<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(wordfence.com) Weekly WordPress Vulnerability Report: Analysis of 87 Newly Disclosed Plugin and Theme Vulnerabilities]]></title><description><![CDATA[<p>(wordfence.com) Weekly WordPress Vulnerability Report: Analysis of 87 Newly Disclosed Plugin and Theme Vulnerabilities</p><p>This week’s WordPress vulnerability report discloses 87 new flaws in plugins/themes, including 3 critical, 34 high, and 50 medium-severity issues. XSS (30) and missing authorization (19) dominate the threat landscape, with SQLi (10) and SSRF (3) also present. Firewall rules deployed for premium users; free users protected after 30 days. 84 patched, 3 unpatched.</p><p>In brief - WordPress ecosystems face significant risk from 87 newly disclosed vulnerabilities, primarily XSS and missing authorization flaws. Immediate patching and monitoring are critical to mitigate exposure.</p><p>Technically - The report details 87 vulnerabilities (CWE-mapped) with CVSS-rated severity: 3 critical, 34 high, 50 medium. XSS (CWE-79) and missing authorization (CWE-862) lead, followed by SQLi (CWE-89), sensitive data exposure (CWE-200), and SSRF (CWE-918). Wordfence Intelligence deployed enhanced firewall rules for premium users; free-tier protection delayed 30 days. Data sourced from in-house research, bug bounties, and public disclosures.</p><p>Source: <a href="https://www.wordfence.com/blog/2026/05/wordfence-intelligence-weekly-wordpress-vulnerability-report-april-27-2026-to-may-3-2026/" rel="nofollow noopener"><span>https://www.</span><span>wordfence.com/blog/2026/05/wor</span><span>dfence-intelligence-weekly-wordpress-vulnerability-report-april-27-2026-to-may-3-2026/</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/484f26b5-3714-456e-9696-6882bc9f965f/wordfence.com-weekly-wordpress-vulnerability-report-analysis-of-87-newly-disclosed-plugin-and-theme-vulnerabilities</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 00:28:11 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/484f26b5-3714-456e-9696-6882bc9f965f.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 May 2026 19:43:31 GMT</pubDate><ttl>60</ttl></channel></rss>