This website uses cookies, pixels, and similar technologies (collectively “Cookies”) to improve your browsing experience. By clicking “Accept All”, you agree to the storing of Cookies on your device and that we may share, track, store, and analyze your interactions with the website to enhance site navigation, analyze site usage, and assist in our marketing efforts. For more information on our use of cookies please review our Cookie Policy.
The Latest WordPress Security News for December 2025: Presented by the Wordfence Threat Intelligence team.
Follow Wordfence On Your Favorite Social Media Platform
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (December 8, 2025 to December 14, 2025)
Last week, there were 238 vulnerabilities disclosed in 218 WordPress Plugins and 9 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database,…
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (December 1, 2025 to December 7, 2025)
Last week, there were 179 vulnerabilities disclosed in 163 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database,…
-
Wordfence Bug Bounty Program Monthly Report – November 2025
Last month in November 2025, the Wordfence Bug Bounty Program received 746 vulnerability submissions from our growing community of security researchers working to improve the…
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (November 24, 2025 to November 30, 2025)
Last week, there were 74 vulnerabilities disclosed in 67 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database,…
-
Attackers Actively Exploiting Critical Vulnerability in Sneeit Framework Plugin
On June 10th, 2025, we received a submission for a Remote Code Execution vulnerability in Sneeit Framework, a WordPress plugin with an estimated 1,700 active…
-
100,000 WordPress Sites Affected by Remote Code Execution Vulnerability in Advanced Custom Fields: Extended WordPress Plugin
On November 18th, 2025, we received a submission for an unauthenticated Remote Code Execution vulnerability in Advanced Custom Fields: Extended, a WordPress plugin with more…
-
Attackers Actively Exploiting Critical Vulnerability in King Addons for Elementor Plugin
On July 24th, 2025, we received a submission for a Privilege Escalation vulnerability in King Addons for Elementor, a WordPress plugin with more than 10,000…

Check out our database for a full list of WordPress plugin vulnerabilities.
Every week, the Wordfence team publishes unique threat intelligence data, research, alerts and threat analysis to the public WordPress community as part of our commitment to a Defense In Depth approach to security.
📭 Get the Latest WordPress Security News, Alerts and Updates Sent to Your Inbox Weekly:
Join The WordPress Security Mailing List
WordPress Security News Archives:
These stories and more can be found on the Wordfence Blog.
- WordPress Security News December 2025
- WordPress Security News November 2025
- WordPress Security News October 2025
WordPress Security Video Highlights:
Plugin vulnerability alerts and summaries from the Wordfence Youtube Channel.







