Wordfence Intelligence Weekly WordPress Vulnerability Report (August 25, 2025 to August 31, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🌞 Spring into Summer with Wordfence! Now through September 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!

💉 Participate in the SQLsplorer Challenge! Now through September 22, 2025, all SQL Injection vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier AND earn a 20% bonus on all SQL Injection vulnerability submissions.


Last week, there were 157 vulnerabilities disclosed in 128 WordPress Plugins and 27 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 54 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 28,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 103
Unpatched 54


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 108
High Severity 47
Critical Severity 2


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 52
Missing Authorization 24
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 19
Cross-Site Request Forgery (CSRF) 14
Deserialization of Untrusted Data 11
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 7
Unrestricted Upload of File with Dangerous Type 4
Exposure of Sensitive Information to an Unauthorized Actor 3
Improper Privilege Management 3
Improper Control of Generation of Code ('Code Injection') 2
Server-Side Request Forgery (SSRF) 2
Improper Authentication 1
Improper Authorization 1
Improper Handling of Insufficient Permissions or Privileges 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
Inadequate Encryption Strength 1
Incorrect Authorization 1
Incorrect Privilege Assignment 1
URL Redirection to Untrusted Site ('Open Redirect') 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
18
14
10
9
8
6
5
5
4
4
4
4
4
3
3
3
3
3
3
3
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
ACF Recent Posts Widget acf-recent-posts-widget
Add Code To Head add-code-to-head
Addon Elements for Elementor (formerly Elementor Addon Elements) addon-elements-for-elementor-page-builder
Advance Seat Reservation Management for WooCommerce scw-seat-reservation
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available) aftership-woocommerce-tracking
Ajax Search Lite – Live Search & Filter ajax-search-lite
All Bootstrap Blocks all-bootstrap-blocks
All-in-One WP Migration and Backup all-in-one-wp-migration
Amministrazione Trasparente amministrazione-trasparente
Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version
BetPress betpress
bidorbuy Store Integrator bidorbuystoreintegrator
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection stopbadbots
Blog Designer PRO for WordPress blog-designer-pro
Bold Page Builder bold-page-builder
Booking Calendar booking
Booking System Trafft booking-system-trafft
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools woocommerce-jetpack
bSlider – Create Responsive Image, Post, Product, and Video Sliders b-slider
Captcha.eu captcha-eu
Chartbeat chartbeat
Chatbox Manager wa-chatbox-manager
Cookie Notice & Consent cookie-notice-consent
Customer Support Ticket System & Helpdesk wp-ticket
Dokan Pro dokan-pro
Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms
Dynamic AJAX Product Filters for WooCommerce dynamic-ajax-product-filters-for-woocommerce
E-cab Taxi Booking Manager for Woocommerce ecab-taxi-booking-manager
ElementInvader Addons for Elementor elementinvader-addons-for-elementor
Employee Directory – Staff & Team Directory employee-directory
Employee Spotlight – Team Member Showcase & Meet the Team Plugin employee-spotlight
Epeken All Kurir for Woocommerce epeken-all-kurir
Epic Review epic-review
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar mage-eventpress
Event List eventlist
Events Addon for Elementor events-addon-for-elementor
Exertio Framework exertio-framework
Feeds for TikTok – Keep Your Site Fresh with Your Latest Videos b-tiktok-feed
File Manager, Code Editor, and Backup by Managefy softdiscover-db-file-manager
Goal Tracker for Patreon goal-tracker-for-patreon
Google XML News Sitemap plugin gn-xml-sitemap
Gutenify – Visual Site Builder Blocks & Site Templates gutenify
Hello Followers - Social Counter Plugin for WordPress hellofollowers
Hotel Listings hotel-listing
Houzez CRM houzez-crm
iATS Online Forms iats-online-forms
Image Gallery Block – Showcase Photos in Stunning Responsive Grids 3d-image-gallery
Info Cards – present key information in elegant card layouts info-cards
Instant Breaking News instant-breaking-news
Institutions Directory institutions-directory
Invisible Optin invisible-optin
Javo Core javo-core
JS Archive List jquery-archive-list-widget
Lazy Load for Videos lazy-load-for-videos
Link View link-view
List Sub Pages list-sub-pages
LWSCache lwscache
MultiSite Clone Duplicator multisite-clone-duplicator
Nest Addons nest-addons
Newsletter subscription optin module newsletter-subscription-widget-for-sendblaster
NextGEN Gallery Search nextgen-gallery-search-galleries
Nifty Backups – WordPress Backup & Restore nifty-backups
Ninja Forms – The Contact Form Builder That Grows With You ninja-forms
Ocean Extra ocean-extra
OSM Map Widget for Elementor osm-map-elementor
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE otter-blocks
Page Manager for Elementor page-manager-for-elementor
Parallax Section Block – give any section scroll-stopping depth parallax-section
Password Reset with Code for WordPress REST API bdvs-password-reset
PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms
Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress
Post Grid Gutenberg Blocks – PostX ultimate-post
Post Type Converter post-type-converter
PPWP – Password Protect Pages password-protect-page
Premium Age Verification / Restriction for WordPress age-restriction
Printeers Print & Ship invition-print-ship
Pro Bulk Watermark Plugin for WordPress pro-watermark
Pronamic Google Maps pronamic-google-maps
Quiz Maker, Poll Maker & Survey Maker by Opinion Stage social-polls-by-opinionstage
Ray Enterprise Translation lingotek-translation
Related Posts Lite related-posts-lite
Responsive Mobile-Friendly Tooltip responsive-mobile-friendly-tooltip
RingCentral Communications Plugin – FREE rccp-free
Savyour Affiliate Partner savyour-affiliate-partner
SEO For Images seo-for-images
Simple Contact Form Plugin for WordPress – WP Easy Contact wp-easy-contact
Simple Download Monitor simple-download-monitor
Simple Page Access Restriction simple-page-access-restriction
SiteSEO – SEO Simplified siteseo
Slider Revolution revslider
Small Package Quotes – USPS Edition small-package-quotes-usps-edition
Solace Extra solace-extra
SUMO Memberships for WooCommerce sumomemberships
Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers sunshine-photo-cart
Table Editor wp-table-editor
TablePress – Tables in WordPress made easy tablepress
Task Manager task-manager
Theme Blvd Widget Areas theme-blvd-widget-areas
Theme Switcher Reloaded theme-switcher-reloaded
Transcoder transcoder
Tripadvisor Shortcode tripadvisor-shortcode
UiCore Elements – Free widgets and templates for Elementor uicore-elements
Ultimate Tag Warrior Importer utw-importer
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator
Unlimited Elements For Elementor unlimited-elements-for-elementor
UPC/EAN/GTIN Barcode Generator/Importer upc-ean-barcode-generator
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP userswp
Vibes vibes
Video Gallery – YouTube Gallery, Playlist & Video Grid youtube-showcase
Video Share VOD – Turnkey Video Site Builder Script video-share-vod
WooCommerce csv import export extendons-eo-wooimport-export
WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay
WooCommerce Photo Reviews Premium woocommerce-photo-reviews
WordPress Automatic Plugin wp-automatic
WordPress HTML custom-html-bodyhead
WP Bulk Delete wp-bulk-delete
WP Hotel Booking wp-hotel-booking
WP Thumbtack Review Slider wp-thumbtack-review-slider
WP ULike Pro wp-ulike-pro
WPAvatar wpavatar
Xagio SEO & AEO – AI SEO for Google Rankings & AI Visibility xagio-seo
XM-Backup xm-backup
XmasB Quotes xmasb-quotes
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons
Xpro Theme Builder For Elementor – FREE xpro-theme-builder
Yahoo! WebPlayer yahoo-media-player
YayPricing – WooCommerce Dynamic Pricing & Discounts yaypricing
Zephyr Project Manager zephyr-project-manager


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
777 triple-seven
AI Hub - Startup & Technology WordPress Theme aihub
ArcHub - Architecture and Interior Design WordPress Theme archub
Aromatica - Cafe & Coffee Shop WordPress Theme aromatica
Blanka - One Page WordPress Theme blanka-wp
Cars4Rent | Auto Rental & Taxi WordPress Theme + RTL cars4rent
Creatify creatify
Famita - Minimalist WooCommerce WordPress Theme famita
FinAg - Creative & Finance Agency PSD Template finag
Golo - City Travel Guide WordPress Theme golo
Houzez houzez
Hub - Responsive Multi-Purpose WordPress Theme hub
Indutri indutri
Ireca - Car Rental Boat, Bike, Vehicle, Calendar WordPress Theme ireca
Jannah - Newspaper Magazine News BuddyPress AMP jannah
Lione - Creative Portfolio WordPress Theme lione
Magazine Saga magazine-saga
Makeaholic - Beauty Cosmetics WordPress Theme makeaholic
Neresa - Elementor WordPress Theme neresa-wp
Noo JobMonster noo-jobmonster
Nuss - Hotel Booking WordPress nuss
Pin = Pinterest Style / Personal Masonry Blog / Front-end Submission pin-wp
Spock - Medical Doctor Dentist & Beauty WordPress Theme spock
Uncode uncode
WooHoo Newspaper Magazine Theme woohoo
WooTour woo-tour
Ziston - Directory Listing WordPress Theme ziston


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Drag and Drop File Upload for Elementor Forms [drag-and-drop-file-upload-for-elementor-forms]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
Dokan Pro [dokan-pro]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
Event List [eventlist]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
Hotel Listings [hotel-listing]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 27, 2025
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
777 [triple-seven]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 26, 2025
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
Creatify [creatify]
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 25, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 30, 2025
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 26, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Houzez [houzez]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 30, 2025
Affected Software
Indutri [indutri]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 27, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 25, 2025
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Magazine Saga [magazine-saga]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 28, 2025
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 30, 2025
Affected Software
Ray Enterprise Translation [lingotek-translation]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 29, 2025
Affected Software
Task Manager [task-manager]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
UPC/EAN/GTIN Barcode Generator/Importer [upc-ean-barcode-generator]
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
WooCommerce csv import export [extendons-eo-wooimport-export]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 25, 2025
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Aug 30, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
JS Archive List [jquery-archive-list-widget]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Nest Addons [nest-addons]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
Vibes [vibes]
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
bidorbuy Store Integrator [bidorbuystoreintegrator]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Aug 29, 2025
Affected Software
Cookie Notice & Consent [cookie-notice-consent]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Aug 29, 2025
Affected Software
Researcher
CVSS Rating
6.6 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Small Package Quotes – USPS Edition [small-package-quotes-usps-edition]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Exertio Framework [exertio-framework]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Aug 28, 2025
Affected Software
iATS Online Forms [iats-online-forms]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
Slider Revolution [revslider]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2025
Affected Software
WooCommerce Photo Reviews Premium [woocommerce-photo-reviews]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 30, 2025
Affected Software
ACF Recent Posts Widget [acf-recent-posts-widget]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Booking System Trafft [booking-system-trafft]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
Chartbeat [chartbeat]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Chatbox Manager [wa-chatbox-manager]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Dynamic AJAX Product Filters for WooCommerce [dynamic-ajax-product-filters-for-woocommerce]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Dynamic AJAX Product Filters for WooCommerce [dynamic-ajax-product-filters-for-woocommerce]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
Events Addon for Elementor [events-addon-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Lazy Load for Videos [lazy-load-for-videos]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Link View [link-view]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
List Sub Pages [list-sub-pages]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2025
Affected Software
Ocean Extra [ocean-extra]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
OSM Map Widget for Elementor [osm-map-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Responsive Mobile-Friendly Tooltip [responsive-mobile-friendly-tooltip]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Simple Download Monitor [simple-download-monitor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Solace Extra [solace-extra]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Transcoder [transcoder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Unlimited Elements For Elementor [unlimited-elements-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
WordPress HTML [custom-html-bodyhead]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
WPAvatar [wpavatar]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
BetPress [betpress]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Captcha.eu [captcha-eu]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 30, 2025
Affected Software
Epic Review [epic-review]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 30, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Houzez [houzez]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 30, 2025
Affected Software
Institutions Directory [institutions-directory]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Invisible Optin [invisible-optin]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 31, 2025
Affected Software
Noo JobMonster [noo-jobmonster]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2025
Affected Software
MultiSite Clone Duplicator [multisite-clone-duplicator]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Newsletter subscription optin module [newsletter-subscription-widget-for-sendblaster]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
NextGEN Gallery Search [nextgen-gallery-search-galleries]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Podlove Podcast Publisher [podlove-podcasting-plugin-for-wordpress]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Savyour Affiliate Partner [savyour-affiliate-partner]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
Theme Blvd Widget Areas [theme-blvd-widget-areas]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Theme Switcher Reloaded [theme-switcher-reloaded]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Uncode [uncode]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
WooTour [woo-tour]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
WP ULike Pro [wp-ulike-pro]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
XmasB Quotes [xmasb-quotes]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
Yahoo! WebPlayer [yahoo-media-player]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Aug 30, 2025
Affected Software
Amministrazione Trasparente [amministrazione-trasparente]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Pronamic Google Maps [pronamic-google-maps]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
All Bootstrap Blocks [all-bootstrap-blocks]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2025
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
Javo Core [javo-core]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2025
Affected Software
Printeers Print & Ship [invition-print-ship]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2025
Affected Software
WooCommerce Payment Gateway for Saferpay [woocommerce-payment-gateway-for-saferpay]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2025
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
Add Code To Head [add-code-to-head]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
All-in-One WP Migration and Backup [all-in-one-wp-migration]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Goal Tracker for Patreon [goal-tracker-for-patreon]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Tripadvisor Shortcode [tripadvisor-shortcode]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
WP Thumbtack Review Slider [wp-thumbtack-review-slider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Houzez CRM [houzez-crm]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Instant Breaking News [instant-breaking-news]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Page Manager for Elementor [page-manager-for-elementor]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Post Type Converter [post-type-converter]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 25, 2025
Affected Software
PPWP – Password Protect Pages [password-protect-page]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2025
Affected Software
Printeers Print & Ship [invition-print-ship]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2025
Affected Software
Related Posts Lite [related-posts-lite]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
SEO For Images [seo-for-images]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Simple Page Access Restriction [simple-page-access-restriction]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
Table Editor [wp-table-editor]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 28, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
WP Bulk Delete [wp-bulk-delete]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2025
Affected Software
WP Hotel Booking [wp-hotel-booking]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 25, 2025
Affected Software
XM-Backup [xm-backup]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2025
Affected Software
Zephyr Project Manager [zephyr-project-manager]
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments