Wordfence Intelligence Weekly WordPress Vulnerability Report (July 7, 2025 to July 13, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🌞 Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!


Last week, there were 110 vulnerabilities disclosed in 78 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 44 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 27,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 61
Unpatched 49


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 65
High Severity 34
Critical Severity 11


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 36
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 17
Missing Authorization 13
Deserialization of Untrusted Data 8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 6
Unrestricted Upload of File with Dangerous Type 6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
Improper Privilege Management 4
Authentication Bypass Using an Alternate Path or Channel 2
Authorization Bypass Through User-Controlled Key 2
Exposure of Sensitive Information to an Unauthorized Actor 2
Improper Control of Generation of Code ('Code Injection') 2
Server-Side Request Forgery (SSRF) 2
Cross-Site Request Forgery (CSRF) 1
External Control of File Name or Path 1
Improper Neutralization of Formula Elements in a CSV File 1
Improper Neutralization of Special Elements Used in a Template Engine 1
Unverified Password Change 1
Use of Hard-coded Credentials 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
10
10
8
8
7
7
6
4
4
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) azon-addon-js-composer
AnyComment anycomment
Auto Login After Registration auto-login-after-registration
BeeTeam368 Extensions beeteam368-extensions
Billingo Official for WooCommerce billingo
Broken Link Notifier broken-link-notifier
Click & Pledge WPJobBoard click-pledge-wpjobboard
Contact Form 7 Editor Button cf7-editor-button
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery
CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online coschool
CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids
Dot html,php,xml etc pages dot-htmlphpxml-etc-pages
Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite
Events Manager – Calendar, Bookings, Tickets, and more! events-manager
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media evergreen-content-poster
Friends friends
FunnelKit – Funnel Builder for WooCommerce Checkout funnel-builder
gAppointments - Appointment booking addon for Gravity Forms gAppointments
GB Forms DB gb-forms-db
Guest Support guest-support
Gwolle Guestbook gwolle-gb
HTML5 Radio Player - WPBakery Page Builder Addon lbg-cleverbakery
Infility Global infility-global
Internal Linking of Related Contents internal-linking-of-related-contents
JetEngine jet-engine
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor kadence-blocks
Lana Downloads Manager lana-downloads-manager
Learts Addons learts-addons
Lightbox & Modal Popup WordPress Plugin – FooBox foobox-image-lightbox
LoginWP - Pro loginwp-pro
Media Folder media-folder
Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce
Modern Events Calendar Lite modern-events-calendar-lite
Multi-language Responsive Contact Form responsive-contact-form
Pakke EnvĂ­os pakke
Pay with Contact Form 7 pay-with-contact-form-7
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel foogallery
Premium Age Verification / Restriction for WordPress age-restriction
Premium SEO Pack – WP SEO Plugin premium-seo-pack
Pro Bulk Watermark Plugin for WordPress pro-watermark
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More product-xml-feeds-for-woocommerce
ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities
Profiler – What Slowing Down Your WP profiler-what-slowing-down
PW WooCommerce On Sale! pw-woocommerce-on-sale
RSFirewall! rsfirewall
ShareBang, Ultimate Social Share Buttons for WordPress sharebang
Shortcode Generator shortcode-generator
Simple Featured Image simple-featured-image
Simple Link Directory Pro qc-simple-link-directory
Site Chat on Telegram site-chat-on-telegram
SMu Manual DoFollow manuall-dofollow
Super Store Finder superstorefinder-wp
Support Board supportboard
Support Ticket System for WooCommerce support-ticket-system-for-woocommerce
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz sureforms
Templazee – A collection of Blocks and Template Library templazee
Tennis Court Bookings tennis-court-bookings
The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis profitori
Torod – The smart shipping and delivery portal for e-shops and retailers torod
Ultimate Push Notifications ultimate-push-notifications
Ultimate Video Player WordPress & WooCommerce Plugin fwduvp
URL Shortener Plugin For WordPress exact-links
WCFM – Frontend Manager for WooCommerce wc-frontend-manager
Widget for Google Reviews business-reviews-wp
Wishlist for WooCommerce: Multi Wishlists Per Customer wish-list-for-woocommerce
WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields
Wordpress Auto Spinner wp-auto-spinner
wordpress-flat-countdown wordpress-flat-countdown
WP Pipes wp-pipes
WP Register Profile With Shortcode wp-register-profile-with-shortcode
WP Super Edit wp-super-edit
WP-BusinessDirectory – Business directory plugin for WordPress wp-businessdirectory
WPBookit wpbookit
WPC Smart Compare for WooCommerce woo-smart-compare
WPCode Content Ratio wpcode-content-ratio
wpForo Forum wpforo
WPGYM - Wordpress Gym Management System gym-management


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Billey - Creative Portfolio & Agency Elementor WordPress Theme billey
electrician electrician
fwdevp fwdevp
Hillter - Responsive Hotel Booking for WordPress hillter
Houzez houzez
Invico - WordPress Consulting Business Theme invico
ListingEasy - Directory Listing WordPress Theme listingeasy
Medizin - Medical WooCommerce Theme medizin
Noisa noisa
Nokri – Job Board WordPress Theme nokri
Nuss - Hotel Booking WordPress nuss
Ofiz - WordPress Business Consulting Theme ofiz
Sala - Startup & SaaS WordPress Theme sala
SmartSEO | SEO & Marketing HTML Theme smartseo
Travel Booking WordPress Theme traveler
Woodmart woodmart
Yogi - Health Beauty & Yoga WordPress Theme yogi


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
GB Forms DB [gb-forms-db]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jul 11, 2025
Affected Software
Support Ticket System for WooCommerce [support-ticket-system-for-woocommerce]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jul 11, 2025
Affected Software
Medical Prescription Attachment Plugin for WooCommerce [medical-prescription-attachment-plugin-for-woocommerce]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
Simple Link Directory Pro [qc-simple-link-directory]
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 8, 2025
Affected Software
Support Board [supportboard]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 8, 2025
Affected Software
Support Board [supportboard]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
WPBookit [wpbookit]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
BeeTeam368 Extensions [beeteam368-extensions]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Jul 8, 2025
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
wordpress-flat-countdown [wordpress-flat-countdown]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Widget for Google Reviews [business-reviews-wp]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Woodmart [woodmart]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
WPBookit [wpbookit]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 8, 2025
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 12, 2025
Affected Software
AnyComment [anycomment]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 8, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Site Chat on Telegram [site-chat-on-telegram]
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Super Store Finder [superstorefinder-wp]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 11, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 9, 2025
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
Friends [friends]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 13, 2025
Affected Software
JetEngine [jet-engine]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 8, 2025
Affected Software
Learts Addons [learts-addons]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 8, 2025
Affected Software
Noisa [noisa]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 7, 2025
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 11, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
Click & Pledge WPJobBoard [click-pledge-wpjobboard]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
WP Pipes [wp-pipes]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 11, 2025
CVSS Rating
7.3 (High)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Woodmart [woodmart]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Broken Link Notifier [broken-link-notifier]
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jul 10, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
fwdevp [fwdevp]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
WP Register Profile With Shortcode [wp-register-profile-with-shortcode]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Simple Featured Image [simple-featured-image]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Woodmart [woodmart]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Auto Login After Registration [auto-login-after-registration]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Contact Form 7 Editor Button [cf7-editor-button]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 11, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
CSS3 Compare Pricing Tables for WordPress [css3_web_pricing_tables_grids]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Dot html,php,xml etc pages [dot-htmlphpxml-etc-pages]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
electrician [electrician]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 9, 2025
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 11, 2025
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 9, 2025
Affected Software
Gwolle Guestbook [gwolle-gb]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
Infility Global [infility-global]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Media Folder [media-folder]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Pay with Contact Form 7 [pay-with-contact-form-7]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Shortcode Generator [shortcode-generator]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
SMu Manual DoFollow [manuall-dofollow]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 9, 2025
Affected Software
WP Super Edit [wp-super-edit]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 11, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Tennis Court Bookings [tennis-court-bookings]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Wordpress Auto Spinner [wp-auto-spinner]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
WPCode Content Ratio [wpcode-content-ratio]
Researcher
CVSS Rating
5.9 (Medium)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
Modern Events Calendar Lite [modern-events-calendar-lite]
Researcher(s): Unknown
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Jul 9, 2025
Affected Software
Lana Downloads Manager [lana-downloads-manager]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Jul 9, 2025
Affected Software
wpForo Forum [wpforo]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 8, 2025
Affected Software
Internal Linking of Related Contents [internal-linking-of-related-contents]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
LoginWP - Pro [loginwp-pro]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Multi-language Responsive Contact Form [responsive-contact-form]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 11, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Profiler – What Slowing Down Your WP [profiler-what-slowing-down]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 8, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 7, 2025
Affected Software
Ultimate Push Notifications [ultimate-push-notifications]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Woodmart [woodmart]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Jul 8, 2025
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Jul 11, 2025
Affected Software
RSFirewall! [rsfirewall]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 12, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 11, 2025
Affected Software
Houzez [houzez]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 10, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 7, 2025
Affected Software
PW WooCommerce On Sale! [pw-woocommerce-on-sale]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 9, 2025
CVSS Rating
4.1 (Medium)
Patch Status
Patched
Published
Jul 10, 2025
Affected Software
Broken Link Notifier [broken-link-notifier]


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments