Wordfence Intelligence Weekly WordPress Vulnerability Report (October 20, 2025 to October 26, 2025)

📱 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📱

🚀  Operation: Maximum Impact Challenge! Now through November 10, 2025, earn 2X bounty rewards for all in-scope submissions in software with at least 5,000 active installs and fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!

📁 The LFInder Challenge: Refine your LFI hunting skills with an expanded scope. Now through November 24, 2025, all LFI vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier, AND earn a 30% bonus on all Local File Inclusion vulnerability submissions not already increased by another promotion.


Last week, there were 143 vulnerabilities disclosed in 128 WordPress Plugins and 9 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 58 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 29,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

  • WAF-RULE-869 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-870 – Data redacted while we work with the vendor on a patch.

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 98
Unpatched 45


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 2
Medium Severity 118
High Severity 19
Critical Severity 4


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 58
Missing Authorization 26
Cross-Site Request Forgery (CSRF) 11
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 8
Server-Side Request Forgery (SSRF) 7
Improper Authorization 5
Exposure of Sensitive Information to an Unauthorized Actor 4
Improper Control of Generation of Code ('Code Injection') 3
Unrestricted Upload of File with Dangerous Type 3
Authorization Bypass Through User-Controlled Key 2
Deserialization of Untrusted Data 2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
Improper Privilege Management 2
Improper Access Control 1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 1
Improper Input Validation 1
Improper Neutralization of Formula Elements in a CSV File 1
Incorrect Authorization 1
Incorrect Privilege Assignment 1
Insertion of Sensitive Information into Log File 1
URL Redirection to Untrusted Site ('Open Redirect') 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
15
13
9
7
7
7
6
5
5
4
4
3
3
3
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Jay
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Academy LMS Pro academy-pro
ACF to REST API acf-to-rest-api
Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance advanced-database-cleaner
Advanced FAQ Manager advanced-faq-manager
AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant chatbot-ai-free-models
AIO Forms – Craft Complex Forms Easily all-in-one-forms
Ajax Search Lite – Live Search & Filter ajax-search-lite
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier aio-time-clock-lite
BackWPup – WordPress Backup & Restore Plugin backwpup
Beaver Builder Plugin (Starter Version) bb-plugin
Bg Book Publisher bg-book-publisher
Bold Page Builder bold-page-builder
Builderall for WordPress builderall-cheetah-for-wp
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More charitable
Check Plagiarism check-plagiarism
Cinza Grid cinza-grid
Compliance by Hu-manity.co cookie-notice
Creta Testimonial Showcase creta-testimonial-showcase
Directorist: AI-Powered Business Directory, Listings & Classified Ads directorist
Disable Content Editor For Specific Template disable-contect-editor-for-specific-template
Discussion Board – WordPress Forum Plugin wp-discussion-board
DoFollow Case by Case dofollow-case-by-case
Dynamic User Directory dynamic-user-directory
Easy Social Share Buttons for WordPress easy-social-share-buttons3
Element Pack Addons for Elementor – Widgets, Templates and Addons bdthemes-element-pack-lite
Email Subscription Popup — Newsletter & GDPR Consent email-subscribe
Email Tracker email-tracker
eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams eroom-zoom-meetings-webinar
FanBridge signup fanbridge-signup
Fast Velocity Minify fast-velocity-minify
FileBird Pro filebird-pro
Flexible Refund for WooCommerce – EU One Click Return flexible-refund-and-return-order-for-woocommerce
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) fusewp
GenerateBlocks generateblocks
Gutenberg gutenberg
HAPPY – Helpdesk Support Ticket System happy-helpdesk-support-ticket-system
Hercules Core hercules-core
IndieAuth indieauth
JB News Ticker jb-news-ticker
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder king-addons
KiotViet Sync kiotvietsync
Litho Addons litho-addons
LLM Hubspot Blog Import llm-hubspot-blog-import
Make Email Customizer for WooCommerce make-email-customizer-for-woocommerce
MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system
Material Design Iconic Font Integration material-design-iconic-font-integration
MDTF – Meta Data and Taxonomies Filter wp-meta-data-filter-and-taxonomy-filter
Microsoft Azure Storage for WordPress windows-azure-storage
Mixlr Shortcode mixlr-shortcode
Multi Item Responsive Slider mislider
MxChat – AI Chatbot & Content Generation for WordPress mxchat-basic
Name: Print Button Shortcode print-button-shortcode
NGINX Cache Optimizer nginx-cache-optimizer
NS Maintenance Mode for WP ns-maintenance-mode-for-wp
Oboxmedia Ads oboxmedia-ads
Originality.ai AI Checker originality-ai
Password Policy Manager | Password Manager password-policy-manager
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content password-protected
Persian Admnin Fonts persian-admin-fonts
Photographers galleries photographers-galleries
PixelYourSite – Your smart PIXEL (TAG) & API Manager pixelyoursite
Playerzbr playerzbr
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers popup-builder-block
Posts By Tag posts-by-tag
PowerPress Podcasting plugin by Blubrry powerpress
Premium Age Verification / Restriction for WordPress age-restriction
Product Filter for WooCommerce by WBW woo-product-filter
PublishPress Blocks – Block Controls, Block Visibility, Block Permissions advanced-gutenberg
qnotsquiz qnotsquiz
Quickcreator – AI Blog Writer quickcreator
RapidResult rapidresult
Real Cookie Banner: GDPR & ePrivacy Cookie Consent real-cookie-banner
Reservation Plugin dt-reservation-plugin
Responsive iframe GoogleMap responsive-iframe-googlemap
Responsive Progress Bar responsive-progress-bar
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator feedzy-rss-feeds
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution shopengine
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin woolentor-addons
Shortcodes and extra features for Phlox theme auxin-elements
Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website simple-banner
Simple Business Data simple-business-data
Simple Excel Pricelist for WooCommerce simple-excel-pricelist-for-woocommerce
Simple Pull Quote simple-pull-quote
Simple Registration for WooCommerce woocommerce-simple-registration
Simple Tableau Viz simple-tableau-viz
Simple Youtube Shortcode simple-youtube-shortcode
SimpLy Gallery simply-gallery-block
Slider Templates slider-templates
SM CountDown Widget smcountdown
Social Feed Gallery insta-gallery
SpendeOnline.org spendeonline
Sprout Clients – CRM and Lead Management sprout-clients
Sprout Invoices – Client Invoicing & Estimates sprout-invoices
ST Categories Widget st-category-wp
Stockie Extra stockie-extra
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions wp-full-stripe-free
Supervisor supervisor
Team Members Showcase wps-team
Testimonial Carousel For Elementor testimonials-carousel-elementor
ThemeRain Core themerain-core
This-or-That this-or-that
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin time-clock
Tutor LMS Pro tutor-pro
Tutor LMS – eLearning and online course solution tutor
URL Shortener Plugin For WordPress exact-links
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds userfeedback-lite
VikBooking Hotel Booking Engine & PMS vikbooking
VNPAY Payment gateway vnpay-for-woocommerce
Watu Quiz watu
Welcart e-Commerce usc-e-shop
WhyDonate – FREE Donate button – Crowdfunding – Fundraising wp-whydonate
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets widget-options
WooCommerce Designer Pro wc-designer-pro
WP AD Gallery wp-ad-gallery
WP AdCenter – Ad Manager & Adsense Ads wpadcenter
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map wp-google-maps
WP Gravity Forms Zoho CRM and Bigin gf-zoho
WP Responsive Meet The Team wp-responsive-meet-the-team
WP Restaurant Listings wp-restaurant-listings
WP Rocket wp-rocket
WP VR – 360 Panorama and Virtual Tour Builder wpvr
WP-Force Images Download wp-force-images-download
WP-Thumbnail wp-thumbnail
WPC Countdown Timer for WooCommerce wpc-countdown-timer
WPComplete wpcomplete
wpForo Forum wpforo
WPMobile.App wpappninja
ZoloBlocks – Advanced Gutenberg Blocks, Website Builder & Page Design Toolkit zoloblocks


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Bard - A Theatre and Performing Arts WordPress Theme bardwp
Codiqa - Software & Digital WordPress Theme codiqa
Enfold - Responsive Multi-Purpose Theme enfold
Listeo - Directory & Listings With Booking - WordPress Theme listeo
Listify listify
Motors - Car Dealer, Rental & Listing WordPress theme motors
Open Source Genesis Framework genesis
Soledad soledad
The7 — Website and eCommerce Builder for WordPress dt-the7


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Oct 25, 2025
Affected Software
HAPPY – Helpdesk Support Ticket System [happy-helpdesk-support-ticket-system]
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
WooCommerce Designer Pro [wc-designer-pro]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Oct 21, 2025
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
IndieAuth [indieauth]
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Make Email Customizer for WooCommerce [make-email-customizer-for-woocommerce]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Simple Registration for WooCommerce [woocommerce-simple-registration]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Soledad [soledad]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Academy LMS Pro [academy-pro]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Oct 24, 2025
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
wpForo Forum [wpforo]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Oct 26, 2025
Affected Software
Easy Social Share Buttons for WordPress [easy-social-share-buttons3]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Oct 21, 2025
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Watu Quiz [watu]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Oct 26, 2025
Affected Software
WPMobile.App [wpappninja]
Researcher
CVSS Rating
6.6 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Researcher
CVSS Rating
6.6 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Creta Testimonial Showcase [creta-testimonial-showcase]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
GenerateBlocks [generateblocks]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
RapidResult [rapidresult]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Advanced FAQ Manager [advanced-faq-manager]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Bg Book Publisher [bg-book-publisher]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
Builderall for WordPress [builderall-cheetah-for-wp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Cinza Grid [cinza-grid]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Dynamic User Directory [dynamic-user-directory]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 25, 2025
Affected Software
Gutenberg [gutenberg]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Hercules Core [hercules-core]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
JB News Ticker [jb-news-ticker]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Material Design Iconic Font Integration [material-design-iconic-font-integration]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Mixlr Shortcode [mixlr-shortcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Oboxmedia Ads [oboxmedia-ads]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Photographers galleries [photographers-galleries]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Playerzbr [playerzbr]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 22, 2025
Affected Software
Posts By Tag [posts-by-tag]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Name: Print Button Shortcode [print-button-shortcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Responsive iframe GoogleMap [responsive-iframe-googlemap]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Responsive Progress Bar [responsive-progress-bar]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 20, 2025
Affected Software
WP Rocket [wp-rocket]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Simple Business Data [simple-business-data]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
Simple Excel Pricelist for WooCommerce [simple-excel-pricelist-for-woocommerce]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Simple Pull Quote [simple-pull-quote]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Simple Tableau Viz [simple-tableau-viz]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Simple Youtube Shortcode [simple-youtube-shortcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 26, 2025
Affected Software
SimpLy Gallery [simply-gallery-block]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 24, 2025
Affected Software
Slider Templates [slider-templates]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
SM CountDown Widget [smcountdown]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
SpendeOnline.org [spendeonline]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
ST Categories Widget [st-category-wp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Testimonial Carousel For Elementor [testimonials-carousel-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
This-or-That [this-or-that]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
WP AD Gallery [wp-ad-gallery]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 22, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
WP Responsive Meet The Team [wp-responsive-meet-the-team]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
WP Restaurant Listings [wp-restaurant-listings]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
WP-Force Images Download [wp-force-images-download]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
WP-Thumbnail [wp-thumbnail]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 20, 2025
Affected Software
Researcher
CVSS Rating
6.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Researcher
CVSS Rating
6.3 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Reservation Plugin [dt-reservation-plugin]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 22, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
VNPAY Payment gateway [vnpay-for-woocommerce]
Researcher
CVSS Rating
5.5 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Welcart e-Commerce [usc-e-shop]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Oct 20, 2025
Affected Software
ACF to REST API [acf-to-rest-api]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Oct 22, 2025
Affected Software
NS Maintenance Mode for WP [ns-maintenance-mode-for-wp]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 26, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Social Feed Gallery [insta-gallery]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Stockie Extra [stockie-extra]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Oct 24, 2025
Affected Software
ThemeRain Core [themerain-core]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 20, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
WPComplete [wpcomplete]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Email Tracker [email-tracker]
Researcher
CVSS Rating
4.7 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Oct 22, 2025
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
Fast Velocity Minify [fast-velocity-minify]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
qnotsquiz [qnotsquiz]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
Check Plagiarism [check-plagiarism]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
Disable Content Editor For Specific Template [disable-contect-editor-for-specific-template]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 26, 2025
Affected Software
DoFollow Case by Case [dofollow-case-by-case]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
FanBridge signup [fanbridge-signup]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 25, 2025
Affected Software
FileBird Pro [filebird-pro]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Flexible Refund for WooCommerce – EU One Click Return [flexible-refund-and-return-order-for-woocommerce]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 20, 2025
Affected Software
KiotViet Sync [kiotvietsync]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 22, 2025
Affected Software
Listify [listify]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 21, 2025
Affected Software
Litho Addons [litho-addons]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
LLM Hubspot Blog Import [llm-hubspot-blog-import]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025
Affected Software
MDTF – Meta Data and Taxonomies Filter [wp-meta-data-filter-and-taxonomy-filter]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 23, 2025
Affected Software
NGINX Cache Optimizer [nginx-cache-optimizer]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Persian Admnin Fonts [persian-admin-fonts]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 21, 2025
Affected Software
Stockie Extra [stockie-extra]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 23, 2025
Affected Software
Supervisor [supervisor]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 24, 2025


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments