Security News

WordPress Vulnerabilities — July 2026

What mattered in WordPress plugin security last month, and what to do about it.

A monthly summary of the WordPress security disclosures worth your attention — filtered for what actually needs action rather than everything that received an identifier.

How to read this

Hundreds of plugin vulnerabilities are published every month. Almost none affect your site. The useful question is never “what was disclosed?” but “what was disclosed in something I have installed, that is active, and that has a fix?” — which is the question Risk Monitor answers in a few seconds.

The pattern this month

  • Upload handlers, again. Unauthenticated file upload remains the highest-impact recurring category in the plugin ecosystem, and premium extensions distributed outside WordPress.org patch slowest because updates do not arrive through the dashboard.
  • Incomplete patches. More than one issue this cycle needed a second release. Updating to the first “fixed” version is not always enough — check the version the advisory names, not the one you happen to be on.
  • Directory removals. Several plugins were closed without explanation. A closed listing on an active plugin deserves a replacement plan.

What to do this month

  1. Run one scan and deal with anything in the fix-today bucket.
  2. Check any premium extensions manually — they do not appear in WordPress update notifications.
  3. Delete inactive plugins you have not used since the last roundup.
  4. Confirm your PHP version is still receiving security support.

WordPress core is on the 7.0 line, with security releases also issued for the 6.8 and 6.9 branches. If you are on an older branch than those, you are outside security support.

Want this checked automatically across every plugin, theme and core file on your site? WPDeeply Risk Monitor is free.