Wordfence Intelligence Weekly WordPress Vulnerability Report (May 12, 2025 to May 18, 2025)


📢 In case you missed it, Wordfence just published its annual WordPress security report for 2024. Read it now to learn more about the evolving risk landscape of WordPress so you can keep your sites protected in 2025 and beyond.  


Last week, there were 148 vulnerabilities disclosed in 125 WordPress Plugins and 10 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 59 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 26,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 92
Unpatched 56


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 109
High Severity 26
Critical Severity 13


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Missing Authorization 33
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 30
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 23
Cross-Site Request Forgery (CSRF) 17
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 8
Unrestricted Upload of File with Dangerous Type 7
Deserialization of Untrusted Data 6
Exposure of Sensitive Information to an Unauthorized Actor 5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
Authorization Bypass Through User-Controlled Key 4
Improper Control of Generation of Code ('Code Injection') 4
Improper Authorization 2
External Control of File Name or Path 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
Incorrect Authorization 1
Server-Side Request Forgery (SSRF) 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
27
16
8
8
7
6
5
5
5
4
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
6Storage Rentals 6storage-rentals
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager ap-plugin-scripteo
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) all-in-one-seo-pack
AlT Monitoring alt-monitoring
Apollo lbg-audio7_html5_full_width_sticky_pro
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress latepoint
Aptivada for WP aptivada-for-wp
Arconix Shortcodes arconix-shortcodes
Audio Comments Plugin audio-comments
B2i Investor Tools b2i-investor-tools
BERTHA AI. Your AI co-pilot for WordPress and Chrome bertha-ai-free
BNS Twitter Follow Button bns-twitter-follow-button
Bold Page Builder bold-page-builder
Bon Toolkit bon-toolkit
Booking Calendar booking
Broadstreet broadstreet
Bux Woocommerce bux-woocommerce
Chameleon HTML5 Audio Player With/Without Playlist lbg-audio1-html5
CountDown Pro WP Plugin circular_countdown
Crawlomatic Multipage Scraper Post Generator crawlomatic-multipage-scraper-post-generator
CSS3 Accordions for WordPress css3_accordions
CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids
CSS3 Tooltips for WordPress css3_tooltips
CURCY - WooCommerce Multi Currency - Currency Switcher woocommerce-multi-currency
Custom 404 Pro custom-404-pro
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs wp-expand-tabs-free
Dokan Pro dokan-pro
Dot html,php,xml etc pages dot-htmlphpxml-etc-pages
Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms
Echo RSS Feed Post Generator rss-feed-post-generator-echo
EG-Series eg-series
Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin bdthemes-element-pack
Estatik Mortgage Calculator estatik-mortgage-calculator
Eventer eventer
EventON (Pro) - WordPress Virtual Event Calendar Plugin eventON
EventON – Events Calendar eventon-lite
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin experto-cta-widget
Facturante – Facturación Electrónica facturante
FancyBox for WordPress fancybox-for-wordpress
FAT Services Booking fat-services-booking
File Manager Advanced Shortcode file-manager-advanced-shortcode
File Manager Advanced Shortcode advanced-file-manager-pro-premium
File Provider file-provider
Front End Users front-end-only-users
Frontend Dashboard frontend-dashboard
Grand Conference Theme Custom Post Type grandconference-custom-post
Import Export For WooCommerce import-export-for-woocommerce
Interview interview
Jetpack Debug Helper jetpack-debug-helper
Jupiter X Core jupiterx-core
Magic Responsive Slider and Carousel WordPress magic-carousel
MapSVG mapsvg
MapSVG – Vector maps, Image maps, Google Maps mapsvg-lite-interactive-vector-maps
Multimedia Responsive Carousel with Image Video Audio Support multimedia-carousel
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions dc-woocommerce-multi-vendor
Nasa Core nasa-core
Newsletter – Send awesome emails from WordPress newsletter
Newsletters newsletters-lite
Ninja Forms Webhooks ninja-forms-webhooks
Ninja Tables Pro ninja-tables-pro
Opal Woo Custom Product Variation opal-woo-custom-product-variation
PeepSo Core: File Uploads peepso-files
Pinterest Automatic wp-pinterest-automatic
Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder
Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider post-slider-and-carousel
Posts per Cat posts-per-cat
Printcart Web to Print Product Designer for WooCommerce printcart-integration
ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities
Push notification for Mobile and Web app push-notification-mobile-and-web-app
QuickCal quickcal
Radio Player Shoutcast & Icecast WordPress Plugin audio4-html5
Rankie - Wordpress Rank Tracker Plugin valvepress-rankie
Real Cookie Banner Pro real-cookie-banner-pro
Real Cookie Banner: GDPR & ePrivacy Cookie Consent real-cookie-banner
Relevanssi Premium relevanssi-premium
Relevanssi – A Better Search relevanssi
Responsive HTML5 Audio Player PRO With Playlist lbg-audio2-html5
RS WP Book Showcase – A Complete Book Catalogue & Library System rs-wp-books-showcase
Salon Booking Pro salon-booking-plugin-pro-cc
Salon Booking System – Free Version salon-booking-system
SEO Flow by LupsOnline lupsonline-link-netwerk
SEO合集(支持百度/Google/Bing/头条推送) baiduseo
Sharespine Woocommerce Connector sharespine-woocommerce-connector
ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب shayanweb-admin-fontchanger
Short URL shorten-url
SHOUT lbg-audio8-html5-radio_ads
Simple Link Directory Pro qc-simple-link-directory
Spotlight Social Feeds – Block, Shortcode, and Widget (Premium) spotlight-social-photo-feeds-premium
STAGGS – Product Configurator Toolkit staggs
Sticky HTML5 Music Player lbg-audio3-html5
Sticky Radio Player lbg-audio5-html5-shoutcast_sticky
Subaccounts for WooCommerce subaccounts-for-woocommerce
Tainacan tainacan
TI WooCommerce Wishlist ti-woocommerce-wishlist
TicketBAI Facturas para WooCommerce wp-ticketbai
TNC FlipBook pdf-viewer-for-wordpress
Tours tours
UberSlider uber-classic
UiPress lite | Effortless custom dashboards, admin themes and pages uipress-lite
UltraAddons for Elementor ultraaddons-elementor-lite
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator
Uncanny Toolkit for LearnDash uncanny-learndash-toolkit
ValidateCertify Free validar-certificados-de-cursos
Video Player & FullScreen Video Background universal-video-player-and-bg
WC Affiliate – WooCommerce Affiliate Plugin wc-affiliate
WCPOS – Point of Sale (POS) plugin for WooCommerce woocommerce-pos
Weluka Lite weluka-lite
WHMpress - WHMCS WordPress Integration Plugin whmpress
Wise Chat wise-chat
Wishlist wishlist
Wordpress Auto Spinner wp-auto-spinner
WordPress Events Calendar Registration & Tickets wpeventplus
WP Content Security Plugin wp-content-security-policy
WP JobHunt wp-jobhunt
WP Notes Widget wp-notes-widget
WP Ultimate Tours Builder WP_UltimateToursBuilder
WP-Members Membership Plugin wp-members
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance wp-optimize
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden wp2leads
WPBot Pro Wordpress Chatbot wpbot-pro
WPC Product Options for WooCommerce wpc-product-options
WPCHURCH - Church Management System for Wordpress church-management
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell wpfunnels
WPGYM - Wordpress Gym Management System gym-management
X Addons for Elementor x-addons-elementor


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Acerola - Ultra Minimalist Agency Theme acerola
AnyWhere Elementor Pro anywhere-elementor-pro
Bimber - Viral Magazine WordPress Theme bimber
HotStar – MultiPurpose Business WordPress Theme hotstar
Plant | Gardening & Houseplants WordPress Theme plant
Rozario - Restaurant & Food WordPress Theme rozario
Seven Stars - Modern Responsive MultiPurpose Theme sevenstars
Spare - Ultimate MultiPurpose LESS Theme spare
The Business - Powerful One Page Biz Theme nrgbusiness
TheGem thegem


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Crawlomatic Multipage Scraper Post Generator [crawlomatic-multipage-scraper-post-generator]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Echo RSS Feed Post Generator [rss-feed-post-generator-echo]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 16, 2025
Affected Software
TI WooCommerce Wishlist [ti-woocommerce-wishlist]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 14, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
May 12, 2025
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
May 13, 2025
Affected Software
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
FAT Services Booking [fat-services-booking]
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Estatik Mortgage Calculator [estatik-mortgage-calculator]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Nasa Core [nasa-core]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
QuickCal [quickcal]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
May 12, 2025
Affected Software
Subaccounts for WooCommerce [subaccounts-for-woocommerce]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
May 12, 2025
Affected Software
TheGem [thegem]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Eventer [eventer]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
File Provider [file-provider]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
May 12, 2025
Affected Software
Relevanssi Premium [relevanssi-premium]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Wise Chat [wise-chat]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
WP JobHunt [wp-jobhunt]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
May 13, 2025
Affected Software
FancyBox for WordPress [fancybox-for-wordpress]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
May 14, 2025
Affected Software
File Manager Advanced Shortcode [file-manager-advanced-shortcode]
File Manager Advanced Shortcode [advanced-file-manager-pro-premium]
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
WP Content Security Plugin [wp-content-security-policy]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Apollo [lbg-audio7_html5_full_width_sticky_pro]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
CountDown Pro WP Plugin [circular_countdown]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Interview [interview]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
MapSVG [mapsvg]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
May 12, 2025
Affected Software
Newsletters [newsletters-lite]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
May 12, 2025
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Short URL [shorten-url]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
SHOUT [lbg-audio8-html5-radio_ads]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Sticky HTML5 Music Player [lbg-audio3-html5]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Sticky Radio Player [lbg-audio5-html5-shoutcast_sticky]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
UberSlider [uber-classic]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Aptivada for WP [aptivada-for-wp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 17, 2025
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
Bon Toolkit [bon-toolkit]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Broadstreet [broadstreet]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Dokan Pro [dokan-pro]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
EG-Series [eg-series]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Jupiter X Core [jupiterx-core]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
MapSVG [mapsvg]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Ninja Tables Pro [ninja-tables-pro]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 15, 2025
Affected Software
Posts per Cat [posts-per-cat]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 15, 2025
Affected Software
TI WooCommerce Wishlist [ti-woocommerce-wishlist]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
TNC FlipBook [pdf-viewer-for-wordpress]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
UltraAddons for Elementor [ultraaddons-elementor-lite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
Weluka Lite [weluka-lite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
WP Notes Widget [wp-notes-widget]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
X Addons for Elementor [x-addons-elementor]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
AlT Monitoring [alt-monitoring]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Arconix Shortcodes [arconix-shortcodes]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Audio Comments Plugin [audio-comments]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
May 12, 2025
Affected Software
B2i Investor Tools [b2i-investor-tools]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Dot html,php,xml etc pages [dot-htmlphpxml-etc-pages]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
May 13, 2025
Affected Software
Grand Conference Theme Custom Post Type [grandconference-custom-post]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Import Export For WooCommerce [import-export-for-woocommerce]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
SEO Flow by LupsOnline [lupsonline-link-netwerk]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
May 13, 2025
Affected Software
Ninja Forms Webhooks [ninja-forms-webhooks]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Unpatched
Published
May 12, 2025
Affected Software
BNS Twitter Follow Button [bns-twitter-follow-button]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 18, 2025
Affected Software
Bux Woocommerce [bux-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 15, 2025
Affected Software
Drag and Drop File Upload for Elementor Forms [drag-and-drop-file-upload-for-elementor-forms]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 15, 2025
Affected Software
Front End Users [front-end-only-users]
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 15, 2025
Affected Software
Jetpack Debug Helper [jetpack-debug-helper]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 12, 2025
Affected Software
Opal Woo Custom Product Variation [opal-woo-custom-product-variation]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Push notification for Mobile and Web app [push-notification-mobile-and-web-app]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Simple Link Directory Pro [qc-simple-link-directory]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Tainacan [tainacan]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Video Player & FullScreen Video Background [universal-video-player-and-bg]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
May 13, 2025
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
May 12, 2025
Affected Software
Real Cookie Banner Pro [real-cookie-banner-pro]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
6Storage Rentals [6storage-rentals]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
AnyWhere Elementor Pro [anywhere-elementor-pro]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CSS3 Compare Pricing Tables for WordPress [css3_web_pricing_tables_grids]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 13, 2025
Affected Software
Custom 404 Pro [custom-404-pro]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Eventer [eventer]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 14, 2025
Affected Software
File Provider [file-provider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
MapSVG [mapsvg]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Pinterest Automatic [wp-pinterest-automatic]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
QuickCal [quickcal]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Salon Booking Pro [salon-booking-plugin-pro-cc]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 15, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Sharespine Woocommerce Connector [sharespine-woocommerce-connector]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 12, 2025
Affected Software
TheGem [thegem]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 15, 2025
Affected Software
Tours [tours]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
ValidateCertify Free [validar-certificados-de-cursos]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Wishlist [wishlist]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
Wishlist [wishlist]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 16, 2025
Affected Software
Wordpress Auto Spinner [wp-auto-spinner]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
May 16, 2025
Affected Software
WP Ultimate Tours Builder [WP_UltimateToursBuilder]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
May 15, 2025


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments