Weekly WP Vulnerabilities: 10/13/25 – 10/19/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-866 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-867 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-868 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched102
Unpatched64

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity1
Medium Severity124
High Severity35
Critical Severity6

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Missing Authorization43
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)38
Cross-Site Request Forgery (CSRF)18
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)14
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)9
Unrestricted Upload of File with Dangerous Type8
Exposure of Sensitive Information to an Unauthorized Actor7
Authorization Bypass Through User-Controlled Key6
Authentication Bypass Using an Alternate Path or Channel2
Improper Authorization2
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
Incorrect Privilege Assignment2
Server-Side Request Forgery (SSRF)2
Acceptance of Extraneous Untrusted Data With Trusted Data1
Deserialization of Untrusted Data1
External Control of File Name or Path1
Improper Authentication1
Improper Control of Generation of Code (‘Code Injection’)1
Improper Neutralization of Alternate XSS Syntax1
Improper Privilege Management1
Insertion of Sensitive Information into Log File1
Insertion of Sensitive Information Into Sent Data1
Missing Authentication for Critical Function1
Use of Hard-coded Credentials1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
academistacademist
Blogmaticblogmatic
ClassifiedPro – reCommerce WordPress Themeclassified-pro
Construction Lightconstruction-light
Edumaeduma
Felan Frameworkfelan-framework
GoStore – Elementor WooCommerce WordPress Themegostore
HiStudy – Online Courses & Education Templatehistudy
HomeLancerhomelancer
Houzezhouzez
KALLYAS – Creative eCommerce Multi-Purpose WordPress Themekallyas
News Eventnews-event
REHub – Price Comparison, Multi Vendor Marketplace WordPress Themerehub-theme
Revolution – Creative Multipurpose WordPress Themerevolution
Salient | Creative Multipurpose & WooCommerce Themesalient
Savory – Restaurant WordPress Themesavory
Sparkle FSEsparkle-fse
Woodmartwoodmart
XStorexstore

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Acknowledgifyacknowledgify
Admin Management Xtendedadmin-management-xtended
Advanced Coupons – WooCommerce Coupons & Store Creditadvanced-coupons-for-woocommerce-free
AI ChatBot – WPBot for Live Support and Lead Generationchatbot
Ally – Web Accessibility & Usabilitypojo-accessibility
Attesa Extraattesa-extra
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Binary MLM Planbinary-mlm-plan
Block Countryblock-country
BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editorblockspare
Business Directory Plugin – Easy Listing Directories for WordPressbusiness-directory-plugin
Case Addonscase-addons
CloudSearchcloud-search
Content Writercontent-writer
Cost Calculator Buildercost-calculator-builder
Demo Import Kitdemo-import-kit
Dhivehi Textdhivehi-text
Digisellerdigiseller
DirectoryPress – Business Directory And Classified Ad Listingdirectorypress
DocoDoco Store Locatordocodoco-store-locator
Duplicate Page, Hide Title, Custom CSS & JS, Exclude Search, Template Info – Pagelycurrent-template-name
Dynamically Display Postsdynamically-display-posts
E2Pdf – Export Pdf Tool for WordPresse2pdf
Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPresseasy-post-submission
Estatik Real Estate Pluginestatik
Event postevent-post
Event Tickets and Registrationevent-tickets
Events Calendar Made Simple – Pie Calendarpie-calendar
External Loginexternal-login
FileBird – WordPress Media Library Folders & File Managerfilebird
Find And Replace content for WordPressfind-and-replace-content
Flex QR Code Generatorflex-qr-code-generator
Free Follow-Up Emails & Marketing Automation for WooCommerce – ShopMagicshopmagic-for-woocommerce
Front End Usersfront-end-only-users
FunKItoolsfunkitools
GoCachegocache-cdn
GSpeech TTS – WordPress Text To Speech Plugingspeech
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patternsessential-blocks
Headline Analyzerheadline-analyzer
Houzez Theme – Functionalityhouzez-theme-functionality
Interactive Content – H5Ph5p
Keyy Two Factor Authentication (like Clef)keyy
Kognetiks Chatbotchatbot-chatgpt
LearnPress – WordPress LMS Pluginlearnpress
Library Management Systemlibrary-management-system
Link Whisper Freelink-whisper
Lisfinity Core – Lisfinity Core plugin used for pebas® Lisfinity WordPress themelisfinity-core
Login with YourMembership – YM SSO Loginlogin-with-yourmembership
MasterStudy LMS WordPress Plugin – for Online Courses and Educationmasterstudy-lms-learning-management-system
MDTF – Meta Data and Taxonomies Filterwp-meta-data-filter-and-taxonomy-filter
Media Library Assistantmedia-library-assistant
MeetingHub for Zoom Meeting, Google Meet, Jitsi Meet, Webex, & Microsoft Teams | The All-in-One Webinar & Video Conference Solutionmeetinghub
Memberlite Shortcodesmemberlite-shortcodes
NextMove Lite – Thank You Page for WooCommercewoo-thank-you-page-nextmove-lite
NikanWP WooCommerce Reportingwc-reports-lite
Oceanpayment CreditCard Gatewayoceanpayment-creditcard-gateway
One Page Express Companionone-page-express-companion
onOffice for WP-Websitesonoffice-for-wp-websites
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimizationoptimole-wp
Orion SMS OTP Verificationorion-sms-otp-verification
Outdooroutdoor
Ova Adventova-advent
OwnID Passwordless Loginownid-passwordless-login
Paid Videochat Turnkey Site – HTML5 PPV Live Webcamsppv-live-webcams
Penci Bookmark & Followpenci-bookmark-follow
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)buddyforms
PowerBI Embed Reportsembed-power-bi-reports
PPOM – Product Addons & Custom Fields for WooCommercewoocommerce-product-addon
Product Catalog Simplepost-type-x
Product Table For WooCommerceproduct-table-for-woocommerce
Quick Featured Imagesquick-featured-images
Quick Social Loginquick-login
Raychatraychat
Redirection for Contact Form 7wpcf7-redirect
Related Posts Literelated-posts-lite
Reloadly Pluginreloadly-topup-widget
replyMailreplymail
Reviews Widgets for Google & 45+ platforms by Repusosocial-testimonials-and-reviews-widget
Revive Social – Social Media Auto Post and Scheduling Automation Plugintweet-old-post
Rich Snippet Site Reporteasysnippet
RTMKitrometheme-for-elementor
Sendle Shipping Pluginofficial-sendle-shipping-method
SEO合集(支持百度/Google/Bing/头条推送)baiduseo
Shortcode Buttonshortcode-button
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIFshortpixel-image-optimiser
Simple Content Templates for Blog Posts & Pagessimple-post-template
Simple Job Boardsimple-job-board
Simple Stripesimple-stripe
Slick Google Mapslick-google-map
SmartCrawl SEO checker, analyzer & optimizersmartcrawl-seo
SUMO Memberships for WooCommercesumomemberships
SureForms – Contact Form, Custom Form Builder, Calculator & Moresureforms
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schemasurerank
Tab Ultimatetabs-pro
tagDiv Cloud Librarytd-cloud-library
tagDiv Composertd-composer
TARIFFUXXtariffuxx
Task Schedulertask-scheduler
TheGem Demo Import (for WPBakery)thegem-importer
TheGem Theme Elements (for WPBakery)thegem-elements
Theme Editortheme-editor
Theme Importertheme-importer
TopBartopbar
Truelysell Coretruelysell-core
u-design-coreu-design-core
UiChemy — Figma Converter for Elementor, Gutenberg and Bricksuichemy
UPC/EAN/GTIN Barcode Generator/Importerupc-ean-barcode-generator
URLYar URL Shortnerurlyar
Voice Feedback – Voice Recorder for Audio Feedbackvoice-feedback
WebinarPress – Webinar System for WordPresswp-webinarsystem
Welcart e-Commerceusc-e-shop
WhyDonate – FREE Donate button – Crowdfunding – Fundraisingwp-whydonate
Woocommerce Category and Products Accordion Panelaccordion-panel-for-category-and-products
WowRevenue – Product Bundles & Bulk Discountsrevenue
WP BookWidgetswp-bookwidgets
WP Dashboard Chatwp-dashboard-chat
WP Go Maps (formerly WP Google Maps)wp-google-maps
WP Google Map Pluginwp-google-map
WP jQuery Pagerwp-jquery-pdf-paged
WP Last Modified Infowp-last-modified-info
WP SMS – Ultimate SMS & MMS Notifications, OTP, 2FA, and WooCommerce & Forms Integrationswp-sms
Wp tabber widgetwp-tabber-widget
WP Travel Gutenberg Blockswp-travel-blocks
WP ViewSTLwp-viewstl
WPBakery Page Builderjs_composer
WPBifröst – Instant Passwordless Temporary Login Linkscreate-temporary-login
WPC Smart Quick View for WooCommercewoo-smart-quick-view
WPC Smart Wishlist for WooCommercewoo-smart-wishlist
WPCasawpcasa
wpNamedUserswpnamedusers
XX2WP Integration Toolsfb2wp-integration-tools
Zip Attachmentszip-attachments

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *