Wordfence Intelligence Weekly WordPress Vulnerability Report (November 3, 2025 to November 9, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

📁 The LFInder Challenge: Refine your LFI hunting skills with an expanded scope. Now through November 24, 2025, all LFI vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier, AND earn a 30% bonus on all Local File Inclusion vulnerability submissions not already increased by another promotion.


Last week, there were 153 vulnerabilities disclosed in 134 WordPress Plugins and no WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 68 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 29,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 109
Unpatched 44


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 121
High Severity 22
Critical Severity 9


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Missing Authorization 39
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 35
Cross-Site Request Forgery (CSRF) 20
Exposure of Sensitive Information to an Unauthorized Actor 16
Unrestricted Upload of File with Dangerous Type 7
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 6
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 5
Deserialization of Untrusted Data 3
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
Server-Side Request Forgery (SSRF) 3
Authorization Bypass Through User-Controlled Key 2
Improper Authorization 2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 2
Improper Control of Generation of Code ('Code Injection') 1
Incorrect Authorization 1
Incorrect Comparison 1
Insertion of Sensitive Information into Log File 1
Missing Authentication for Critical Function 1
Protection Mechanism Failure 1
Reliance on Untrusted Inputs in a Security Decision 1
URL Redirection to Untrusted Site ('Open Redirect') 1
Use of Hard-coded Cryptographic Key 1
Use of Hard-coded Password 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
12
11
8
7
7
7
6
6
6
6
5
4
3
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
Jay
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Academy LMS academy
Academy LMS Pro academy-pro
Ad Inserter – Ad Manager & AdSense Ads ad-inserter
Ai Auto Tool Content Writing Assistant All in One ai-auto-tool
AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine
Alex Reservations: Smart Restaurant Booking alex-reservations
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier aio-time-clock-lite
Asgaros Forum asgaros-forum
Associados Amazon Plugin brzon
aThemes Addons for Elementor – Widgets, Sliders, Galleries & Form Styler athemes-addons-for-elementor-lite
Auto Prune Posts auto-prune-posts
Backup Migration backup-backup
Better Find and Replace – AI-Powered Suggestions real-time-auto-find-and-replace
Blog2Social: Social Media Auto Post & Scheduler blog2social
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar booking-manager
Bootstrap Multi-language Responsive Portfolio bootstrap-multi-language-responsive-portfolio
Broken Link Manager broken-link-manager
Carousel Block – Showcase Images in Elegant Sliding Displays b-carousel-block
CE21 Suite ce21-suite
Centangle-Team centangle-team
clubmember clubmember
Connect Contact Form 7 and AWeber integrate-contact-form-7-and-aweber
Connector Wizard (formerly LC Wizard) ghl-wizard
Content Locker for Elementor content-locker-for-elementor
Content Pilot – Autoblogging & Affiliate Marketing Suite wp-content-pilot
CoSchedule coschedule-by-todaymade
Course Booking System course-booking-system
Crypto Payment Gateway with Payeer for WooCommerce crypto-payment-gateway-with-payeer-for-woocommerce
CYAN Backup cyan-backup
Depicter — Popup & Slider Builder depicter
Document Embedder – let visitors read files without downloading document-emberdder
DominoKit dominokit
Download Manager download-manager
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy easy-digital-downloads
Easy Email Subscription email-subscription-with-secure-captcha
Easy Upload Files During Checkout easy-upload-files-during-checkout
Elegance Menu elegance-menu
EM Beer Manager em-beer-manager
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress email-subscribers
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More envira-gallery-lite
EventPrime – Events Calendar, Bookings, Tickets & AI eventprime-event-calendar-management
Everest Forms Pro everest-forms-pro
Extensions for Leaflet Map extensions-leaflet-map
Features features
Feeds for YouTube (YouTube video, channel, and gallery plugin) feeds-for-youtube
File Manager for Google Drive – Integrate Google Drive integrate-google-drive
Flexible Refund for WooCommerce – EU One Click Return flexible-refund-and-return-order-for-woocommerce
follow-my-blog-post follow-my-blog-post
Footnotes Made Easy footnotes-made-easy
Free Quotation free-quotation
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce wp-marketing-automations
Graphina – Charts and Graphs For Elementor graphina-elementor-charts-and-graphs
Gravity Forms gravityforms
Greenshift – animation and page builder blocks greenshift-animation-and-page-builder-blocks
Groups – Memberships and Access Control groups
Guest posting / Frontend Posting / Front Editor – WP Front User Submit front-editor
HTML Forms – Simple WordPress Forms Plugin html-forms
Hub Core hub-core
Hubbub Lite – Fast, free social sharing and follow buttons social-pug
IDonate – Blood Donation, Request And Donor Management System idonate
Image Comparison Addon for Elementor image-comparison-elementor-addon
Image Hover Effects for Elementor image-hover-effects-elementor-addon
Import Export For WooCommerce import-export-for-woocommerce
Insert Headers and Footers Code – HT Script insert-headers-and-footers-script
JetElements jet-elements
KiotViet Sync kiotvietsync
Label Plugins label-plugins
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress
LinkedIn Resume linkedin-resume
LMB^Box Smileys lmbbox-smileys
Login Page Customizer – Customize Login Screen & Branding customizer-login-page
Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha feather-login-page
Mail Mint – Email Marketing, Automation & WooCommerce Emails with AI Assistance mail-mint
Mang Board WP mangboard
MapMap mapmap
Master Blocks – Ultimate Blocks for Marketers ultimate-blocks-for-gutenberg
MeetingList meeting-list
Nari Accountant nari-accountant
New User Approve new-user-approve
North north-plugin
Ohio Extra ohio-extra
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More themeisle-companion
Ovatheme Events Manager ova-events-manager
Page & Post Notes page-post-notes
Pagerank tools pagerank-tools
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred mycred
Posts Navigation Links for Sections and Headings – Free by WP Masters posts-navigation-links-for-sections-and-headings-free-by-wp-masters
Premium Portfolio Features for Phlox theme auxin-portfolio
Quick Featured Images quick-featured-images
Restaurant Menu and Food Ordering mp-restaurant-menu
Reuse Builder reuse-builder
Rey Core Rey-Core
Saphali LiqPay for donate saphali-liqpay-for-donate
Seriously Simple Podcasting seriously-simple-podcasting
SH Contextual Help sh-contextual-help
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin woolentor-addons
Simple Downloads List simple-downloads-list
Simple User Capabilities simple-user-capabilities
Smart Auto Upload Images – Import External Images smart-auto-upload-images
SMS for WordPress sms4wp
Spectra Legacy – Gutenberg Blocks ultimate-addons-for-gutenberg
Strong Testimonials strong-testimonials
SUMO Affiliates Pro affs
TablePress – Tables in WordPress made easy tablepress
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms simple-tags
TAX SERVICE Electronic HDM virtual-hdm-for-taxservice-am
The Events Calendar the-events-calendar
Top Bar Notification top-bar-notification
Traveler Option Tree custom-option-tree
Travelers' Map travelers-map
Ultimate FAQ Accordion Plugin ultimate-faqs
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included uncanny-automator
ViaAds viaads
VikBooking Hotel Booking Engine & PMS vikbooking
Visit Counter visit-counter
Visual Link Preview visual-link-preview
WooCommerce Recover Abandoned Cart rac
WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards
WordPress eCommerce Plugin – Studiocart studiocart
WP 2FA – Two-factor authentication for WordPress wp-2fa
WP Airbnb Review Slider wp-airbnb-review-slider
WP Carticon wp-carticon
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) delicious-recipes
WP Global Screen Options wp-global-screen-options
WP Hotel Booking wp-hotel-booking
WP Snow Effect wp-snow-effect
WP-CRM System – Manage Clients and Projects wp-crm-system
WP2Social Auto Publish facebook-auto-publish
WPCF7 Stop words wpcf7-stop-words
WPeMatico RSS Feed Fetcher wpematico
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell wpfunnels
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode gdpr-cookie-consent
ZoloBlocks – Advanced Gutenberg Blocks, Website Builder & Page Design Toolkit zoloblocks


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
CE21 Suite [ce21-suite]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
CE21 Suite [ce21-suite]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Easy Upload Files During Checkout [easy-upload-files-during-checkout]
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
Gravity Forms [gravityforms]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Nov 4, 2025
Affected Software
KiotViet Sync [kiotvietsync]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Nov 3, 2025
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Simple User Capabilities [simple-user-capabilities]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
TAX SERVICE Electronic HDM [virtual-hdm-for-taxservice-am]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
EM Beer Manager [em-beer-manager]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Content Locker for Elementor [content-locker-for-elementor]
Image Comparison Addon for Elementor [image-comparison-elementor-addon]
Image Hover Effects for Elementor [image-hover-effects-elementor-addon]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Researchers
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Nov 6, 2025
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Asgaros Forum [asgaros-forum]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Backup Migration [backup-backup]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Crypto Payment Gateway with Payeer for WooCommerce [crypto-payment-gateway-with-payeer-for-woocommerce]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Elegance Menu [elegance-menu]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Nov 9, 2025
Affected Software
Hub Core [hub-core]
CVSS Rating
7.5 (High)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
North [north-plugin]
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
The Events Calendar [the-events-calendar]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Footnotes Made Easy [footnotes-made-easy]
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
CYAN Backup [cyan-backup]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Ovatheme Events Manager [ova-events-manager]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Extensions for Leaflet Map [extensions-leaflet-map]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
Greenshift – animation and page builder blocks [greenshift-animation-and-page-builder-blocks]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Insert Headers and Footers Code – HT Script [insert-headers-and-footers-script]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
JetElements [jet-elements]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Ohio Extra [ohio-extra]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Reuse Builder [reuse-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Rey Core [Rey-Core]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Saphali LiqPay for donate [saphali-liqpay-for-donate]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Simple Downloads List [simple-downloads-list]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
Affected Software
Travelers' Map [travelers-map]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Visual Link Preview [visual-link-preview]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Broken Link Manager [broken-link-manager]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Centangle-Team [centangle-team]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Label Plugins [label-plugins]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
LinkedIn Resume [linkedin-resume]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
LMB^Box Smileys [lmbbox-smileys]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Mang Board WP [mangboard]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
MapMap [mapmap]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Pagerank tools [pagerank-tools]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
SH Contextual Help [sh-contextual-help]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 4, 2025
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Top Bar Notification [top-bar-notification]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Visit Counter [visit-counter]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
WP2Social Auto Publish [facebook-auto-publish]
CVSS Rating
5.6 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Everest Forms Pro [everest-forms-pro]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
WPCF7 Stop words [wpcf7-stop-words]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Academy LMS Pro [academy-pro]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
CoSchedule [coschedule-by-todaymade]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Course Booking System [course-booking-system]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
DominoKit [dominokit]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Download Manager [download-manager]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
EventPrime – Events Calendar, Bookings, Tickets & AI [eventprime-event-calendar-management]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 6, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Flexible Refund for WooCommerce – EU One Click Return [flexible-refund-and-return-order-for-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
Affected Software
follow-my-blog-post [follow-my-blog-post]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
WP Hotel Booking [wp-hotel-booking]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Nov 4, 2025
Affected Software
KiotViet Sync [kiotvietsync]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Nov 4, 2025
Affected Software
KiotViet Sync [kiotvietsync]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
Affected Software
Seriously Simple Podcasting [seriously-simple-podcasting]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
Affected Software
Seriously Simple Podcasting [seriously-simple-podcasting]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Simple User Capabilities [simple-user-capabilities]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
WP Snow Effect [wp-snow-effect]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
The Events Calendar [the-events-calendar]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Nov 7, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
Easy Email Subscription [email-subscription-with-secure-captcha]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Quick Featured Images [quick-featured-images]
CVSS Rating
4.7 (Medium)
Patch Status
Patched
Published
Nov 3, 2025
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
clubmember [clubmember]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Free Quotation [free-quotation]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
WP Hotel Booking [wp-hotel-booking]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
MeetingList [meeting-list]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Bootstrap Multi-language Responsive Portfolio [bootstrap-multi-language-responsive-portfolio]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Nari Accountant [nari-accountant]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
WP Carticon [wp-carticon]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 8, 2025
Affected Software
Auto Prune Posts [auto-prune-posts]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 7, 2025
Affected Software
Connect Contact Form 7 and AWeber [integrate-contact-form-7-and-aweber]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 8, 2025
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
Easy Email Subscription [email-subscription-with-secure-captcha]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
EventPrime – Events Calendar, Bookings, Tickets & AI [eventprime-event-calendar-management]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Nov 4, 2025
Affected Software
Features [features]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
WP Hotel Booking [wp-hotel-booking]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Import Export For WooCommerce [import-export-for-woocommerce]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Nov 4, 2025
Affected Software
KiotViet Sync [kiotvietsync]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Nov 6, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 8, 2025
Affected Software
New User Approve [new-user-approve]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
Page & Post Notes [page-post-notes]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
Posts Navigation Links for Sections and Headings – Free by WP Masters [posts-navigation-links-for-sections-and-headings-free-by-wp-masters]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 5, 2025
Affected Software
Strong Testimonials [strong-testimonials]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 8, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 3, 2025
Affected Software
ViaAds [viaads]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
Affected Software
WooCommerce Ultimate Points And Rewards [woocommerce-ultimate-points-and-rewards]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 9, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Nov 3, 2025
Affected Software
WP Global Screen Options [wp-global-screen-options]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Nov 4, 2025
Affected Software
Researcher
CVSS Rating
4.0 (Medium)
Patch Status
Patched
Published
Nov 6, 2025
Affected Software
WP Airbnb Review Slider [wp-airbnb-review-slider]
CVSS Rating
2.7 (Low)
Patch Status
Unpatched
Published
Nov 9, 2025
Affected Software
Traveler Option Tree [custom-option-tree]
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments