Wordfence Intelligence Weekly WordPress Vulnerability Report (September 8, 2025 to September 14, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🚀  Operation: Maximum Impact Challenge! Now through November 10, 2025, earn 2X bounty rewards for all in-scope submissions in software with at least 5,000 active installs and fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!

💉 Participate in the SQLsplorer Challenge! Now through September 22, 2025, all SQL Injection vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier AND earn a 20% bonus on all SQL Injection vulnerability submissions.


Last week, there were 124 vulnerabilities disclosed in 105 WordPress Plugins and 16 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 48 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 28,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 75
Unpatched 49


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 98
High Severity 22
Critical Severity 4


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 48
Missing Authorization 20
Cross-Site Request Forgery (CSRF) 19
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 13
Improper Control of Generation of Code ('Code Injection') 4
Unrestricted Upload of File with Dangerous Type 4
Authorization Bypass Through User-Controlled Key 3
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 3
Exposure of Sensitive Information to an Unauthorized Actor 2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
Server-Side Request Forgery (SSRF) 2
Absolute Path Traversal 1
External Control of File Name or Path 1
Incorrect Authorization 1
Use of Hard-coded Credentials 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
11
9
8
7
6
6
6
5
5
5
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce
Admin in English with Switch admin-in-english-with-switch
Advanced Settings 3 advanced-settings
Ajax WooSearch ajax-woosearch
All in one Minifier all-in-one-minifier
Analytics Reduce Bounce Rate analytics-unbounce
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating authorsy
Auto Save Remote Images (Drafts) auto-save-remote-images-drafts
AutoCatSet autocatset
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress automatorwp
azurecurve BBCode azurecurve-bbcode
BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS & JavaScript searchpro
BeyondCart Connector beyondcart
Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid blog-designer-for-elementor
Calendar Plus calendar-plus
Catalog Importer, Scraper & Crawler intelligent-importer
Categorify – WordPress Media Library Category & File Manager categorify
CatFolders – WordPress Media Library Folders & Categories catfolders
CBX Map for Google Map & OpenStreetMap cbxgooglemap
Certifica WP certifica-wp
Countdown Timer for Elementor countdown-timer-for-elementor
Coupon API couponapi
CTL Behance Importer Lite ctl-behance-importer-lite
Digital Events Calendar digital-events-calendar
Doccure Core doccure
Duplicate Page and Post duplicate-wp-page-post
Dynamic Text Field For Contact Form 7 dynamic-text-field-for-contact-form-7
Easy Appointments easy-appointments
Easy Woocommerce Customizer easy-woocommerce-customizer
eID Easy smart-id
Elements Plus! elements-plus
Embed Google Datastudio embed-google-data-studio
Enhanced BibliPlug enhanced-bibliplug
Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance accessibility-checker
Evenium evenium
Export WordPress Pages to Static HTML & PDF — Static Site Export export-wp-page-to-static-html
Fidelo Snippet thebing-snippet
Football Pool football-pool
Fortnox for WooCommerce woocommerce-fortnox-integration
Grid Plus – Unlimited grid layout grid-plus
Heateor Login – Social Login Plugin heateor-login
Include Me include-me
Jobify jobify
LH Signing lh-signing
LWS Cleaner lws-cleaner
Maspik – Ultimate Spam Protection contact-forms-anti-spam
Mikado Core mikado-core
Mitfahrgelegenheit mitfahrgelegenheit
Mixtape mixtape
My Tickets – Accessible Event Ticketing my-tickets
My WP Translate my-wp-translate
MyBrain Utilities mybrain-utilities
NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization nitropack
PagBank / PagSeguro Connect para WooCommerce pagbank-connect
PDF Generator for WordPress pdf-generator-for-wp
PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) peachpay-for-woocommerce
PhpList Subber phpls
Pixeline's Email Protector pixelines-email-protector
Plugin updates blocker plugin-update-blocker
Postie postie
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) powerpack-lite-for-elementor
Propovoice: All-in-One Client Management System propovoice
Publish approval publish-approval
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings seo-by-rank-math
Recipe Card Blocks Lite recipe-card-blocks-by-wpzoom
Resideo Plugin for Resideo - Real Estate WordPress Theme resideo-plugin
Responsive Addons for Elementor – Free Elementor Addons, Kits and Elementor Templates responsive-addons-for-elementor
Responsive Filterable Portfolio Gallery – Media Grid & Video Portfolio responsive-filterable-portfolio
Run Log run-log
Salon Booking System – Free Version salon-booking-system
Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp
Seo Monster seo-monster
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin woolentor-addons
Side Slide Responsive Menu side-slide-responsive-menu
Smartcat Translator for WPML smartcat-wpml
Spotify Embed Creator spotify-embed-creator
Testimonial indianic-testimonial
The Events Calendar the-events-calendar
The Hack Repair Guy's Plugin Archiver hackrepair-plugin-archiver
The integration of the AMO.CRM leads-for-amo-crm
ThemeLoom Widgets themeloom-widgets
Time Tracker time-tracker
Tutor LMS – eLearning and online course solution tutor
Ultimate Blogroll ultimate-blogroll
Ultimate Classified Listings – Classifieds, Directory & Marketplace ultimate-classified-listings
User Meta – User Profile Builder and User management plugin user-meta
WC Return products wc-return-product
Welcart e-Commerce usc-e-shop
Wilmer Core wilmer-core
WooCommerce Booking Bundle Hours woo-booking-bundle-hours
Woocommerce Envato Affiliates wooenvato
Workable Api wrapper-for-workable-api
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets wp-all-import
WP Blast | SEO & Performance Booster wpblast
WP Easy FAQs wp-easy-faqs
WP eBay Product Feeds ebay-feeds-for-wordpress
WP Mailgun SMTP wp-mailgun-smtp
WP Scriptcase wp-scriptcase
WP SendGrid SMTP wp-sendgrid-smtp
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel wp-ultimate-csv-importer
WP-Members Membership Plugin wp-members
WPGYM - Wordpress Gym Management System gym-management
WPLMS Plugin wplms_plugin
ZIP Code Based Content Protection zip-code-based-content-protection
Zoho Flow – No-Code Workflow Automation zoho-flow


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
ButterBelly butterbelly
Cloriato Lite cloriato-lite
ColorWay colorway
Compass compass
Doccure doccure
Dzonia Lite dzonia-lite
Goza - Nonprofit Charity WordPress Theme goza-theme
ListingPro - WordPress Directory & Listing Theme listingpro
Logtik | Logistics, Transportation Theme logtik
Mow mow
Poloray poloray
Resca - Restaurant WordPress Theme resca
Rethink rethink
Road Fighter road-fighter
Themia Lite themia-lite
XStore xstore


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Doccure [doccure]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Doccure Core [doccure]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Doccure [doccure]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
My WP Translate [my-wp-translate]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Sep 12, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
Ajax WooSearch [ajax-woosearch]
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
All in one Minifier [all-in-one-minifier]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
CTL Behance Importer Lite [ctl-behance-importer-lite]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 11, 2025
Affected Software
Recipe Card Blocks Lite [recipe-card-blocks-by-wpzoom]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 11, 2025
Affected Software
The Events Calendar [the-events-calendar]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
XStore [xstore]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Sep 11, 2025
Affected Software
LWS Cleaner [lws-cleaner]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Sep 12, 2025
Affected Software
The Hack Repair Guy's Plugin Archiver [hackrepair-plugin-archiver]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Sep 9, 2025
Affected Software
Duplicate Page and Post [duplicate-wp-page-post]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Easy Appointments [easy-appointments]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Sep 9, 2025
Affected Software
Testimonial [indianic-testimonial]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Additional Custom Product Tabs for WooCommerce [product-tabs-for-woocommerce]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 9, 2025
Affected Software
Auto Save Remote Images (Drafts) [auto-save-remote-images-drafts]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
azurecurve BBCode [azurecurve-bbcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Certifica WP [certifica-wp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Countdown Timer for Elementor [countdown-timer-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Digital Events Calendar [digital-events-calendar]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Dynamic Text Field For Contact Form 7 [dynamic-text-field-for-contact-form-7]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
eID Easy [smart-id]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Elements Plus! [elements-plus]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
Embed Google Datastudio [embed-google-data-studio]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Enhanced BibliPlug [enhanced-bibliplug]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Evenium [evenium]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Football Pool [football-pool]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Jobify [jobify]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Mikado Core [mikado-core]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Mitfahrgelegenheit [mitfahrgelegenheit]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Mixtape [mixtape]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
MyBrain Utilities [mybrain-utilities]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
Spotify Embed Creator [spotify-embed-creator]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
ThemeLoom Widgets [themeloom-widgets]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Wilmer Core [wilmer-core]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 11, 2025
Affected Software
Fortnox for WooCommerce [woocommerce-fortnox-integration]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Workable Api [wrapper-for-workable-api]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
WP Easy FAQs [wp-easy-faqs]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
WP eBay Product Feeds [ebay-feeds-for-wordpress]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
WP Scriptcase [wp-scriptcase]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 12, 2025
Affected Software
Calendar Plus [calendar-plus]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 8, 2025
Affected Software
Easy Woocommerce Customizer [easy-woocommerce-customizer]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 12, 2025
Affected Software
Fidelo Snippet [thebing-snippet]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 13, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 12, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 12, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Seo Monster [seo-monster]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
Side Slide Responsive Menu [side-slide-responsive-menu]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
Ultimate Blogroll [ultimate-blogroll]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 8, 2025
Affected Software
WC Return products [wc-return-product]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 11, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 14, 2025
Affected Software
WPLMS Plugin [wplms_plugin]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
XStore [xstore]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Welcart e-Commerce [usc-e-shop]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
My WP Translate [my-wp-translate]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Sep 12, 2025
Affected Software
ButterBelly [butterbelly]
Cloriato Lite [cloriato-lite]
ColorWay [colorway]
Compass [compass]
Dzonia Lite [dzonia-lite]
Poloray [poloray]
Rethink [rethink]
Road Fighter [road-fighter]
Themia Lite [themia-lite]
WP Mailgun SMTP [wp-mailgun-smtp]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Publish approval [publish-approval]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 14, 2025
Affected Software
WPLMS Plugin [wplms_plugin]
Researcher
CVSS Rating
5.0 (Medium)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Coupon API [couponapi]
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
ZIP Code Based Content Protection [zip-code-based-content-protection]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Include Me [include-me]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Pixeline's Email Protector [pixelines-email-protector]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 8, 2025
Affected Software
Postie [postie]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Welcart e-Commerce [usc-e-shop]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Admin in English with Switch [admin-in-english-with-switch]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Advanced Settings 3 [advanced-settings]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Analytics Reduce Bounce Rate [analytics-unbounce]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
AutoCatSet [autocatset]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 8, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
LH Signing [lh-signing]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 12, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Mow [mow]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
PDF Generator for WordPress [pdf-generator-for-wp]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
Plugin updates blocker [plugin-update-blocker]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 11, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 11, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Run Log [run-log]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 10, 2025
Affected Software
The integration of the AMO.CRM [leads-for-amo-crm]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
WooCommerce Booking Bundle Hours [woo-booking-bundle-hours]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 9, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
XStore [xstore]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 10, 2025
Affected Software
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments