Stuart Neal
Director of Operations at Nextgen Marketing
We have worked with Vitalli and his team for well over a year now and will continue to do so in the future.
Having the confidence in an agency that allowed us to scale up and down development resources, as and when needed, has really made a positive difference to our agency.
Home / Blog / News / 319 WordPress plugin vulnerabilities in one week. Fourteen were critical and one is still unpatched
Wordfence published its weekly vulnerability report on October 1, covering 21–27 September: 319 vulnerabilities disclosed across 222 plugins, from 156 researchers. Nobody reads that list end to end. The useful question for an agency is narrower — which of these are on sites we’re responsible for — and that is the whole case for weekly plugin triage across a client portfolio rather than updating when something breaks.
Request a Quote for WooCommerce <= 2.9.2 — CVE-2026-18143, CVSS 9.8, unauthenticated arbitrary file upload via the AJAX popup handler, published September 25 and listed as unpatched. Unauthenticated file upload on a WooCommerce store is a shell, and there is no version to update to. If a client runs it, the decision today is deactivate or accept the risk — there is no third option while it stays unpatched.
Note it is not the YITH plugin with a similar name. YITH Request a Quote had its own disclosure the same week (CVE-2026-95602), rated 5.3 and already patched.
All patched, all unauthenticated, all 9.8 unless noted:
Three WooCommerce-adjacent plugins in one week, in the quoting, reviews and payments layer — the add-ons that get installed once for a client requirement and then never thought about again.
If you’re on one of our maintenance plans, your sites have already been checked against this week’s list, the patched items are applied, and anything unpatched is flagged with a recommendation — all of it in your next monthly maintenance report. Nothing is needed from you. If you’re not on a plan, this is the volume the plan exists to absorb: 319 disclosures in seven days is not something anyone reviews in their spare time, and the ones that matter are always a handful of specific plugins on specific sites.
Source: Wordfence