Wordfence Intelligence Weekly WordPress Vulnerability Report (September 29, 2025 to October 5, 2025)

📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🚀  Operation: Maximum Impact Challenge! Now through November 10, 2025, earn 2X bounty rewards for all in-scope submissions in software with at least 5,000 active installs and fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!

📁 The LFInder Challenge: Refine your LFI hunting skills with an expanded scope. Now through November 24, 2025, all LFI vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier, AND earn a 30% bonus on all Local File Inclusion vulnerability submissions not already increased by another promotion.


Last week, there were 136 vulnerabilities disclosed in 121 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 44 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 29,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 67
Unpatched 69


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 107
High Severity 19
Critical Severity 9


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 58
Missing Authorization 22
Cross-Site Request Forgery (CSRF) 18
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 6
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 4
Exposure of Sensitive Information to an Unauthorized Actor 3
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
Unrestricted Upload of File with Dangerous Type 3
Authentication Bypass Using an Alternate Path or Channel 2
Deserialization of Untrusted Data 2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
Server-Side Request Forgery (SSRF) 2
External Control of File Name or Path 1
Improper Access Control 1
Improper Authorization 1
Improper Control of Generation of Code ('Code Injection') 1
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') 1
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Improper Verification of Cryptographic Signature 1
Missing Authentication for Critical Function 1
Unverified Password Change 1
URL Redirection to Untrusted Site ('Open Redirect') 1
Use of Hard-coded Cryptographic Key 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
16
15
12
9
8
7
6
6
6
5
4
3
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
A Simple Multilanguage Plugin a-simple-multilanguage
AffiliateWP affiliatewp
All in One Music Player all-in-one-music-player
All Social Share Options all-social-share-options
Any News Ticker any-news-ticker
AP Background ap-background
Appy Pie Connect for WooCommerce appy-pie-connect-for-woocommerce
Auto Bulb Finder for WordPress auto-bulb-finder-for-wp-wc
Avada (Fusion) Builder fusion-builder
Backup Bolt backup-bolt
Before After Image majestic-before-after-image
Bei Fen – WordPress Backup Plugin bei-fen
Big Post Shipping for WooCommerce woo-bigpost-shipping
Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp
Block for Mailchimp – Add Email Subscription Forms and Collect Leads block-for-mailchimp
BP Direct Menus bp-direct-menus
Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) bulk-image-title-attribute
CF7 Auto Responder Addon CF7-autoresponder-addon
Chat by Chatwee chatwee
Comment Info Detector comment-info-detector
ContentMX Content Publisher contentmx-content-publisher
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels enhanced-e-commerce-for-woocommerce-store
Copypress Rest API copypress-rest-api
Cost Calculator Builder cost-calculator-builder
Custom Post Type Attachment custom-post-type-pdf-attachment
dbview dbview
Download Manager download-manager
Duplicate Page, Hide Title, Custom CSS & JS, Exclude Search, Template Info – Pagely current-template-name
Easy Elementor Addons – Addons Pack for Elementor Page Builder easy-elementor-addons
Effect Maker effect-maker
Epic Bootstrap Buttons epic-bootstrap-buttons
Eulerpool Research Systems alleaktien-quantitativ
Event Tickets, RSVPs, Calendar ticket-spot
Export Categories export-categories
FancyTabs fancytabs
File Manager, Code Editor, and Backup by Managefy softdiscover-db-file-manager
Fintelligence Calculator fintelligence-calculator
Flexi – Guest Submit flexi
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More formgent
Generic Elements generic-elements-for-elementor
GiveWP – Donation Plugin and Fundraising Platform give
GutenBee – Gutenberg Blocks gutenbee
IgnitionDeck Crowdfunding Platform ignitiondeck
Integrate Dynamics 365 CRM integrate-dynamics-365-crm
Interactive Human Anatomy with Clickable Body Parts interactive-medical-drawing-of-human-body
Ird Slider ird-slider
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress jeg-elementor-kit
JobSearch WP Job Board wp-jobsearch
Jock On Air Now (JOAN) joan
JoomSport – for Sports: Team & League, Football, Hockey & more joomsport-sports-league-results-management
LatePoint – Calendar Booking Plugin for Appointments and Events latepoint
Layers layers
LockerPress – WordPress Security Plugin lockerpress-wordpress-security
Maps from Yandex for Elementor mihdan-elementor-yandex-maps
Marquee Addons for Elementor – Essential Motion Widgets & Templates marquee-addons-for-elementor
Meks Easy Maps meks-easy-maps
Meta Tag Manager meta-tag-manager
Mobile Site Redirect mobile-site-redirect
MPWizard – Create Mercado Pago Payment Links mpwizard
My AskAI my-askai
Nelio Content – Editorial Calendar & Social Media Auto-Posting nelio-content
NEX-Forms LITE nex-forms-lite
Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE nexa-blocks
Notification Bar simple-bar
OAuth Single Sign On – SSO (OAuth Client) miniorange-login-with-eve-online-google-facebook
Opal Service opal-service
Optimize More! – CSS optimize-more-css
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More themeisle-companion
PayPal Forms paypal-forms
planetcalc planetcalc
Post By Email post-by-email
Post Grid post-grid
Qyrr – simply and modern QR-Code creation qyrr-code
Restrict User Registration restrict-user-registration
RestroPress – Online Food Ordering System restropress
Rock Convert rock-convert
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions s2member
Schema Plugin For Divi, Gutenberg & Shortcodes wp-structured-data-schema
SEO Meta Description Updater seo-meta-description-updater
SiteAlert (Formerly WP Health) my-wp-health-check
SiteGround Email Marketing siteground-email-marketing
Smart Docs smart-docs
Smart WeTransfer smart-wetransfer
SmartCrawl SEO checker, analyzer & optimizer smartcrawl-seo
SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7
Spirit Framework spirit-framework
Survey Anyplace surveyanyplace
TableGen – Data Table Generator table-creator
Taskbot taskbot
Testimonial – Testimonial Slider, Reviews Slider, Testimonial By AI testimonial
TextBuilder textbuilder
The Pack Elementor addon the-pack-addon
Tiny Bootstrap Elements Light tiny-bootstrap-elements-light
Tooltipy (tooltips for WP) bluet-keywords-tooltip-generator
Travel & Tours Meta Search adiaha-hotel
Trinity Audio – Text to Speech AI audio player to convert content into audio trinity-audio
TS Demo Importer ts-demo-importer
Ultimate Learning Pro indeed-learning-pro
Ultimate Multi Design Video Carousel ultimate-multi-design-video-carousel
Ultimate Viral Quiz ultimate-viral-quiz
Ultra Addons Lite for Elementor ut-elementor-addons-lite
Unify unify
Upload.am – File Hosting & VPN upload-am-file-hosting-vpn
USERCENTRICS CMP usercentrics-consent-management-platform
Video Gallery by Huzzaz huzzaz-video-gallery
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder wdesignkit
WeedMaps Menu for WordPress weedmaps-menu-embed
Woo superb slideshow transition gallery with random effect woo-superb-slideshow-transition-gallery-with-random-effect
WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder
WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem
Wp cycle text announcement wp-cycle-text-announcement
WP Dispatcher wp-dispatcher
WP Photo Album Plus wp-photo-album-plus
WP Photo Effects wp-photo-effects
WP SinoType wp-sinotype
WPRecovery wprecovery
X Addons for Elementor x-addons-elementor
Yoast SEO Premium wordpress-seo-premium
Yoga Schedule Momoyoga momoyoga-integration
ZoloBlocks – Advanced Gutenberg Blocks, Website Builder & Page Design Toolkit zoloblocks


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Avada | Website Builder For WordPress & WooCommerce Avada
Constructor constructor
Customify customify
The7 — Website and eCommerce Builder for WordPress dt-the7


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Appy Pie Connect for WooCommerce [appy-pie-connect-for-woocommerce]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Copypress Rest API [copypress-rest-api]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
JoomSport – for Sports: Team & League, Football, Hockey & more [joomsport-sports-league-results-management]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
OAuth Single Sign On – SSO (OAuth Client) [miniorange-login-with-eve-online-google-facebook]
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Post By Email [post-by-email]
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Spirit Framework [spirit-framework]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
WPRecovery [wprecovery]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
TextBuilder [textbuilder]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
WP Dispatcher [wp-dispatcher]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
Cost Calculator Builder [cost-calculator-builder]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Sep 30, 2025
Affected Software
Taskbot [taskbot]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Tiny Bootstrap Elements Light [tiny-bootstrap-elements-light]
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Oct 1, 2025
Affected Software
WooCommerce Vehicle Parts Finder [woo-vehicle-parts-finder]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
AffiliateWP [affiliatewp]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
WP Dispatcher [wp-dispatcher]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Sep 30, 2025
Affected Software
CF7 Auto Responder Addon [CF7-autoresponder-addon]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Oct 1, 2025
Affected Software
NEX-Forms LITE [nex-forms-lite]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Sep 30, 2025
Affected Software
WooCommerce Vehicle Parts Finder [woo-vehicle-parts-finder]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
All in One Music Player [all-in-one-music-player]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
Integrate Dynamics 365 CRM [integrate-dynamics-365-crm]
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Woo superb slideshow transition gallery with random effect [woo-superb-slideshow-transition-gallery-with-random-effect]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Wp cycle text announcement [wp-cycle-text-announcement]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
A Simple Multilanguage Plugin [a-simple-multilanguage]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
All Social Share Options [all-social-share-options]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Any News Ticker [any-news-ticker]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
AP Background [ap-background]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Auto Bulb Finder for WordPress [auto-bulb-finder-for-wp-wc]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
Big Post Shipping for WooCommerce [woo-bigpost-shipping]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
BP Direct Menus [bp-direct-menus]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 4, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Custom Post Type Attachment [custom-post-type-pdf-attachment]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
dbview [dbview]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Epic Bootstrap Buttons [epic-bootstrap-buttons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Eulerpool Research Systems [alleaktien-quantitativ]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
FancyTabs [fancytabs]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Fintelligence Calculator [fintelligence-calculator]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
Avada (Fusion) Builder [fusion-builder]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Generic Elements [generic-elements-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Ird Slider [ird-slider]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
Layers [layers]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 4, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Meks Easy Maps [meks-easy-maps]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
Maps from Yandex for Elementor [mihdan-elementor-yandex-maps]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
My AskAI [my-askai]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Opal Service [opal-service]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
planetcalc [planetcalc]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Rock Convert [rock-convert]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2025
Affected Software
SiteGround Email Marketing [siteground-email-marketing]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Survey Anyplace [surveyanyplace]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
The Pack Elementor addon [the-pack-addon]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 3, 2025
Affected Software
Tooltipy (tooltips for WP) [bluet-keywords-tooltip-generator]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Ultra Addons Lite for Elementor [ut-elementor-addons-lite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Unify [unify]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Video Gallery by Huzzaz [huzzaz-video-gallery]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
WeedMaps Menu for WordPress [weedmaps-menu-embed]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
WP Photo Effects [wp-photo-effects]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
X Addons for Elementor [x-addons-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Yoast SEO Premium [wordpress-seo-premium]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
Yoga Schedule Momoyoga [momoyoga-integration]
Researcher
CVSS Rating
6.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
LockerPress – WordPress Security Plugin [lockerpress-wordpress-security]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Mobile Site Redirect [mobile-site-redirect]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
CVSS Rating
5.9 (Medium)
Patch Status
Patched
Published
Sep 30, 2025
Affected Software
CVSS Rating
5.5 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Interactive Human Anatomy with Clickable Body Parts [interactive-medical-drawing-of-human-body]
CVSS Rating
5.5 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Smart Docs [smart-docs]
CVSS Rating
5.5 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Ultimate Multi Design Video Carousel [ultimate-multi-design-video-carousel]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
Before After Image [majestic-before-after-image]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
Affected Software
WP Photo Album Plus [wp-photo-album-plus]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Oct 4, 2025
Affected Software
Export Categories [export-categories]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Restrict User Registration [restrict-user-registration]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
SiteAlert (Formerly WP Health) [my-wp-health-check]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 29, 2025
Affected Software
Upload.am – File Hosting & VPN [upload-am-file-hosting-vpn]
CVSS Rating
4.7 (Medium)
Patch Status
Patched
Published
Oct 1, 2025
Affected Software
Meta Tag Manager [meta-tag-manager]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Oct 4, 2025
Affected Software
USERCENTRICS CMP [usercentrics-consent-management-platform]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
AP Background [ap-background]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Chat by Chatwee [chatwee]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Comment Info Detector [comment-info-detector]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Constructor [constructor]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
ContentMX Content Publisher [contentmx-content-publisher]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 5, 2025
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Customify [customify]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2025
Affected Software
Download Manager [download-manager]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Effect Maker [effect-maker]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 4, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 5, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Notification Bar [simple-bar]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Optimize More! – CSS [optimize-more-css]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
PayPal Forms [paypal-forms]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 4, 2025
Affected Software
Post Grid [post-grid]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 4, 2025
Affected Software
Post Grid [post-grid]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 5, 2025
Affected Software
SEO Meta Description Updater [seo-meta-description-updater]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 29, 2025
Affected Software
Smart WeTransfer [smart-wetransfer]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 5, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 3, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 4, 2025
Affected Software
TS Demo Importer [ts-demo-importer]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2025
Affected Software
Ultimate Learning Pro [indeed-learning-pro]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
Ultimate Viral Quiz [ultimate-viral-quiz]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Oct 2, 2025
Affected Software
WP SinoType [wp-sinotype]
Researcher
CVSS Rating
3.8 (Low)
Patch Status
Patched
Published
Oct 2, 2025
Affected Software
Backup Bolt [backup-bolt]


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments