPress [builderall-cheetah-for-wp]

CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Researcher

CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

JetEngine [jet-engine]

Researcher

CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon]

Researcher

CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Worry Proof Backup [worry-proof-backup]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 23, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

apollo [apollo]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Aqualots [aqualots]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

asia-garden [asia-garden]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 24, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Chronicle [chronicle]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Coleo [coleo]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Daiquiri [daiquiri]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 23, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Edge Decor [edge-decor]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Eject [eject]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

fleur [fleur]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

gamezone [gamezone]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

horizon [horizon]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

Kingler [kingler]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Le Truffe [letruffe]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Mahogany [mahogany]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

MCKinney's Politics [mckinney-politics]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

metro [metro]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Nirvana [nirvana]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

quantum [quantum]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Rythmo [rhythmo]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Run Gran [run-gran]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Feb 23, 2026

Affected Software

Sweet Date [sweetdate]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Tiger Claw [tiger-claw]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

tribe [tribe]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

wabi-sabi [wabi-sabi]

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

WealthCo [wealthco]

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

Researcher

CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

Researcher

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 24, 2026

Affected Software

Geo Mashup [geo-mashup]

Researcher

CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g]

CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

Profile Builder Pro [profile-builder-pro]

Researcher

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 25, 2026

Affected Software

Riode Core [riode-core]

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 27, 2026

CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 27, 2026

Affected Software

WP Mail Logging [wp-mail-logging]

CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

WP Responsive Images [wp-responsive-images]

CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Bakery Autoresponder Addon [vc-autoresponder-addon]

Researcher

CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Lawyer Directory [lawyer-directory]

CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

photography [photography]

CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

Responsive Lightbox & Gallery [responsive-lightbox]

Researcher

CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

WooCommerce License Manager [fs-license-manager]

Researcher

CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

Eagle Booking [eagle-booking]

Researcher

CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

OVRI Payment [moneytigo]

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Electric Enquiries [electric-enquiries]

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

Simple Download Monitor [simple-download-monitor]

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 25, 2026

Affected Software

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Researcher

CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

WP Accessibility [wp-accessibility]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

AllInOne – Banner Rotator [all-in-one-bannerRotator]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Portfolio Awa [awa-plugins]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

designthemes-portfolio [designthemes-portfolio]

Researcher

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

EM Cost Calculator [cost-calculator]

Researcher

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

grandnews [grandnews]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

ListingPro Plugin [listingpro-plugin]

Researcher

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

metro [metro]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

porto [porto]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Researcher

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

uberSlider_classic [uberSlider_classic]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

UberSlider – Layer Slider WordPress Plugin [uberSlider_mouseinteraction]

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 27, 2026

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Researcher

CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Ultimate Learning Pro [indeed-learning-pro]

Researcher

CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Feb 25, 2026

Affected Software

The Events Calendar [the-events-calendar]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Bakery Autoresponder Addon [vc-autoresponder-addon]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

DT – Directory WordPress Plugin [designthemes-directory-addon]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

Directory Pro [directory-pro]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 24, 2026

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 27, 2026

Affected Software

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

Japanized for WooCommerce [woocommerce-for-japan]

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2026

Affected Software

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Responsive Posts Carousel WordPress Plugin [responsive-posts-carousel-pro]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 26, 2026

Affected Software

Site Suggest [site-suggest]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 23, 2026

Affected Software

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 25, 2026

Affected Software

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon]

Researcher

CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 24, 2026

Affected Software

WooCommerce Order Details [woocommerce-order-details]

Researcher

CVSS Rating
5.0 (Medium)
Patch Status
Patched
Published
Feb 24, 2026

Affected Software

Responsive Lightbox & Gallery [responsive-lightbox]

Researcher

CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Feb 26, 2026

Affected Software

MailArchiver [mailarchiver]

CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

Custom Logo [custom-logo]

CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

TP2WP Importer [tp2wp-importer]

CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Feb 25, 2026

Affected Software

WP Social Meta [wp-social-meta]

CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2026

Affected Software

Really Simple Security Pro [really-simple-ssl-pro]

Researcher

CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 24, 2026

Affected Software

WP Recipe Maker [wp-recipe-maker]


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (February 23, 2026 to March 1, 2026) appeared first on Wordfence.

Puedes consultar el artículo original aquí: https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-february-23-2026-to-march-1-2026/

Published On: 5 de marzo de 2026Categories: Wordfence