Wordfence Intelligence Weekly WordPress Vulnerability Report (July 14, 2025 to July 20, 2025)


📱 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📱

🌞 Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!


Last week, there were 164 vulnerabilities disclosed in 138 WordPress Plugins and 6 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 49 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 28,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

  • WAF-RULE-859 – Data redacted while we work with the vendor on a patch.

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 123
Unpatched 41


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 129
High Severity 19
Critical Severity 16


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 70
Missing Authorization 25
Cross-Site Request Forgery (CSRF) 17
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 13
Exposure of Sensitive Information to an Unauthorized Actor 9
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 7
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 6
Deserialization of Untrusted Data 5
Unrestricted Upload of File with Dangerous Type 4
External Control of File Name or Path 2
Improper Control of Generation of Code ('Code Injection') 2
Authentication Bypass Using an Alternate Path or Channel 1
Authorization Bypass Through User-Controlled Key 1
Improper Privilege Management 1
Server-Side Request Forgery (SSRF) 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
26
16
13
8
7
7
7
6
4
4
4
4
3
3
3
3
3
3
3
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
aapanel WP Toolkit aapanel-wp-toolkit
Affiliate Reviews affiliate-reviews
Alike - WordPress Custom Post Comparison alike
All In One Lightbox – show any media in beautiful popups lightbox-block
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) azon-addon-js-composer
Animator – Scroll Triggered Animations scroll-triggered-animations
AntiSpam for Contact Form 7 cf7-antispam
Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky
Attachment Manager attachment-manager
Avada (Fusion) Builder fusion-builder
Avishi WP PayPal Payment Button avishi-wp-paypal-payment-button
bbPress Move Topics bbp-move-topics
bbPress Notify (No-Spam) bbpress-notify-nospam
Bears Backup bears-backup
Block Editor Gallery Slider for WordPress – Image Slider, Gallery Carousel & Lightbox Plugin block-editor-gallery-slider
Bold Page Builder bold-page-builder
Brandfolder – Digital Asset Management Simplified. brandfolder
Breeze Checkout breeze-checkout
Brevo SMTP – YaySMTP smtp-sendinblue
Chatbox Manager wa-chatbox-manager
Cloud SAML SSO – Single Sign On Login cloud-sso-single-sign-on
CM Pop-Up – Create engaging popups to capture attention and boost interaction cm-pop-up-banners
Companion Auto Update companion-auto-update
Copymatic – AI Content Writer & Generator copymatic
CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online coschool
Cost Calculator ql-cost-calculator
Counter live visitors for WooCommerce counter-visitor-for-woocommerce
Coupon Affiliates – Affiliate Plugin for WooCommerce woo-coupon-usage
Crowdfunding for WooCommerce crowdfunding-for-woocommerce
Custom API for WP custom-api-for-wp
Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce
DB Backup db-backup
Easy Appointment Booking & Scheduling System – Webba Booking Calendar webba-booking-lite
Easy Elementor Addons – Addons Pack for Elementor Page Builder easy-elementor-addons
ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic) elex-bulk-edit-products-prices-attributes-for-woocommerce-basic
Email Attachment by Order Status & Products email-attachment-by-order-status-products
EPay.bg Payments epaybg-payments
Fade Slider fade-slider
FG Drupal to WordPress fg-drupal-to-wp
FluentSnippets – High-Performance Code Snippets, Header & Footer Code, Custom CSS & PHP Code Manager easy-code-manager
FoodMenu - WP Creative Restaurant Menu Showcase WooCommerce dzs-restaurantmenu
Formality formality
Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions ghostkit
GSheetConnector – WooCommerce Google Sheets Connector, Export Orders & Products wc-gsheetconnector
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor gutentor
hpb seo plugin for WordPress hpbseo
HT Contact Form – Drag & Drop Form Builder for WordPress ht-contactform
HTML5 Radio Player - WPBakery Page Builder Addon lbg_radio_player_addon_visual_composer
IDonatePro - Blood Donation, Request And Donor Management WordPress Plugin idonate-pro
Image Wall image-wall
Import CDN-Remote Images import-cdn-remote-images
Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms integration-for-contact-form-7-and-google-sheets
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms integration-for-contact-form-7-and-pipedrive
JetBlocks for Elementor jet-blocks
JetBlog jet-blog
JetElements jet-elements
JetEngine jet-engine
JetFormBuilder — Dynamic Blocks Form Builder jetformbuilder
JetMenu jet-menu
JetPopup jet-popup
JetSearch jet-search
JetSmartFilters jet-smart-filters
JetTabs jet-tabs
JetTricks jet-tricks
JetWooBuilder jet-woo-builder
KBx Pro Ultimate knowledgebase-helpdesk-pro
Knowledge Base knowledgebase
lbg-audio4-html5-shoutcast lbg-audio4-html5-shoutcast
LeadBI Plugin for WordPress leadbi
Listly: Listicles For WordPress listly
Live Stream Badger live-stream-badger
LoginPress Pro loginpress-pro
Madara - Core madara-core
Malcure Malware Shield — Removal, Repair, Monitor wp-malware-removal
Map My Locations map-my-locations
Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits master-addons
MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro
Maya Business Plugin paymaya-checkout-for-woocommerce
Media Library Assistant media-library-assistant
Mediabay - WordPress Media Library Folders mediabay
MORKVA Vchasno Kasa Integration mrkv-vchasno-kasa
Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer
News Kit Addons For Elementor news-kit-elementor-addons
Newsletters newsletters-lite
OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) stepbyteservice-openstreetmap
PartnerskĂœ systĂ©m Martinus martinus-partnersky-system
Pinterest Automatic wp-pinterest-automatic
Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship biteship
ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities
Real Estate Property 2025 Create Your Own Fields and Search Bar real-estate-right-now
Residential Address Detection residential-address-detection
Responsive Addons for Elementor – Free Elementor Addons, Kits and Elementor Templates responsive-addons-for-elementor
Restaurant Menu and Food Ordering mp-restaurant-menu
Restrict File Access restrict-file-access
Revolution Video Player With Bottom Playlist WordPress Plugin - YouTube/Vimeo/Self-Hosted Support revolution_video_player
Robokassa payment gateway for Woocommerce robokassa
Ruven Themes: Shortcodes ruven-themes-shortcodes
School Management System for Wordpress school-management
Shortcodes Ultimate – Content Elements shortcodes-ultimate
SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support lbg-audio8-html5-radio-ads
Simple Link Directory Pro qc-simple-link-directory
Simple Stripe Checkout simple-stripe-checkout
Site.pro for WooCommerce b1-accounting
SMTP for Amazon SES – YaySMTP smtp-amazon-ses
SMTP for SendGrid – YaySMTP smtp-sendgrid
SMTP2GO for WordPress – Email Made Easy smtp2go
Stop and Block bots plugin Anti-bots antibots
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers woocommerce-exporter
Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools woocommerce-store-toolkit
Strong Testimonials strong-testimonials
Temporarily Hidden Content temporarily-hidden-content
Terms descriptions terms-descriptions
Testimonial Post type testimonial-post-type
The Plus Addons for Elementor Page Builder Pro theplus_elementor_addon
Theme Builder For Elementor theme-builder-for-elementor
ThemeREX Addons trx_addons
Ultimate WP Mail ultimate-wp-mail
Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer
Universal Video Player - Addon for WPBakery Page Builder lbg_universal_video_player_addon_visual_composer
URL Shortener Plugin For WordPress exact-links
Useful Tab Block – Responsive & AMP-Compatible useful-tab-block-responsive-amp-compatible
Vertical scroll image slideshow gallery vertical-scroll-image-slideshow-gallery
Videopack video-embed-thumbnail-generator
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments wallet-system-for-woocommerce
Welcart e-Commerce usc-e-shop
Widget for Google Reviews business-reviews-wp
WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet woocommerce-refund-and-exchange
WooCommerce Shop Page Builder dzs-wootable
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) delicious-recipes
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce wp-event-manager
WP Hide Post — Hide Posts, Pages, Custom Post Types, and Control Products Visibility for WooCommerce wp-post-hide
WP Smart Flexslider wp-smart-flexslider
WP-Click-Tracker wp-click-track
WPAdverts – Classifieds Plugin wpadverts
YayExtra – WooCommerce Extra Product Options yayextra
Youtube Vimeo Video Player and Slider WP Plugin video_player_youtube_vimeo
Zuppler Online Ordering zuppler-online-ordering


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Alone – Charity Multipurpose Non-profit WordPress Theme alone
Goza - Nonprofit Charity WordPress Theme goza-theme
GymBase Theme Classes gymbase_classes
Hestia hestia
Houzez houzez
Visual Art | Gallery WordPress Theme visual-arts


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jul 16, 2025
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Bears Backup [bears-backup]
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jul 14, 2025
Affected Software
Custom User Registration Fields for WooCommerce [user-registration-plugin-for-woocommerce]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Formality [formality]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
LoginPress Pro [loginpress-pro]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Attachment Manager [attachment-manager]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Madara - Core [madara-core]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
aapanel WP Toolkit [aapanel-wp-toolkit]
Researcher
CVSS Rating
8.2 (High)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
Counter live visitors for WooCommerce [counter-visitor-for-woocommerce]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 16, 2025
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 16, 2025
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 15, 2025
Affected Software
KBx Pro Ultimate [knowledgebase-helpdesk-pro]
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 14, 2025
Affected Software
Restrict File Access [restrict-file-access]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 15, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Widget for Google Reviews [business-reviews-wp]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 15, 2025
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Custom API for WP [custom-api-for-wp]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
JetSearch [jet-search]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
Ultimate WP Mail [ultimate-wp-mail]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 15, 2025
Affected Software
CVSS Rating
6.6 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
CVSS Rating
6.6 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Site.pro for WooCommerce [b1-accounting]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic) [elex-bulk-edit-products-prices-attributes-for-woocommerce-basic]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
GymBase Theme Classes [gymbase_classes]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 15, 2025
Affected Software
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Pinterest Automatic [wp-pinterest-automatic]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
Affiliate Reviews [affiliate-reviews]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
Avada (Fusion) Builder [fusion-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Crowdfunding for WooCommerce [crowdfunding-for-woocommerce]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 18, 2025
Affected Software
EPay.bg Payments [epaybg-payments]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Image Wall [image-wall]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetElements [jet-elements]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetPopup [jet-popup]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetPopup [jet-popup]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetSearch [jet-search]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetSmartFilters [jet-smart-filters]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetTabs [jet-tabs]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetTricks [jet-tricks]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetWooBuilder [jet-woo-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 18, 2025
Affected Software
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 18, 2025
Affected Software
Live Stream Badger [live-stream-badger]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Map My Locations [map-my-locations]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
Media Library Assistant [media-library-assistant]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 18, 2025
Affected Software
PartnerskĂœ systĂ©m Martinus [martinus-partnersky-system]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Ruven Themes: Shortcodes [ruven-themes-shortcodes]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 14, 2025
Affected Software
Strong Testimonials [strong-testimonials]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 18, 2025
Affected Software
Temporarily Hidden Content [temporarily-hidden-content]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Testimonial Post type [testimonial-post-type]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 18, 2025
Affected Software
ThemeREX Addons [trx_addons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Useful Tab Block – Responsive & AMP-Compatible [useful-tab-block-responsive-amp-compatible]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Vertical scroll image slideshow gallery [vertical-scroll-image-slideshow-gallery]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Videopack [video-embed-thumbnail-generator]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Apollo - Sticky Full Width HTML5 Audio Player [lbg-audio5-html5-shoutcast-sticky]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 18, 2025
Affected Software
Avishi WP PayPal Payment Button [avishi-wp-paypal-payment-button]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 16, 2025
Affected Software
bbPress Move Topics [bbp-move-topics]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 19, 2025
Affected Software
bbPress Notify (No-Spam) [bbpress-notify-nospam]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 14, 2025
Affected Software
Email Attachment by Order Status & Products [email-attachment-by-order-status-products]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 14, 2025
Affected Software
Fade Slider [fade-slider]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 15, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
HTML5 Radio Player - WPBakery Page Builder Addon [lbg_radio_player_addon_visual_composer]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
JetBlog [jet-blog]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 18, 2025
Affected Software
JetSearch [jet-search]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 16, 2025
Affected Software
Multimedia Playlist Slider Addon for WPBakery Page Builder [lbg_vp_youtube_vimeo_addon_visual_composer]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 15, 2025
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
lbg-audio4-html5-shoutcast [lbg-audio4-html5-shoutcast]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 15, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 20, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Simple Link Directory Pro [qc-simple-link-directory]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 20, 2025
Affected Software
Simple Stripe Checkout [simple-stripe-checkout]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 14, 2025
Affected Software
WP Smart Flexslider [wp-smart-flexslider]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Universal Video Player - Addon for WPBakery Page Builder [lbg_universal_video_player_addon_visual_composer]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Universal Video Player - Addon for WPBakery Page Builder [lbg-universal-video-player-addon-visual-composer]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 14, 2025
Affected Software
WP-Click-Tracker [wp-click-track]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Zuppler Online Ordering [zuppler-online-ordering]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Jul 14, 2025
Affected Software
Companion Auto Update [companion-auto-update]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
FG Drupal to WordPress [fg-drupal-to-wp]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Welcart e-Commerce [usc-e-shop]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 19, 2025
Affected Software
Breeze Checkout [breeze-checkout]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Hestia [hestia]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetSmartFilters [jet-smart-filters]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 17, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Maya Business Plugin [paymaya-checkout-for-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Residential Address Detection [residential-address-detection]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 15, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 18, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 18, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Brevo SMTP – YaySMTP [smtp-sendinblue]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Knowledge Base [knowledgebase]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Jul 17, 2025
Affected Software
Terms descriptions [terms-descriptions]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Animator – Scroll Triggered Animations [scroll-triggered-animations]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Chatbox Manager [wa-chatbox-manager]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Cost Calculator [ql-cost-calculator]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 16, 2025
Affected Software
DB Backup [db-backup]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Houzez [houzez]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Import CDN-Remote Images [import-cdn-remote-images]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetElements [jet-elements]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetEngine [jet-engine]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetMenu [jet-menu]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetPopup [jet-popup]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetTabs [jet-tabs]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetTricks [jet-tricks]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
JetWooBuilder [jet-woo-builder]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
News Kit Addons For Elementor [news-kit-elementor-addons]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Newsletters [newsletters-lite]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025
Affected Software
Theme Builder For Elementor [theme-builder-for-elementor]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 16, 2025


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments