Home About Services Projects Blog Contact Policy
Industry Report

Record High: Over 200
Vulnerabilities in a Week

EA

Author

Eslam Abdullah

Date

Status

Critical Surge

WordPress vulnerabilities report – record week in April 2026

The third week of April 2026 has officially set a new record for the number of security vulnerabilities discovered within the WordPress ecosystem. According to data aggregated from various security firms, a staggering 216 new vulnerabilities were logged in just seven days.

The Data Breakdown

Of the 216 vulnerabilities, nearly 85% were found in third-party plugins, with the remainder affecting themes and core WordPress components. Surprisingly, a significant portion of these flaws were related to cross-site scripting (XSS) and unauthorized metadata access.

"We are seeing a more aggressive push from security researchers using automated fuzzing tools, which explains the high volume. However, the speed at which developers are patching these is not keeping up," Eslam explains.

Why the Surge?

Industry experts attribute this surge to several factors:

  • Increased use of AI-driven vulnerability scanners by both white-hat and black-hat hackers.
  • A wave of legacy plugins becoming incompatible with PHP 8.4's stricter typing.
  • Coordinated disclosures from several major security audits.

Recommendations

Website owners are advised to minimize the number of active plugins, use a robust Web Application Firewall (WAF), and enable auto-updates for critical security patches. Regular security audits are now more essential than ever.