Wordfence Intelligence Weekly WordPress Vulnerability Report (December 1, 2025 to December 7, 2025)

Wordfence Intelligence Weekly WordPress Vulnerability Report (December 1, 2025 to December 7, 2025)

Last week, there were 192 vulnerabilities disclosed in 174 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 60 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 31,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 123
Unpatched 69


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 160
High Severity 22
Critical Severity 10


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Missing Authorization 56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 53
Cross-Site Request Forgery (CSRF) 30
Exposure of Sensitive Information to an Unauthorized Actor 14
Unrestricted Upload of File with Dangerous Type 11
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 8
Authorization Bypass Through User-Controlled Key 6
Improper Authorization 2
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
Improper Privilege Management 2
External Control of File Name or Path 1
Improper Authentication 1
Improper Control of Generation of Code ('Code Injection') 1
Incorrect Implementation of Authentication Algorithm 1
Incorrect Privilege Assignment 1
Server-Side Request Forgery (SSRF) 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
18
16
14
9
9
6
6
6
5
5
5
4
4
4
4
Mdr
4
3
3
3
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
10Web Booster – Website speed optimization, Cache & Page Speed optimizer tenweb-speed-optimizer
Accessiy by CodeConfig – Accessibility Widgets for ADA, EAA & WCAG Compliance codeconfig-accessibility
Actionwear products sync actionwear-products-sync
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript add-custom-codes
Advanced Custom Fields: Extended acf-extended
Advanced FAQ Manager advanced-faq-manager
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic all-in-one-seo-pack
All-in-One Video Gallery all-in-one-video-gallery
Application Passwords application-passwords
Arconix Shortcodes arconix-shortcodes
ARK Related Posts ark-relatedpost
Auto Alt Text auto-alt-text
Auto Thumbnailer auto-thumbnailer
Autoptimize autoptimize
Backup, Restore and Migrate your sites with XCloner xcloner-backup-and-restore
Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library blockart-blocks
Booking Calendar booking
Bread & Butter: AI Lead Intelligence Engine bread-butter
Business Directory Plugin – Easy Listing Directories for WordPress business-directory-plugin
Canadian Nutrition Facts Label canadian-nutrition-facts-label
Chartify – WordPress Chart Plugin chart-builder
Clik stats clikstats
Constant Contact + WooCommerce constant-contact-woocommerce
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress contact-form-plugin
Contact Form Email contact-form-to-email
ContentStudio contentstudio
Cool Tag Cloud cool-tag-cloud
CoSign Single Signon cosign-sso
Cost Calculator Builder cost-calculator-builder
CRM Memberships crm-memberships
CryptX cryptx
CSS3 Buttons css3-buttons
CSSIgniter Shortcodes cssigniter-shortcodes
CSV Sumotto csv-sumotto
Custom Layouts – Post + Product grids made easy custom-layouts
Custom Post Type UI custom-post-type-ui
Custom Sidebars by ProteusThemes custom-sidebars-by-proteusthemes
Cute News Ticker cute-news-ticker
Demo Importer Plus demo-importer-plus
DesignThemes LMS designthemes-lms
dream gallery dream-gallery
Easy Jump Links Menus easy-jump-links-menus
ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system
Envo Extra envo-extra
EPROLO-Dropshipping eprolo-dropshipping
Ergonet Cache ergonet-varnish-cache
ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support erp
Event Booking Manager for WooCommerce mage-eventpress
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin everest-backup
Export All Posts, Products, Orders, Refunds & Users wp-ultimate-exporter
Extra Post Images extra-post-images
Featured Image via URL featured-image-via-url
Feedback Modal for Website feedback-modal-for-website
Feeds for TikTok – Display Video Feeds in Grid Layouts b-tiktok-feed
FitVids for WordPress fitvids-for-wordpress
Flex QR Code Generator flex-qr-code-generator
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution fluent-booking
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler fluent-cart
Formstack Online Forms formstack
Frontend Admin by DynamiApps acf-frontend-form-element
FunnelKit – Funnel Builder for WooCommerce Checkout funnel-builder
g-FFL Cockpit g-ffl-cockpit
Generic Elements generic-elements-for-elementor
Get Cash get-cash
Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications
Gravity Forms gravityforms
GSheetConnector For WPForms – WPForms Google Sheets Integration (Real-Time Sync) gsheetconnector-wpforms
Gutenverse News – News Blocks for Blog & Magazine Sites gutenverse-news
Happy Addons for Elementor happy-elementor-addons
Hide Categories Or Products On Shop Page hide-categories-or-products-on-shop-page
HUSKY – Products Filter Professional for WooCommerce woocommerce-products-filter
Hype pico
Image Cleanup image-cleanup
Image Optimizer by wps.sk image-optimizer-wpssk
Jabbernotification jabberbenachrichtigung
JNews Gallery jnews-gallery
JNews Paywall jnews-paywall
Kadence WooCommerce Email Designer kadence-woocommerce-email-designer
Link Whisper Free link-whisper
List Attachments Shortcode list-attachments-shortcode
Listar – Directory Listing & Classifieds WordPress Plugin listar-directory-listing
Live CSS Preview live-css-preview
Live Sales Notification for Woocommerce – Woomotiv woomotiv
Make Section & Column Clickable For Elementor make-section-column-clickable-elementor
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits master-addons
Media Library Downloader media-library-downloader
Modula Image Gallery – Photo Grid & Video Gallery modula-best-grid-gallery
MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce
MxChat – AI Chatbot & Content Generation for WordPress mxchat-basic
My auctions allegro my-auctions-allegro-free-edition
My Tickets – Accessible Event Ticketing my-tickets
myLCO mylco
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit nexter-extension
Norby AI norby-ai
Nouri.sh Newsletter newsletters-from-rss-to-email-newsletters-using-nourish
Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto codistoconnect
Omnipress omnipress
Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce
Payaza payaza
Paysera Payment Gateway for WooCommerce woo-payment-gateway-paysera
PDF Catalog for WooCommerce pdf-catalog-for-woocommerce
PDF Invoices & Packing Slips for WooCommerce woocommerce-pdf-invoices-packing-slips
PDF Thumbnail Generator pdf-thumbnail-generator
Photo Gallery by Ays – Responsive Image Gallery gallery-photo-gallery
Plug your WooCommerce into the largest catalog of customized print products from Helloprint helloprint
Portfolio and Projects portfolio-and-projects
Post Cloner post-cloner
Post Grid post-grid
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App post-smtp
PostGallery postgallery
Premium Addons for Elementor – Powerful Elementor Templates & Widgets premium-addons-for-elementor
Projectopia – Project Management Tool projectopia-core
Quantic Social Image Hover tw-image-hover-share
Quiz Maker by AYS quiz-maker
reHub Framework rehub-framework
RevInsite revinsite
Rich Showcase for Google Reviews widget-google-reviews
Salon Booking System – Free Version salon-booking-system
Search, Filters & Merchandising for WooCommerce instantsearch-for-woocommerce
SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter
Sermon Manager sermon-manager-for-wordpress
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution shopengine
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert
SMTP Mail smtp-mail
Social Feed Gallery Portfolio social-feed-gallery-portfolio
SSP Debug ssp-debugging
Starter Templates – AI-Powered Templates for Elementor & Gutenberg astra-sites
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers suremails
SurveyFunnel – Survey Plugin for WordPress surveyfunnel-lite
SurveyJS: Drag & Drop Form Builder surveyjs
SV100 Companion sv100-companion
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent tablesome
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms simple-tags
Takeads monetize-link
Thai Lottery Widget thai-lottery-widget
Thank You Page Customizer for WooCommerce – Increase Your Sales woo-thank-you-page-customizer
The7 Elements dt-the7-core
Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor thim-elementor-kit
Time Sheets time-sheets
Torod – The smart shipping and delivery portal for e-shops and retailers torod
TR Timthumb tr-timthumb
Trail Manager trail-manager
Twitscription twitscription
Ultra Skype Button ultra-skype-button
User Generator and Importer user-importer-and-generator
User Spam Remover user-spam-remover
User Verification by PickPlugins user-verification
VikRentCar Car Rental Management System vikrentcar
Visualizer – Tables & Charts Manager with Built-in AI Generator visualizer
Voidek Employee Portal voidek-employee-portal
WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors wc-vendors
Webcake – Landing Page Builder webcake
WebP Express webp-express
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot wedocs
Weekly Planner weekly-planner
Widgets for Google Reviews wp-reviews-plugin-for-google
WP AI CoPilot – AI content writer plugin, ChatGPT WordPress, GPT-3/4 , Ai assistance ai-co-pilot-for-wp
WP Directory Kit wpdirectorykit
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics wp-google-analytics-events
WP Landing Page wp-landing-page
Wp Social Login and Register Social Counter wp-social
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets wp-social-reviews
WP Ultimate Review wp-ultimate-review
WP-SOS-Donate Donation Sidebar Plugin wp-sos-donate
WPKoi Templates for Elementor wpkoi-templates-for-elementor
WPS Bidouille wps-bidouille
WPZOOM Addons for Elementor – Starter Templates & Widgets wpzoom-elementor-addons
Xagio SEO – AI Powered SEO xagio-seo
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons
Yandex.Metrica wp-yandex-metrika
Yet Another WebClap for WordPress yet-another-webclap-for-wordpress
Zigaform – Price Calculator & Cost Estimation Form Builder Lite zigaform-calculator-cost-estimation-form-builder-lite


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
AdForest adforest
REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme rehub-theme


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
10.0 (Critical)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
WP Directory Kit [wpdirectorykit]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
DesignThemes LMS [designthemes-lms]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Flex QR Code Generator [flex-qr-code-generator]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
Frontend Admin by DynamiApps [acf-frontend-form-element]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
Gravity Forms [gravityforms]
Researcher(s): Unknown
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
SV100 Companion [sv100-companion]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
All-in-One Video Gallery [all-in-one-video-gallery]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Auto Thumbnailer [auto-thumbnailer]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
ContentStudio [contentstudio]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Dec 1, 2025
Affected Software
Cost Calculator Builder [cost-calculator-builder]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Demo Importer Plus [demo-importer-plus]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Featured Image via URL [featured-image-via-url]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
PostGallery [postgallery]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
User Generator and Importer [user-importer-and-generator]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Cool Tag Cloud [cool-tag-cloud]
Researcher
CVSS Rating
8.1 (High)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
My auctions allegro [my-auctions-allegro-free-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
My auctions allegro [my-auctions-allegro-free-edition]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
The7 Elements [dt-the7-core]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Dec 1, 2025
Affected Software
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Rich Showcase for Google Reviews [widget-google-reviews]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Time Sheets [time-sheets]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Widgets for Google Reviews [wp-reviews-plugin-for-google]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Advanced FAQ Manager [advanced-faq-manager]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 1, 2025
Affected Software
Arconix Shortcodes [arconix-shortcodes]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
Autoptimize [autoptimize]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Canadian Nutrition Facts Label [canadian-nutrition-facts-label]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
CryptX [cryptx]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
CSS3 Buttons [css3-buttons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
CSSIgniter Shortcodes [cssigniter-shortcodes]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Cute News Ticker [cute-news-ticker]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Easy Jump Links Menus [easy-jump-links-menus]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Envo Extra [envo-extra]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Extra Post Images [extra-post-images]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 7, 2025
Affected Software
Generic Elements [generic-elements-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
JNews Gallery [jnews-gallery]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
List Attachments Shortcode [list-attachments-shortcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Omnipress [omnipress]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
RevInsite [revinsite]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Sermon Manager [sermon-manager-for-wordpress]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Social Feed Gallery Portfolio [social-feed-gallery-portfolio]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Thai Lottery Widget [thai-lottery-widget]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
TR Timthumb [tr-timthumb]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 7, 2025
Affected Software
WP Ultimate Review [wp-ultimate-review]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Ultra Skype Button [ultra-skype-button]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Yet Another WebClap for WordPress [yet-another-webclap-for-wordpress]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 3, 2025
Affected Software
Clik stats [clikstats]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
CSV Sumotto [csv-sumotto]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
dream gallery [dream-gallery]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Jabbernotification [jabberbenachrichtigung]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Link Whisper Free [link-whisper]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
myLCO [mylco]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Nouri.sh Newsletter [newsletters-from-rss-to-email-newsletters-using-nourish]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Twitscription [twitscription]
CVSS Rating
5.4 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Application Passwords [application-passwords]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
PDF Catalog for WooCommerce [pdf-catalog-for-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
AdForest [adforest]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Constant Contact + WooCommerce [constant-contact-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 1, 2025
Affected Software
Contact Form Email [contact-form-to-email]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
CRM Memberships [crm-memberships]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Feedback Modal for Website [feedback-modal-for-website]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
g-FFL Cockpit [g-ffl-cockpit]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
g-FFL Cockpit [g-ffl-cockpit]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 1, 2025
Affected Software
Get Cash [get-cash]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Hype [pico]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Image Cleanup [image-cleanup]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 2, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
Order Delivery Date for WooCommerce [order-delivery-date-for-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Payaza [payaza]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
Post Cloner [post-cloner]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 3, 2025
Affected Software
Post Grid [post-grid]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
SendPulse Email Marketing Newsletter [sendpulse-email-marketing-newsletter]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
SSP Debug [ssp-debugging]
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 2, 2025
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
User Spam Remover [user-spam-remover]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Voidek Employee Portal [voidek-employee-portal]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
WebP Express [webp-express]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Dec 7, 2025
Affected Software
Yandex.Metrica [wp-yandex-metrika]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Dec 1, 2025
Affected Software
Zigaform – Price Calculator & Cost Estimation Form Builder Lite [zigaform-calculator-cost-estimation-form-builder-lite]
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Dec 1, 2025
Affected Software
WP Directory Kit [wpdirectorykit]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
FitVids for WordPress [fitvids-for-wordpress]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Dec 7, 2025
Affected Software
Make Section & Column Clickable For Elementor [make-section-column-clickable-elementor]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Trail Manager [trail-manager]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Weekly Planner [weekly-planner]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 6, 2025
Affected Software
Actionwear products sync [actionwear-products-sync]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
ARK Related Posts [ark-relatedpost]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Auto Alt Text [auto-alt-text]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 3, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 7, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
ContentStudio [contentstudio]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Custom Sidebars by ProteusThemes [custom-sidebars-by-proteusthemes]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
EPROLO-Dropshipping [eprolo-dropshipping]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Ergonet Cache [ergonet-varnish-cache]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Gravitec.net – Web Push Notifications [gravitec-net-web-push-notifications]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Happy Addons for Elementor [happy-elementor-addons]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Hide Categories Or Products On Shop Page [hide-categories-or-products-on-shop-page]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Image Cleanup [image-cleanup]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Image Optimizer by wps.sk [image-optimizer-wpssk]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
JNews Paywall [jnews-paywall]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Live CSS Preview [live-css-preview]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Media Library Downloader [media-library-downloader]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
MultiParcels Shipping For WooCommerce [multiparcels-shipping-for-woocommerce]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Norby AI [norby-ai]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
PDF Thumbnail Generator [pdf-thumbnail-generator]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 1, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Portfolio and Projects [portfolio-and-projects]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 2, 2025
Affected Software
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Quantic Social Image Hover [tw-image-hover-share]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
Quiz Maker by AYS [quiz-maker]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
reHub Framework [rehub-framework]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 7, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
SMTP Mail [smtp-mail]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Takeads [monetize-link]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 5, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 4, 2025
Affected Software
Time Sheets [time-sheets]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Paysera Payment Gateway for WooCommerce [woo-payment-gateway-paysera]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 7, 2025
Affected Software
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Dec 5, 2025
Affected Software
WP Landing Page [wp-landing-page]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 6, 2025
Affected Software
WPKoi Templates for Elementor [wpkoi-templates-for-elementor]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 2, 2025
Affected Software
WPS Bidouille [wps-bidouille]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Dec 4, 2025
Affected Software
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments