319 WordPress plugin vulnerabilities in one week. Fourteen were critical and one is still unpatched

Wordfence published its weekly vulnerability report on October 1, covering 21–27 September: 319 vulnerabilities disclosed across 222 plugins, from 156 researchers. Nobody reads that list end to end. The useful question for an agency is narrower — which of these are on sites we’re responsible for — and that is the whole case for weekly plugin triage across a client portfolio rather than updating when something breaks.

The week in numbers

  • 319 vulnerabilities, 222 plugins, 156 researchers
  • 305 patched, 14 unpatched at time of publication
  • By severity: 226 medium, 79 high, 14 critical
  • Most common type by a distance: cross-site scripting (96), then missing authorization (59), authorization bypass through a user-controlled key (26) and SQL injection (24)
  • Wordfence also shipped a firewall rule for the WordPress core unauthenticated local file inclusion in `locate_template()` affecting core up to 7.1.1 — the same core issue that has been under active attack since the 7.1.2 patch

The one to look at first

Request a Quote for WooCommerce <= 2.9.2 — CVE-2026-18143, CVSS 9.8, unauthenticated arbitrary file upload via the AJAX popup handler, published September 25 and listed as unpatched. Unauthenticated file upload on a WooCommerce store is a shell, and there is no version to update to. If a client runs it, the decision today is deactivate or accept the risk — there is no third option while it stays unpatched.

Note it is not the YITH plugin with a similar name. YITH Request a Quote had its own disclosure the same week (CVE-2026-95602), rated 5.3 and already patched.

The other criticals worth grepping for

All patched, all unauthenticated, all 9.8 unless noted:

  • Visual Composer Website Builder <= 45.16.0 — local file inclusion via `vcv-template` (CVE-2026-12227)
  • Meta Box AIO <= 3.11.0 and its standalone extensions — privilege escalation to administrator (CVE-2026-13355)
  • miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 — authentication bypass (CVE-2026-85984)
  • Ultra Addons for Contact Form 7 <= 3.5.50 — arbitrary file upload via the signature field (CVE-2026-82901)
  • Automation Web Platform <= 4.8.6 — privilege escalation (CVE-2026-14281)
  • Paytium: Mollie payment forms & donations <= 5.0.3 — privilege escalation (CVE-2026-18467)
  • Give Tributes <= 2.3.1 — PHP object injection (CVE-2026-19658)
  • YAHMAN Add-ons <= 0.9.30 — remote code execution (CVE-2026-75799)
  • Customer Reviews for WooCommerce <= 5.120.0 — arbitrary attachment deletion, 9.1 (CVE-2026-89055)
  • Bookly / Online Scheduling and Appointment Booking System <= 28.2 — unauthenticated booking token disclosure and deletion, 9.1 (CVE-2026-93399)

Three WooCommerce-adjacent plugins in one week, in the quoting, reviews and payments layer — the add-ons that get installed once for a client requirement and then never thought about again.

The practical version of this

  • Keep a current plugin inventory across every site you manage. Reading a list like this is only useful if you can answer “do we run any of these” in minutes, not days
  • Handle the unpatched entries separately from the patched ones. Patched is a workflow; unpatched is a judgement call that someone has to make and record
  • Thirteen of the fourteen unpatched items this week are medium or high rather than critical, but a 7.5 unauthenticated SQL injection in a small plugin is still a bad week if it’s on a client site

What this means for Codelibry clients

If you’re on one of our maintenance plans, your sites have already been checked against this week’s list, the patched items are applied, and anything unpatched is flagged with a recommendation — all of it in your next monthly maintenance report. Nothing is needed from you. If you’re not on a plan, this is the volume the plan exists to absorb: 319 disclosures in seven days is not something anyone reviews in their spare time, and the ones that matter are always a handful of specific plugins on specific sites.

Source: Wordfence

Vitalii Omelchenko
Founder at Codelibry and WordPress enthusiast. Helping digital agencies to protect their margins and do better at website delivery. Need help with wordpress builds? Book a call using the Contact page
our Blog

Explore our Latest Insights

company icon
The WordPress backdoor that rebuilds itself. Deleting the files is not a cleanup
News
October 2, 2026
company icon
How agency retainer billing cycle can 5x LTV
WordPress
September 30, 2026
company icon
Meet Ipsum, WordPress’s next default theme — and what else 7.2 has in store
News
September 29, 2026
whatsapp icon