Security News

WordPress Vulnerabilities — June 2026

June’s WordPress plugin security disclosures, and the recurring themes behind them.

June’s disclosures repeated a familiar shape: a small number of genuinely urgent issues in widely installed plugins, and a long tail of authenticated findings that matter mainly to sites with untrusted contributors.

Themes worth noting

  • Authenticated-but-low-privilege findings. A vulnerability requiring subscriber or contributor access is not harmless on a site with open registration. Check whether you have registration enabled before dismissing one.
  • Long-tail abandonment. Several affected plugins had no maintainer to patch them. These become replace-soon items, not update items.
  • Add-on ecosystems. Extensions for large plugins continue to be the weakest link — smaller teams, slower patching, no directory distribution.

The recurring lesson

Most sites that get compromised are not running a zero-day. They are running something with a fix that has been available for months. The gap between “patch exists” and “patch installed” is where nearly all of the damage happens, and closing it is mostly an operational problem rather than a technical one.

A five-minute monthly routine

  1. Scan.
  2. Update everything in the fix-today bucket.
  3. Delete one thing you do not use.
  4. Note anything abandoned, and schedule the replacement rather than promising yourself you will remember.

Want this checked automatically across every plugin, theme and core file on your site? WPDeeply Risk Monitor is free.