Skip to content
DnsLister Forum

Where domain hunters compare notes

WordPress: I Counted Almost 50 Unpatched WordPress Plugins in a Single Week — What the Hell Is Happening to This Ecosystem?

Alright, so I saw this Wordfence report from last week and honestly my jaw dropped. Nearly 50 plugins and themes dropped with active, unpatched vulnerabilities in a single week. That's not a normal week. That's a red flag waving right in our faces.

And look, I get it. We all know the WordPress plugin ecosystem has always been a bit of a wild west. But this feels different. This feels like developers are just straight up walking away. Abandoning ship. Leaving their code rotting on millions of sites while they go do something else.

Here's the thing that really gets me though. A lot of people think "oh I'll just deactivate the plugin and I'm safe." Nope. Not even close. Those files are still sitting there on your server, still reachable, still exploitable in plenty of cases. You gotta fully delete that stuff. Gone. Off the server. Otherwise you're just locking the front door while the back door is wide open.

A few things worth calling out specifically. WordPress core itself, versions 7.1 and below, has an unauthenticated stored XSS issue through wpautop blockquote handling. No CVE assigned yet, which is wild. Then there's Admin Menu Editor Pro, which appears to have been backdoored. That's a supply chain compromise right there. No CVE either. If you ran that, you need to be checking your admin accounts right now, like yesterday.

Couple of messy ones too. Better Messages at 2.15.22 has a reflected XSS, CVE-2026-18555, but the patch status is all over the place depending on where you look. And Subscriptions for WooCommerce at 2.0.2 has a CSRF thing, CVE-2026-87854, with mixed reports on whether it's fixed. So verify your versions, don't just assume.

Now here's the full list of unpatched stuff. Go through it and check your sites.

| CVE | Plugin / Theme |

|—|—|

| CVE-2026-81402 | DS Ad Rotator |

| CVE-2026-86710 | Login with QR |

| CVE-2026-87796 | Multi Uploader for Gravity Forms |

| CVE-2026-86707 | Private Feed Key |

| CVE-2026-84171 | WP images upload on piclect |

| CVE-2026-84099 | IDB Ecommerce (wpStoreCart 5) |

| CVE-2026-87935 | Paid Downloads |

| CVE-2026-84047 | Album Cover Finder |

| CVE-2026-87791 | Design Scuole Italia |

| CVE-2026-87792 | Design Scuole Italia |

| CVE-2026-89307 | Design Scuole Italia |

| CVE-2026-87770 | Price Drop Alert for WooCommerce |

| CVE-2026-80491 | SAMO Forms |

| CVE-2026-87767 | Shortcut Link (wp shortcut link and advertisement baner) |

| CVE-2026-87775 | Tz Weekly Radio Schedule |

| CVE-2026-87774 | Tz Weekly Radio Schedule |

| CVE-2026-87963 | Yo |

| CVE-2026-88793 | YouTube Embed – YouTube Gallery, Vimeo Gallery |

| CVE-2026-87786 | Dewa Kirim – WooCommerce Gojek / Gosend |

| CVE-2026-88792 | Dictionary |

| CVE-2026-85129 | Hoo Companion |

| CVE-2026-74933 | GenieWords |

| CVE-2026-15664 | Quill Forms |

| CVE-2026-86801 | To Do List Member |

| CVE-2026-86802 | To Do List Member |

| CVE-2026-88993 | All Bootstrap Blocks |

| CVE-2026-14844 | Master Slider |

| CVE-2026-15650 | RT Mega Menu |

| CVE-2026-14855 | RT Mega Menu |

| CVE-2026-88904 | PuppyFW |

| CVE-2026-87965 | Easy Appointments |

| CVE-2026-91008 | Event Booking Manager for WooCommerce |

| CVE-2026-87842 | Zonify – Amazon Product Importer for WooCommerce |

| CVE-2026-92465 | WP Mega Menu |

| CVE-2026-75959 | GoPay for WooCommerce |

| CVE-2026-92579 | AVideo |

| CVE-2026-1242 | BlockSpare |

| CVE-2026-16557 | Nimble Builder |

| CVE-2026-15698 | Business Name Generator |

| CVE-2026-91010 | Invisible Anti-Spam & CAPTCHA |

| CVE-2026-87891 | Rox Appointment Booking |

| CVE-2026-87907 | Rox Appointment Booking |

| CVE-2026-87906 | Rox Appointment Booking |

| CVE-2026-87840 | Tripzzy |

| CVE-2026-87839 | Tripzzy |

So what do you actually do about it. First, if you're running any of these, delete them completely. Not deactivate. Delete. Then go find something that's actually maintained. Second, audit your admin accounts. Look for users you didn't create and files that changed when they shouldn't have. Especially if Admin Menu Editor Pro was ever on your site. Third, keep an eye on the vendors. Only reinstall if the original dev comes back and drops a real, verified patch. Otherwise you're just inviting the same problem back in.

But here's what I really wanna know. Why is this happening all at once. Is the security compliance burden just too much for solo devs to keep up with. Are people quietly pivoting away from WordPress entirely. Or is this just what happens when an ecosystem gets this big and this old. Curious what other admins and devs are seeing out there.

TL;DR — Wordfence's latest report shows almost 50 WordPress plugins and themes with unpatched vulnerabilities in just one week. WordPress core also has an unpatched XSS bug, and Admin Menu Editor Pro appears backdoored — both with no CVE yet. Deactivating a vulnerable plugin isn't enough; the files stay exploitable, so you must fully delete them. Check the list, clean your sites, and audit admin accounts if you ever ran Admin Menu Editor Pro. Why so many devs are abandoning their plugins all at once is the bigger question.

Source: r/StopBadBots · by /u/siterightaway

Leave a Reply

Your email address will not be published. Required fields are marked *