Weekly WP Vulnerabilities: 10/27/25 – 11/2/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched71
Unpatched5

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity48
High Severity23
Critical Severity5

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)21
Missing Authorization17
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)7
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)4
Exposure of Sensitive Information to an Unauthorized Actor3
Unrestricted Upload of File with Dangerous Type3
Authorization Bypass Through User-Controlled Key2
Cross-Site Request Forgery (CSRF)2
Improper Authorization2
Improper Control of Generation of Code (‘Code Injection’)2
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)2
Improper Privilege Management2
Absolute Path Traversal1
Authentication Bypass Using an Alternate Path or Channel1
Client-Side Enforcement of Server-Side Security1
Deserialization of Untrusted Data1
External Control of File Name or Path1
Improper Output Neutralization for Logs1
Incorrect Authorization1
Protection Mechanism Failure1
Server-Side Request Forgery (SSRF)1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Consultingconsulting
KALLYAS – Creative eCommerce Multi-Purpose WordPress Themekallyas
kleokleo
Masterstudy – Education WordPress Thememasterstudy
Noo JobMonsternoo-jobmonster
Sahifasahifa
SmartMag – Newspaper Magazine & News WordPresssmart-mag
WpResidencewpresidence

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Advanced Ads – Ad Manager & AdSenseadvanced-ads
Analytify Prowp-analytify-pro
Anti-Malware Security and Brute-Force Firewallgotmls
AppPresser – Mobile App Frameworkapppresser
Auto Featured Image (Auto Post Thumbnail)auto-post-thumbnail
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipmentbooking-and-rental-manager-for-woocommerce
Call Now Button – The #1 Click to Call Button for WordPresscall-now-button
Community Eventscommunity-events
Consulting Elementor Widgetsconsulting-elementor-widgets
CSS & JavaScript Toolboxcss-javascript-toolbox
Doccure Coredoccure
Document Library Litedocument-library-lite
Easy Testimonial Slider and Formeasy-testimonial-rotator
Employee Spotlight – Team Member Showcase & Meet the Team Pluginemployee-spotlight
ERI File Libraryeri-file-library
Facebook for WooCommercefacebook-for-woocommerce
Flying Images: Optimize and Lazy Load Images for Faster Page Speednazy-load
Folderlyfolderly
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)fusewp
Groundhogg — CRM, Newsletters, and Marketing Automationgroundhogg
HUSKY – Products Filter Professional for WooCommercewoocommerce-products-filter
IDonate – Blood Donation, Request And Donor Management Systemidonate
Import WP – Export and Import CSV and XML files to WordPressjc-importer
Inactive Logoutinactive-logout
Insert PHP Code Snippetinsert-php-code-snippet
Jannah – Extensionsjannah-extensions
K Elementsk-elements
King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementorking-addons
List category postslist-category-posts
LiteSpeed Cachelitespeed-cache
NS Maintenance Mode for WPns-maintenance-mode-for-wp
OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)oopspam-anti-spam
Polylangpolylang
Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carouseldepicter
Popup Box – Create Countdown, Coupon, Video, Contact Form Popupsays-popup-box
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile Apppost-smtp
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pageswplegalpages
Qi Blocksqi-blocks
Qzzr Shortcode Pluginqzzr-shortcode
Range Slider Addon for Gravity Formsrange-slider-addon-for-gravity-forms
RESTful Content Syndicationrestful-syndication
Schema & Structured Data for WP & AMPschema-and-structured-data-for-wp
Schema Scalpelschema-scalpel
Service Finder Bookingssf-booking
Simple Paymentsimple-payment
Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issuesite-checkup
SiteSEO – SEO Simplifiedsiteseo
Smart Coupons For WooCommerce Couponswt-smart-coupons-for-woocommerce
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluenttablesome
The Events Calendarthe-events-calendar
Thumbnail Slider With Lightboxwp-responsive-slider-with-lightbox
Translate WordPress and go Multilingual – Weglotweglot
Web Accessibility by accessiBeaccessibe
WooCommercewoocommerce
WooCommerce Designer Prowc-designer-pro
WordPress User Extra Fieldswp-user-extra-fields
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)delicious-recipes
WP Discoursewp-discourse
WPC Name Your Price for WooCommercewpc-name-your-price
WPCOM Memberwpcom-member
wpForo Forumwpforo
Zombifyzombify

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *