Wordfence Intelligence Weekly WordPress Vulnerability Report (February 17, 2025 to February 23, 2025)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugins and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 308 vulnerabilities disclosed in 268 WordPress Plugins and 7 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 73 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 22,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-811 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 205
Unpatched 103


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 2
Medium Severity 227
High Severity 65
Critical Severity 14


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 169
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 30
Cross-Site Request Forgery (CSRF) 20
Missing Authorization 20
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 15
Deserialization of Untrusted Data 9
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 7
Improper Control of Generation of Code ('Code Injection') 6
Authorization Bypass Through User-Controlled Key 5
Generation of Error Message Containing Sensitive Information 4
Exposure of Sensitive Information to an Unauthorized Actor 3
Improper Access Control 3
Improper Input Validation 3
Unrestricted Upload of File with Dangerous Type 3
Server-Side Request Forgery (SSRF) 2
URL Redirection to Untrusted Site ('Open Redirect') 2
Improper Authorization 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
Incorrect Privilege Assignment 1
Insertion of Sensitive Information into Log File 1
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute 1
Unverified Password Change 1
Use of Cache Containing Sensitive Information 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
33
16
15
13
12
12
12
9
9
8
8
8
7
6
6
6
6
6
6
5
5
5
4
4
4
4
4
4
3
3
3
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
.htaccess Login block htaccess-login-block
1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone 1-click-migration
17TRACK for WooCommerce 17track
3D Photo Gallery 3d-photo-gallery
A1POST.BG Shipping for WooCommerce a1post-bg-shipping-for-woocommerce
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder ablocks
Accept Donations with PayPal & Stripe easy-paypal-donation
Actionwear products sync actionwear-products-sync
Active Products Tables for WooCommerce. Use constructor to create tables  profit-products-tables-for-woocommerce
AcuGIS Leaflet Maps mapfig-premium-leaflet-map-maker
ADFO – Custom data in admin dashboard admin-form
Adsmonetizer adsensei-b30
Affiliate Coupons – Coupon Display Manager – Excellent Tool for Affiliate Marketers affiliate-coupons
Affiliate Links Manager affiliate-links-manager
Affiliate Links – Link Cloaking and Management affiliate-links
All In Menu – Header menu creator all-in-menu
AMO Team Showcase amo-team-showcase
Apptivo Business Site apptivo-business-site
AR for WordPress ar-for-wordpress
Assistant – Every Day Productivity Apps assistant
Atarim – Visual Feedback, Review & AI Collaboration atarim-visual-collaboration
Autoship Cloud for WooCommerce Subscription Products autoship-cloud
Bandsintown Events bandsintown
Better Customer List for WooCommerce woo-better-customer-list
BigBuy Dropshipping Connector for WooCommerce bigbuy-wc-dropshipping-connector
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment booking-and-rental-manager-for-woocommerce
Booking Package booking-package
Booking Ultra Pro Appointments Booking Calendar Plugin booking-ultra-pro
Brevo SMTP – YaySMTP smtp-sendinblue
Business Card Block – Display Business or Personal Info in Card Format business-card-block
C9 Admin Dashboard c9-admin-dashboard
C9 Blocks c9-blocks
CanadaHelps Embedded Donation Form embedded-cdn
Categorized Gallery Plugin categorized-gallery
CATS Job Listings cats-job-listings
CHATLIVE – Support online chat chatlive
Coaching Staffs coaching-staffs
Contact Form Plugin contact-form-lite
Contact Us By Lord Linus contact-us-by-lord-linus
Content Blocks (Custom Post Widget) custom-post-widget
Cookie Notice Bar cookie-notice-bar
Coronavirus (COVID-19) Notice Message coronavirus-covid-19-notice-message
Cosmic Blocks (40+) Content Editor Blocks Collection cosmic-blocks
Countdown Timer timer-countdown
Countdown Timer Block – Animated Countdown for Events or Launches countdown-time
Counters Block – Animated Number Counters, Stats & Dynamic KPIs counters-block
Custom Post Type Date Archives custom-post-type-date-archives
DB Tables Import/Export db-tables-importexport
DeBounce Email Validator debounce-io-email-validator
Delivery Date Time & Pickup for WooCommerce byconsole-woo-order-delivery-time
Digihood HTML Sitemap wedesin-html-sitemap
Disable Auto Updates disable-auto-updates
Doctor Appointment Booking doctor-appointment-booking
Drivr Lite – Google Drive Plugin drivr-google-drive-file-picker
Easy Charts easy-charts
Easy Elementor Addons – Addons Pack for Elementor Page Builder easy-elementor-addons
Easy Form easy-form
Easy MLS Listings Import easy-mls-listings-import
Easy Notify Lite easy-notify-lite
Easy Quotes easy-quotes
Easypromos Plugin easypromos
Ecwid by Lightspeed Ecommerce Shopping Cart ecwid-shopping-cart
Education Addon for Elementor education-addon
Elementor Website Builder – more than just a page builder elementor
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor elementskit-lite
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files embed-any-document
Estatik Mortgage Calculator estatik-mortgage-calculator
Estatik Real Estate Plugin estatik
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) wp-event-solution
Events Calendar for GeoDirectory events-for-geodirectory
Events Manager – Calendar, Bookings, Tickets, and more! events-manager
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI everest-forms
EZ SQL Reports Shortcode Widget and DB Backup elisqlreports
Fast Flow fast-flow-dashboard
File Icons file-icons
File Uploads Addon for WooCommerce woo-addon-uploads
FileBird – WordPress Media Library Folders & File Manager filebird
Flagged Content flagged-content
Flashfader flashfader
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later flexible-wishlist
Flexmls® IDX Plugin flexmls-idx
flickr-slideshow-wrapper flickr-slideshow-wrapper
Fontsampler fontsampler
FormCraft formcraft3
Front End Users front-end-only-users
Frontend Admin by DynamiApps acf-frontend-form-element
FunnelKit – Funnel Builder for WooCommerce Checkout funnel-builder
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law gdpr-cookie-compliance
GetBookingsWP – Appointments Booking Calendar Plugin For WordPress get-bookings-wp
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) gift-voucher
Google Maps GPX Viewer google-maps-gpx-viewer
GPX Viewer gpx-viewer
Greenshift – animation and page builder blocks greenshift-animation-and-page-builder-blocks
Gtbabel gtbabel
Gumlet Video gumlet-video
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns essential-blocks
Head, Footer and Post Injections header-footer
Icon List Block – Add Icon-Based Lists with Custom Styles icon-list-block
igumbi Online Booking igumbi-online-booking
Indeed Ultimate Learning Pro ulp-duplicate-post-sql-timebased
Info Cards – Add Text and Media in Card Layouts info-cards
IP2Location Country Blocker ip2location-country-blocker
K Elements k-elements
Keap Official Opt-in Forms infusionsoft-official-opt-in-forms
Kush Micro News kush-micro-news
Legoeso PDF Manager legoeso-pdf-manager
Lenix Leads Collector lenix-elementor-leads-addon
Lexicata lexicata
Library Bookshelves library-bookshelves
Limit Bio limit-bio
List Urls list-urls
Live css css-live
Login & Register Customizer – Popup | Slider | Inline | WooCommerce easy-login-woocommerce
LTL Freight Quotes – ABF Freight Edition ltl-freight-quotes-abf-freight-edition
LTL Freight Quotes – GlobalTranz Edition ltl-freight-quotes-globaltranz-edition
LTL Freight Quotes – Old Dominion Edition ltl-freight-quotes-odfl-edition
LTL Freight Quotes – Purolator Edition ltl-freight-quotes-purolator-freight-edition
LTL Freight Quotes – R+L Carriers Edition ltl-freight-quotes-rl-edition
LTL Freight Quotes – SAIA Edition ltl-freight-quotes-saia-edition
LTL Freight Quotes – SEFL Edition ltl-freight-quotes-sefl-edition
LTL Freight Quotes – TForce Edition ltl-freight-quotes-ups-edition
magayo Lottery Results magayo-lottery-results
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin majestic-support
Mambo Importer mambo-joomla-importer
Maps for WP maps-for-wp
Market Exporter market-exporter
MemorialDay memorialday
Mini Course Generator | Embed mini-courses and interactive content mini-course-generator
Modal Window – create popup modal window modal-window
Mortgage Calculator / Loan Calculator mortgage-loan-calculator
MyTicket Events myticket-events
Newpost Catch newpost-catch
Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita
Open Hours – Easy Opening Hours open-hours
Option Editor option-editor
Order Limit For WooCommerce ( Free Version ) wc-order-limit-lite
Page and Post Lister page-and-post-lister
Pago por Redsys pago-redsys-tpv-grafreak
PeproDev Ultimate Invoice pepro-ultimate-invoice
Pie Calendar – Events Calendar Made Simple pie-calendar
Pie Register – User Registration, Profiles & Content Restriction pie-register
Pinpoint Booking System – Version 2 booking-system
Place Order Without Payment for WooCommerce wc-place-order-without-payment
Plug your WooCommerce into the largest catalog of customized print products from Helloprint helloprint
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls poll-maker
Pollin pollin
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) buddyforms
Post Grid post-grid
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App post-smtp
Prime Addons for Elementor prime-addons-for-elementor
ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities
Protected wp-login protected-wp-login
Pure Chat – Live Chat & More! pure-chat
QR Code for WooCommerce wc-qr-codes
Rapid Cache rapid-cache
Raptive Ads adthrive-ads
ravpage ravpage
Reaction Buttons reaction-buttons
Rebuild Permalinks rebuild-permalinks
Recipe Card Blocks Lite recipe-card-blocks-by-wpzoom
Reset – WordPress Database Reset Plugin reset
Residential Address Detection residential-address-detection
Responsive Addons for Elementor – Free Elementor Addons, Kits and Elementor Templates responsive-addons-for-elementor
Responsive Flickr Slideshow mobile-friendly-flickr-slideshow
Restrict Taxonomies restrict-taxonomies
Rife Extensions & Templates for Elementor rife-elementor-extensions
Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions s2member
S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) s3bubble-amazon-web-services-oembed-media-streaming-support
Saoshyant Slider saoshyant-slider
Schedule schedule
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more scratch-win-giveaways-for-website-facebook
Search with Typesense search-with-typesense
Secure Client Portal and Private File Sharing Plugin – User Private Files user-private-files
SEO Tools seo-automatic-seo-tools
Services Section Block – Showcase Service Details in Grid or Columns services-section
Shipmozo Courier Tracking webparex
Shopwarden – Automated WooCommerce monitoring & testing shopwarden
Show Me The Cookies show-me-the-cookies
Simple Charts simple-charts
Simple Email Subscriber simple-email-subscriber
Simple Map No Api simple-map-no-api
Simple Photo Feed simple-photo-feed
Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) simple-pricing-tables-vc-extension
Simple Signup Form simple-signup-form
Simplebooklet PDF Viewer and Embedder simplebooklet
Small Package Quotes – For Customers of FedEx small-package-quotes-fedex-edition
Small Package Quotes – Unishippers Edition small-package-quotes-unishippers-edition
Small Package Quotes – USPS Edition small-package-quotes-usps-edition
Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert
SMTP for Amazon SES – YaySMTP smtp-amazon-ses
SMTP for SendGrid – YaySMTP smtp-sendgrid
Social Sharing Plugin – Social Warfare social-warfare
Social Snap — Social Share Buttons & Click to Tweet socialsnap
SpeedSize Image & Video AI-Optimizer speedsize-ai-image-optimizer
SS Quiz ssquiz
Sticky Content – Make Any Section Sticky on Scroll sticky-menu-block
Store Locator Widget store-locator-widget
Strong Testimonials strong-testimonials
Subscribe2 – Form, Email Subscribers & Newsletters subscribe2
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress super-testimonial
SVG Support svg-support
System Dashboard system-dashboard
TCBD Tooltip tcbd-tooltip
Team Builder For WPBakery Page Builder(Formerly Visual Composer) team-builder-for-wpbakery-page-builder
Team Builder – Meet the Team team-display
Team Section Block – Showcase Team Members with Layout Options team-section
Terms Dictionary terms-dictionary
Theme File Duplicator theme-file-duplicator
Threepress threepress
Tour Master - Tour Booking, Travel, Hotel tourmaster
Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect
Tribulant Gallery Voting gallery-voting
Typed JS: A typewriter style animation mrlegend-typedjs
Ultimate Classified Listings – Classifieds, Directory & Marketplace ultimate-classified-listings
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member
UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included ultraembed-advanced-iframe
UMich OIDC Login umich-oidc-login
Uncode Core uncode-core
Unlimited Elements For Elementor unlimited-elements-for-elementor
User List user-list
Variable Inspector variable-inspector
Visualizer – Tables & Charts Manager with Built-in AI Generator visualizer
Web Accessibility by accessiBe accessibe
Web Stories Enhancer – Level Up Your Web Stories web-stories-enhancer
Widget BUY.BOX buybox-widget
Wired Impact Volunteer Management wired-impact-volunteer-management
Wishlist wishlist
Wonder Video Embed wonderplugin-video-embed
WOO Codice Fiscale woo-codice-fiscale
WooCommerce Food - Restaurant Menu & Food ordering woo-exfood
WooCommerce HTML5 Video woocommerce-html5-video
WOOEXIM – WooCommerce Export Import Plugin wooexim
WordPress Photo Gallery – Image Gallery photo-image-gallery
WordPress Portfolio Builder – Portfolio Gallery uber-grid
WoWPth wowpth
WP Click Info wp-click-info
WP e-Customers Beta wp-e-customers
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website wp-job-portal
WP Login Control wp-login-control
WP Media Category Management wp-media-category-management
WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps wp-multi-store-locator
WP Responsive Auto Fit Text wp-responsive-slab-text
WP Templata – WordPress Template Library for Elementor wptemplata
WP Video Posts wp-video-posts
WP Wiki Tooltip wp-wiki-tooltip
WP Yelp Review Slider wp-yelp-review-slider
WP-Appbox wp-appbox
WP-Asambleas wp-asambleas
WP-BibTeX wp-bibtex
WP-FormAssembly formassembly-web-forms
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services chatbot
WPExperts Square For GiveWP wpexperts-square-for-give
WPMobile.App wpappninja
WPO365 | MICROSOFT 365 GRAPH MAILER wpo365-msgraphmailer
WPPizza – A Restaurant Plugin wppizza
WPrequal wprequal
WPUpper Share Buttons wpupper-share-buttons
WPvivid — Backup, Migration & Staging wpvivid-backuprestore
WPYog Documents wpyog-documents
XV Random Quotes xv-random-quotes
Yay! Forms yayforms
YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports yaysmtp
YouTube Playlists with Schema jma-youtube-playlists-with-schema
Zigaform – Form Builder Lite zigaform-form-builder-lite
Zigaform – Price Calculator & Cost Estimation Form Builder Lite zigaform-calculator-cost-estimation-form-builder-lite
Ziggeo ziggeo


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
CarSpot – Dealership Wordpress Classified Theme carspot
Hostiko - Hosting WordPress & WHMCS Theme hostiko
Massive Dynamic massive-dynamic
MediCenter - Health Medical Clinic WordPress Theme medicenter
pearl pearl
PressMart - Modern Elementor WooCommerce WordPress Theme pressmart
Uncode uncode


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Flexmls® IDX Plugin [flexmls-idx]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
K Elements [k-elements]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Keap Official Opt-in Forms [infusionsoft-official-opt-in-forms]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
pearl [pearl]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
ravpage [ravpage]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Residential Address Detection [residential-address-detection]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Saoshyant Slider [saoshyant-slider]
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
SS Quiz [ssquiz]
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Place Order Without Payment for WooCommerce [wc-place-order-without-payment]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
A1POST.BG Shipping for WooCommerce [a1post-bg-shipping-for-woocommerce]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Doctor Appointment Booking [doctor-appointment-booking]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 23, 2025
Affected Software
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 23, 2025
Affected Software
Estatik Mortgage Calculator [estatik-mortgage-calculator]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Events Calendar for GeoDirectory [events-for-geodirectory]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Option Editor [option-editor]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Theme File Duplicator [theme-file-duplicator]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Feb 23, 2025
Affected Software
Massive Dynamic [massive-dynamic]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Easy Quotes [easy-quotes]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Gtbabel [gtbabel]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
IP2Location Country Blocker [ip2location-country-blocker]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
LTL Freight Quotes – ABF Freight Edition [ltl-freight-quotes-abf-freight-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
LTL Freight Quotes – GlobalTranz Edition [ltl-freight-quotes-globaltranz-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
LTL Freight Quotes – Old Dominion Edition [ltl-freight-quotes-odfl-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
LTL Freight Quotes – Purolator Edition [ltl-freight-quotes-purolator-freight-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
LTL Freight Quotes – R+L Carriers Edition [ltl-freight-quotes-rl-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
LTL Freight Quotes – SAIA Edition [ltl-freight-quotes-saia-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
LTL Freight Quotes – SEFL Edition [ltl-freight-quotes-sefl-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
LTL Freight Quotes – TForce Edition [ltl-freight-quotes-ups-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Small Package Quotes – For Customers of FedEx [small-package-quotes-fedex-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Small Package Quotes – USPS Edition [small-package-quotes-usps-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Small Package Quotes – Worldwide Express Edition [small-package-quotes-wwe-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Small Package Quotes – Worldwide Express Edition [small-package-quotes-wwe-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Trash Duplicate and 301 Redirect [trash-duplicate-and-301-redirect]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Uncode [uncode]
Researcher
CVSS Rating
7.3 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Custom Post Type Date Archives [custom-post-type-date-archives]
Researcher
CVSS Rating
7.3 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Show Me The Cookies [show-me-the-cookies]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
AcuGIS Leaflet Maps [mapfig-premium-leaflet-map-maker]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
FormCraft [formcraft3]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Kush Micro News [kush-micro-news]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Lenix Leads Collector [lenix-elementor-leads-addon]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Live css [css-live]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Mambo Importer [mambo-joomla-importer]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Rapid Cache [rapid-cache]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Brevo SMTP – YaySMTP [smtp-sendinblue]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
WPMobile.App [wpappninja]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Feb 18, 2025
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Categorized Gallery Plugin [categorized-gallery]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Doctor Appointment Booking [doctor-appointment-booking]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 19, 2025
Affected Software
Legoeso PDF Manager [legoeso-pdf-manager]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Simple Signup Form [simple-signup-form]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Theme File Duplicator [theme-file-duplicator]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Uncode [uncode]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Wishlist [wishlist]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
WP Media Category Management [wp-media-category-management]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
WPExperts Square For GiveWP [wpexperts-square-for-give]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
3D Photo Gallery [3d-photo-gallery]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
AMO Team Showcase [amo-team-showcase]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
AR for WordPress [ar-for-wordpress]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Bandsintown Events [bandsintown]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
C9 Admin Dashboard [c9-admin-dashboard]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
CATS Job Listings [cats-job-listings]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Coaching Staffs [coaching-staffs]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Contact Form Plugin [contact-form-lite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Drivr Lite – Google Drive Plugin [drivr-google-drive-file-picker]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Easy Charts [easy-charts]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Easy MLS Listings Import [easy-mls-listings-import]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Easypromos Plugin [easypromos]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Front End Users [front-end-only-users]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Greenshift – animation and page builder blocks [greenshift-animation-and-page-builder-blocks]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Gumlet Video [gumlet-video]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
igumbi Online Booking [igumbi-online-booking]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Library Bookshelves [library-bookshelves]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
Maps for WP [maps-for-wp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Mortgage Calculator / Loan Calculator [mortgage-loan-calculator]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
Newpost Catch [newpost-catch]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Easy Notify Lite [easy-notify-lite]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Responsive Flickr Slideshow [mobile-friendly-flickr-slideshow]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Simple Charts [simple-charts]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Simple Map No Api [simple-map-no-api]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Store Locator Widget [store-locator-widget]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
SVG Support [svg-support]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
TCBD Tooltip [tcbd-tooltip]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Threepress [threepress]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
UMich OIDC Login [umich-oidc-login]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Widget BUY.BOX [buybox-widget]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Wired Impact Volunteer Management [wired-impact-volunteer-management]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Wonder Video Embed [wonderplugin-video-embed]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
WP Responsive Auto Fit Text [wp-responsive-slab-text]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
WP Wiki Tooltip [wp-wiki-tooltip]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
WP-Appbox [wp-appbox]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
WP-Asambleas [wp-asambleas]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
WP-BibTeX [wp-bibtex]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
WP-FormAssembly [formassembly-web-forms]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Yay! Forms [yayforms]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
YouTube Playlists with Schema [jma-youtube-playlists-with-schema]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Zigaform – Form Builder Lite [zigaform-form-builder-lite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Zigaform – Price Calculator & Cost Estimation Form Builder Lite [zigaform-calculator-cost-estimation-form-builder-lite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
Ziggeo [ziggeo]
Researcher
CVSS Rating
6.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Uncode Core [uncode-core]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
.htaccess Login block [htaccess-login-block]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Adsmonetizer [adsensei-b30]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Affiliate Links Manager [affiliate-links-manager]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Better Customer List for WooCommerce [woo-better-customer-list]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Booking Package [booking-package]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Contact Us By Lord Linus [contact-us-by-lord-linus]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Countdown Timer [timer-countdown]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
DB Tables Import/Export [db-tables-importexport]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
DeBounce Email Validator [debounce-io-email-validator]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Digihood HTML Sitemap [wedesin-html-sitemap]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Easy Form [easy-form]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Fast Flow [fast-flow-dashboard]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
File Icons [file-icons]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Flagged Content [flagged-content]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Flashfader [flashfader]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
flickr-slideshow-wrapper [flickr-slideshow-wrapper]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Fontsampler [fontsampler]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Frontend Admin by DynamiApps [acf-frontend-form-element]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Google Maps GPX Viewer [google-maps-gpx-viewer]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Lexicata [lexicata]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
Limit Bio [limit-bio]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
Limit Bio [limit-bio]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
List Urls [list-urls]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
magayo Lottery Results [magayo-lottery-results]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
MemorialDay [memorialday]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Pago por Redsys [pago-redsys-tpv-grafreak]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Pollin [pollin]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Protected wp-login [protected-wp-login]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Raptive Ads [adthrive-ads]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Rebuild Permalinks [rebuild-permalinks]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Restrict Taxonomies [restrict-taxonomies]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) [s3bubble-amazon-web-services-oembed-media-streaming-support]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
Schedule [schedule]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
SEO Tools [seo-automatic-seo-tools]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Simple Email Subscriber [simple-email-subscriber]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Small Package Quotes – Unishippers Edition [small-package-quotes-unishippers-edition]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Terms Dictionary [terms-dictionary]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Tribulant Gallery Voting [gallery-voting]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
User List [user-list]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Variable Inspector [variable-inspector]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
WOO Codice Fiscale [woo-codice-fiscale]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
WooCommerce HTML5 Video [woocommerce-html5-video]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
WoWPth [wowpth]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
WoWPth [wowpth]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
WP Click Info [wp-click-info]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
WP e-Customers Beta [wp-e-customers]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
WP Login Control [wp-login-control]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
WP Video Posts [wp-video-posts]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
WPYog Documents [wpyog-documents]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
XV Random Quotes [xv-random-quotes]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Zigaform – Price Calculator & Cost Estimation Form Builder Lite [zigaform-calculator-cost-estimation-form-builder-lite]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Unpatched
Published
Feb 19, 2025
Affected Software
Cookie Notice Bar [cookie-notice-bar]
CVSS Rating
5.5 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Reaction Buttons [reaction-buttons]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Market Exporter [market-exporter]
CVSS Rating
5.4 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
Page and Post Lister [page-and-post-lister]
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Simple Photo Feed [simple-photo-feed]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Uncode [uncode]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Actionwear products sync [actionwear-products-sync]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 23, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
BigBuy Dropshipping Connector for WooCommerce [bigbuy-wc-dropshipping-connector]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 20, 2025
Affected Software
C9 Blocks [c9-blocks]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
LTL Freight Quotes – GlobalTranz Edition [ltl-freight-quotes-globaltranz-edition]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Feb 21, 2025
Affected Software
MyTicket Events [myticket-events]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
PeproDev Ultimate Invoice [pepro-ultimate-invoice]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
Post Grid [post-grid]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 18, 2025
Affected Software
Raptive Ads [adthrive-ads]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Small Package Quotes – Unishippers Edition [small-package-quotes-unishippers-edition]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Strong Testimonials [strong-testimonials]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
Delivery Date Time & Pickup for WooCommerce [byconsole-woo-order-delivery-time]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
Indeed Ultimate Learning Pro [ulp-duplicate-post-sql-timebased]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
4.9 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Pollin [pollin]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
WP Yelp Review Slider [wp-yelp-review-slider]
Researcher
CVSS Rating
4.7 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Coronavirus (COVID-19) Notice Message [coronavirus-covid-19-notice-message]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Apptivo Business Site [apptivo-business-site]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
Disable Auto Updates [disable-auto-updates]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 22, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
FormCraft [formcraft3]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
WPrequal [wprequal]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 19, 2025
Affected Software
Prime Addons for Elementor [prime-addons-for-elementor]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
Recipe Card Blocks Lite [recipe-card-blocks-by-wpzoom]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 17, 2025
Affected Software
SpeedSize Image & Video AI-Optimizer [speedsize-ai-image-optimizer]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 23, 2025
Affected Software
System Dashboard [system-dashboard]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Feb 17, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Feb 20, 2025
Affected Software
WPUpper Share Buttons [wpupper-share-buttons]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Feb 18, 2025
Affected Software
XV Random Quotes [xv-random-quotes]
Researcher
CVSS Rating
2.7 (Low)
Patch Status
Patched
Published
Feb 21, 2025
Affected Software
GPX Viewer [gpx-viewer]
CVSS Rating
2.7 (Low)
Patch Status
Patched
Published
Feb 22, 2025
Affected Software
Search with Typesense [search-with-typesense]
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments