Weekly WP Vulnerabilities: 10/20/25 – 10/26/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-869 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-870 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched77
Unpatched43

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity2
Medium Severity101
High Severity13
Critical Severity4

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)49
Missing Authorization20
Cross-Site Request Forgery (CSRF)9
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)8
Server-Side Request Forgery (SSRF)6
Improper Authorization5
Exposure of Sensitive Information to an Unauthorized Actor3
Unrestricted Upload of File with Dangerous Type3
Authorization Bypass Through User-Controlled Key2
Improper Control of Generation of Code (‘Code Injection’)2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
Deserialization of Untrusted Data1
Improper Access Control1
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)1
Improper Input Validation1
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)1
Improper Neutralization of Formula Elements in a CSV File1
Improper Privilege Management1
Incorrect Authorization1
Incorrect Privilege Assignment1
Insertion of Sensitive Information into Log File1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Bard – A Theatre and Performing Arts WordPress Themebardwp
Listeo – Directory & Listings With Booking – WordPress Themelisteo
Open Source Genesis Frameworkgenesis
The7 — Website and eCommerce Builder for WordPressdt-the7

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Academy LMS Proacademy-pro
ACF to REST APIacf-to-rest-api
Advanced Database Cleaneradvanced-database-cleaner
AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistantchatbot-ai-free-models
AIO Forms – Craft Complex Forms Easilyall-in-one-forms
Ajax Search Lite – Live Search & Filterajax-search-lite
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easieraio-time-clock-lite
BackWPup – WordPress Backup & Restore Pluginbackwpup
Beaver Builder Plugin (Starter Version)bb-plugin
Bg Book Publisherbg-book-publisher
Bold Page Builderbold-page-builder
Builderall for WordPressbuilderall-cheetah-for-wp
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & Morecharitable
Check Plagiarismcheck-plagiarism
Cinza Gridcinza-grid
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPresssprout-invoices
Directorist: AI-Powered Business Directory Plugin with Classified Ads Listingsdirectorist
Disable Content Editor For Specific Templatedisable-contect-editor-for-specific-template
Discussion Board – WordPress Forum Pluginwp-discussion-board
Dynamic User Directorydynamic-user-directory
Easy Social Share Buttons for WordPresseasy-social-share-buttons3
Element Pack Addons for Elementorbdthemes-element-pack-lite
Email Subscription Popupemail-subscribe
Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emailsemail-tracker
eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teamseroom-zoom-meetings-webinar
FanBridge signupfanbridge-signup
Fast Velocity Minifyfast-velocity-minify
Flexible Refund and Return Order for WooCommerceflexible-refund-and-return-order-for-woocommerce
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)fusewp
GenerateBlocksgenerateblocks
Gutenberggutenberg
Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocksadvanced-gutenberg
HAPPY – Helpdesk Support Ticket Systemhappy-helpdesk-support-ticket-system
IndieAuthindieauth
JB News Tickerjb-news-ticker
King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementorking-addons
KiotViet Synckiotvietsync
LLM Hubspot Blog Importllm-hubspot-blog-import
MasterStudy LMS WordPress Plugin – for Online Courses and Educationmasterstudy-lms-learning-management-system
Material Design Iconic Font Integrationmaterial-design-iconic-font-integration
MDTF – Meta Data and Taxonomies Filterwp-meta-data-filter-and-taxonomy-filter
Microsoft Azure Storage for WordPresswindows-azure-storage
Mixlr Shortcodemixlr-shortcode
Multi Item Responsive Slidermislider
MxChat – AI Chatbot for WordPressmxchat-basic
Name: Print Button Shortcodeprint-button-shortcode
NGINX Cache Optimizernginx-cache-optimizer
NS Maintenance Mode for WPns-maintenance-mode-for-wp
Oboxmedia Adsoboxmedia-ads
Originality.ai AI Checkeroriginality-ai
Password Policy Manager | Password Managerpassword-policy-manager
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Contentpassword-protected
Persian Admnin Fontspersian-admin-fonts
Photographers galleriesphotographers-galleries
PixelYourSite – Your smart PIXEL (TAG) & API Managerpixelyoursite
Playerzbrplayerzbr
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggerspopup-builder-block
Posts By Tagposts-by-tag
PowerPress Podcasting plugin by Blubrrypowerpress
Product Filter by WBWwoo-product-filter
qnotsquizqnotsquiz
Quickcreator – AI Blog Writerquickcreator
RapidResultrapidresult
Real Cookie Banner: GDPR & ePrivacy Cookie Consentreal-cookie-banner
Responsive iframe GoogleMapresponsive-iframe-googlemap
Responsive Progress Barresponsive-progress-bar
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregatorfeedzy-rss-feeds
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solutionshopengine
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor)woolentor-addons
Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your websitesimple-banner
Simple Business Datasimple-business-data
Simple Excel Pricelist for WooCommercesimple-excel-pricelist-for-woocommerce
Simple Pull Quotesimple-pull-quote
Simple Registration for WooCommercewoocommerce-simple-registration
Simple Tableau Vizsimple-tableau-viz
Simple Youtube Shortcodesimple-youtube-shortcode
Slider Templatesslider-templates
SM CountDown Widgetsmcountdown
Social Feed Galleryinsta-gallery
SpendeOnline.orgspendeonline
ST Categories Widgetst-category-wp
Stockie Extrastockie-extra
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptionswp-full-stripe-free
Supervisorsupervisor
Testimonial Carousel For Elementortestimonials-carousel-elementor
This-or-Thatthis-or-that
Time Clock – A WordPress Employee & Volunteer Time Clock Plugintime-clock
Tutor LMS Protutor-pro
Tutor LMS – eLearning and online course solutiontutor
URL Shortener Plugin For WordPressexact-links
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Secondsuserfeedback-lite
VikBooking Hotel Booking Engine & PMSvikbooking
VNPAY Payment gatewayvnpay-for-woocommerce
Watu Quizwatu
Welcart e-Commerceusc-e-shop
WhyDonate – FREE Donate button – Crowdfunding – Fundraisingwp-whydonate
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgetswidget-options
WooCommerce Designer Prowc-designer-pro
WP AD Gallerywp-ad-gallery
WP AdCenter – Ad Manager & Adsense Adswpadcenter
WP Gravity Forms Zoho CRM and Bigingf-zoho
WP Responsive Meet The Teamwp-responsive-meet-the-team
WP Restaurant Listingswp-restaurant-listings
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPresswpvr
WP-Force Images Downloadwp-force-images-download
WP-Thumbnailwp-thumbnail
WPC Countdown Timer for WooCommercewpc-countdown-timer
WPCompletewpcomplete
wpForo Forumwpforo
WPMobile.Appwpappninja
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patternszoloblocks

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *