190 New Plugin/Theme Vulnerabilities in a Single Week (Feb 2026)

In a single week ending February 18, 2026, SolidWP tracked 190 newly disclosed plugin and theme vulnerabilities.

In the week ending February 18, 2026, SolidWP reported 190 newly disclosed issues across WordPress plugins and themes. That number matters because most business sites are not built to process security news at that pace. They are built to publish content, launch campaigns, and keep forms and integrations working.

When WordPress plugin vulnerabilities appear faster than your team can review and patch, the gap becomes a risk. It only takes one unpatched issue in a commonly used plugin to turn a routine update into an incident response sprint. The fallout rarely stays “technical.” Landing pages get pulled, lead routing breaks, and marketing teams lose confidence in what should be their most reliable channel.

Weekly updates help, but they can also create a false sense of safety. If your process is “update on Fridays,” you can still sit exposed for days while disclosures stack up. Multiply that by a growing list of plugins, multiple environments, and several stakeholders who can approve changes. Now you have a delay problem, not a tooling problem.

The practical fix is visibility plus prioritization. You need to know which WordPress plugin vulnerabilities apply to what is actually installed, which ones are being exploited in the wild, and which updates carry the most operational risk. From there, you can patch with intent, test the right pages, and keep shipping without guessing.

For teams managing several sites, that same approach scales. It turns patching from a constant fire drill into a repeatable workflow, so velocity does not become vulnerability.

This stat is a reminder that patching is now an operating system, not a task. The teams that stay ahead have a way to spot relevant disclosures, rank them by real risk, and act before the backlog grows. That is exactly what consistent monitoring is for. See what we’d watch for you.

Source: SolidWP, WordPress Vulnerability Report