Wordfence Intelligence Weekly WordPress Vulnerability Report (June 30, 2025 to July 6, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🌞 Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!


Last week, there were 133 vulnerabilities disclosed in 126 WordPress Plugins and 16 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 55 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 27,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-858 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 73
Unpatched 60


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 69
High Severity 50
Critical Severity 13


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 37
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 21
Missing Authorization 16
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 14
Unrestricted Upload of File with Dangerous Type 9
Cross-Site Request Forgery (CSRF) 7
Deserialization of Untrusted Data 7
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
Server-Side Request Forgery (SSRF) 4
Improper Control of Generation of Code ('Code Injection') 3
Incorrect Privilege Assignment 3
External Control of File Name or Path 2
Exposure of Sensitive Information to an Unauthorized Actor 1
Improper Access Control 1
Improper Authentication 1
Improper Authorization 1
Improper Privilege Management 1
URL Redirection to Untrusted Site ('Open Redirect') 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
9
9
8
7
6
6
6
5
5
4
4
3
3
3
3
3
3
3
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
(Simply) Guest Author Name guest-author-name
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager ap-plugin-scripteo
AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o aibuddy-openai-chatgpt
AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine
All-in-One Addons for Elementor – WidgetKit widgetkit-for-elementor
Allmart allmart-core
Amazon Products to WooCommerce import-products-to-wc
Auto Thickbox auto-thickbox
Aviation Weather from NOAA aviation-weather-from-noaa
Awesome Gallery awesome-gallery
Awesome Wp Image Gallery awesome-wp-image-gallery
Backwp backwp
Beautiful Cookie Consent Banner beautiful-and-responsive-cookie-consent
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder bit-form
BlossomThemes Social Feed blossomthemes-instagram-feed
Bold Page Builder bold-page-builder
Booking Calendar Contact Form booking-calendar-contact-form
Booking calendar, Appointment Booking System booking-calendar
Booking X – Appointment and Reservation Availability Calendar booking-x
bSecure – Your Universal Checkout bsecure
Bulk Featured Image bulk-featured-image
Card flip image slideshow card-flip-image-slideshow
Carousel Slider carousel-slider
Case Theme User case-theme-user
CF7 7 Mailchimp Add-on CF7-mailchimp-addon
Chatra Live Chat + ChatBot + Cart Saver chatra-live-chat
Click & Pledge CONNECT click-pledge-connect
CM Search And Replace – Optimize content edits with a powerful search and replace tool cm-on-demand-search-and-replace
CMSMasters Content Composer cmsmasters-content-composer
Contact Form 7 reCAPTCHA contact-form-7-recaptcha
Contact Us Page – Contact People contact-us-page-contact-people
Cool fade popup cool-fade-popup
CouponXxL Custom Post Types couponxxl-cpt
CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables
Custom Login And Signup Widget custom-login-and-signup-widget
Database Addon for Contact Form 7 – CFDB7 contact-form-cfdb7
DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer 3d-flipbook-dflip-lite
Divi Builder divi-builder
Divi Torque Lite – Divi Modules for the Divi Builder & Theme addons-for-divi
DocCheck Login doccheck-login
Download Plugin download-plugin
Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-uploads-wc-pro
Easy 3D Viewer woo-3d-viewer
Easy Elements Hider easy-elements-hider
Easy Image Gallery easy-image-gallery
Easy restaurant menu manager easy-pdf-restaurant-menu-upload
Easy Stripe – Tips, Payments, and Donations easy-stripe
Element Pack – Widgets, Templates & Addons for Elementor bdthemes-element-pack-lite
Email Address Security by WebEmailProtector webemailprotector
Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite
Event List eventlist
EventON (Pro) - WordPress Virtual Event Calendar Plugin eventON
Everest Forms - Frontend Listing everest-forms-frontend-listing
fluXtore Funnel Builder fluxtore
Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator
Frontend File Manager Plugin nmedia-user-file-uploader
FW Gallery – Photo, video, audio media presentation and management system with players and slideshow fw-gallery
Gallery Widget gallery-widget
GoZen Forms gozen-forms
Groundhogg — CRM, Newsletters, and Marketing Automation groundhogg
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor gutentor
Happy Addons for Elementor happy-elementor-addons
iFrame Images Gallery wp-iframe-images-gallery
JKDEVKIT jkdevkit
Lead Form Data Collection to CRM wp-leads-builder-any-crm
Leyka leyka
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes lifterlms
LMSACE Connect – WooCommerce Moodle™ LMS Integration lmsace-connect
Magic Buttons for Elementor magic-buttons-for-elementor
Masteriyo LMS PRO learning-management-system-pro
Melapress File Monitor website-file-changes-monitor
MF Plus WPML mf-plus-wpml
MobiLoud – WordPress Mobile Apps – Convert your WordPress Website to Native Mobile Apps mobiloud-mobile-app-plugin
My Reservation System my-reservation-system
NGG Smart Image Search ngg-smart-image-search
Opal Estate Pro – Property Management and Submission opal-estate-pro
OwnerRez ownerrez
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
PayMaster for WooCommerce woocommerce-paymaster-gateway-019
Paytiko for WooCommerce paytiko
PeepSo Core: Groups peepso-groups
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery nextgen-gallery
Pixelating image slideshow gallery pixelating-image-slideshow-gallery
Posts Slider Shortcode posts-slider-shortcode
PowerFolio – Portfolio & Image Gallery for Elementor portfolio-elementor
Premium Addons for Elementor – Powerful Elementor Templates & Widgets premium-addons-for-elementor
Premmerce premmerce
Printcart Web to Print Product Designer for WooCommerce printcart-integration
PrivateContent - Mail Actions private-content-mail-actions
ProcessingJS for WordPress processingjs-for-wp
PublishPress Blocks – Block Controls, Block Visibility, Block Permissions advanced-gutenberg
Qwizcards | online quizzes and flashcards qwiz-online-quizzes-and-flashcards
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! radio-station
RD Contacto rd-wapp
Robo Gallery – Photo & Image Slider robo-gallery
Service Finder Bookings sf-booking
Shortcodes Ultimate – Content Elements shortcodes-ultimate
Smart Docs smart-docs
Soumettre.fr soumettre-fr
Subscribe to Download subscribe-to-download
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder supreme-modules-for-divi
Testimonials Showcase testimonials-showcase
Trust Payments Gateway for WooCommerce (JavaScript Library) trust-payments-gateway-3ds2
Ultra Addons for Contact Form 7 ultimate-addons-for-contact-form-7
Uncode Core uncode-core
UNIVERSAM universam-demo
URL Shortener Plugin For WordPress exact-links
Video Gallery Block video-gallery-block
Video List Manager video-list-manager
VikRentCar Car Rental Management System vikrentcar
WC Pickup Store wc-pickup-store
WooCommerce Product Multi-Action Woo-product-multiaction
WooCommerce Shop Page Builder dzs-wootable
WP Compress – Instant Performance & Speed Optimization wp-compress-image-optimizer
WP fancybox wp-fancybox
WP Firebase Push Notification wp-push-notification-firebase
WP Front-end login and register wp-front-end-login-and-register
WP Human Resource Management hrm
WP Pipes wp-pipes
WP Travel Gutenberg Blocks wp-travel-blocks
WP Video Lightbox wp-video-lightbox
WP Visitor Statistics (Real Time Traffic) wp-stats-manager
WPQuiz wpquiz
WPvivid — Backup, Migration & Staging wpvivid-backuprestore
yContributors ycontributors
YouTube Embed, Playlist and Popup by WpDevArt youtube-video-player


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Alone – Charity Multipurpose Non-profit WordPress Theme alone
Amwerk - Industry & Corporate Business WordPress Theme amwerk
Classiera – Classified Ads WordPress Theme classiera
CouponXxL couponxxl
Divi Divi
Divi Extra extra
Diza - Pharmacy Store Elementor WooCommerce Theme diza
Elessi - WooCommerce AJAX WordPress Theme - RTL support elessi-theme
Home Villas | Real Estate WordPress Theme homevillas-real-estate
Houzez houzez
Kossy - Minimalist eCommerce WordPress Theme kossy
LMS - Education WordPress Theme lms
LogisticsHub - Logistics and Transportation WordPress Theme logistics-hub
Networker - Tech News WordPress Theme with Dark Mode networker
OceanWP oceanwp
Vikinger vikinger


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Click & Pledge CONNECT [click-pledge-connect]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
CouponXxL [couponxxl]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Drag and Drop Multiple File Upload (Pro) - WooCommerce [drag-and-drop-file-uploads-wc-pro]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jun 30, 2025
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Masteriyo LMS PRO [learning-management-system-pro]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jun 30, 2025
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Unpatched
Published
Jul 6, 2025
Affected Software
WP Pipes [wp-pipes]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Jul 4, 2025
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Jul 2, 2025
Affected Software
JKDEVKIT [jkdevkit]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jun 30, 2025
Affected Software
Aviation Weather from NOAA [aviation-weather-from-noaa]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Case Theme User [case-theme-user]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
CMSMasters Content Composer [cmsmasters-content-composer]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Event List [eventlist]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 2, 2025
Affected Software
Everest Forms - Frontend Listing [everest-forms-frontend-listing]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Houzez [houzez]
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Leyka [leyka]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 2, 2025
Affected Software
Premmerce [premmerce]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
PrivateContent - Mail Actions [private-content-mail-actions]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 4, 2025
Affected Software
Subscribe to Download [subscribe-to-download]
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 6, 2025
Affected Software
UNIVERSAM [universam-demo]
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Vikinger [vikinger]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
WooCommerce Product Multi-Action [Woo-product-multiaction]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
WP Travel Gutenberg Blocks [wp-travel-blocks]
Researcher
CVSS Rating
8.0 (High)
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 1, 2025
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
GoZen Forms [gozen-forms]
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
GoZen Forms [gozen-forms]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jun 30, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
NGG Smart Image Search [ngg-smart-image-search]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Video List Manager [video-list-manager]
Researcher
CVSS Rating
7.3 (High)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jul 3, 2025
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Amazon Products to WooCommerce [import-products-to-wc]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Bulk Featured Image [bulk-featured-image]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Custom Login And Signup Widget [custom-login-and-signup-widget]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Download Plugin [download-plugin]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Contact Us Page – Contact People [contact-us-page-contact-people]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Cool fade popup [cool-fade-popup]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Gallery Widget [gallery-widget]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
iFrame Images Gallery [wp-iframe-images-gallery]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Pixelating image slideshow gallery [pixelating-image-slideshow-gallery]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
WPQuiz [wpquiz]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 4, 2025
Affected Software
(Simply) Guest Author Name [guest-author-name]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
Allmart [allmart-core]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jun 30, 2025
Affected Software
Booking Calendar Contact Form [booking-calendar-contact-form]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Card flip image slideshow [card-flip-image-slideshow]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Easy restaurant menu manager [easy-pdf-restaurant-menu-upload]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jun 30, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Magic Buttons for Elementor [magic-buttons-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Magic Buttons for Elementor [magic-buttons-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 2, 2025
Affected Software
Awesome Wp Image Gallery [awesome-wp-image-gallery]
Awesome Gallery [awesome-gallery]
Easy Image Gallery [easy-image-gallery]
Easy 3D Viewer [woo-3d-viewer]
WP Video Lightbox [wp-video-lightbox]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 4, 2025
Affected Software
OwnerRez [ownerrez]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
PayMaster for WooCommerce [woocommerce-paymaster-gateway-019]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 2, 2025
Affected Software
PeepSo Core: Groups [peepso-groups]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Posts Slider Shortcode [posts-slider-shortcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
ProcessingJS for WordPress [processingjs-for-wp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Smart Docs [smart-docs]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jun 30, 2025
Affected Software
Ultra Addons for Contact Form 7 [ultimate-addons-for-contact-form-7]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Uncode Core [uncode-core]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Jul 4, 2025
Affected Software
Video Gallery Block [video-gallery-block]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
WP fancybox [wp-fancybox]
Researcher
CVSS Rating
6.3 (Medium)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Lead Form Data Collection to CRM [wp-leads-builder-any-crm]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Backwp [backwp]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Beautiful Cookie Consent Banner [beautiful-and-responsive-cookie-consent]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
CSS3 Vertical Web Pricing Tables [css3_vertical_web_pricing_tables]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
My Reservation System [my-reservation-system]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Testimonials Showcase [testimonials-showcase]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Jul 2, 2025
Affected Software
Qwizcards | online quizzes and flashcards [qwiz-online-quizzes-and-flashcards]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
WP Front-end login and register [wp-front-end-login-and-register]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
yContributors [ycontributors]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 4, 2025
Affected Software
CF7 7 Mailchimp Add-on [CF7-mailchimp-addon]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
DocCheck Login [doccheck-login]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 4, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
MF Plus WPML [mf-plus-wpml]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
WC Pickup Store [wc-pickup-store]
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Easy Elements Hider [easy-elements-hider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jun 30, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Contact Form 7 reCAPTCHA [contact-form-7-recaptcha]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Frontend File Manager Plugin [nmedia-user-file-uploader]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Melapress File Monitor [website-file-changes-monitor]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jun 30, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
RD Contacto [rd-wapp]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
WP Firebase Push Notification [wp-push-notification-firebase]
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments