Weekly WP Vulnerabilities: 10/6/25 – 10/12/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-865 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched75
Unpatched39

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity1
Medium Severity81
High Severity24
Critical Severity8

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)35
Missing Authorization19
Cross-Site Request Forgery (CSRF)11
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)10
Exposure of Sensitive Information to an Unauthorized Actor8
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)7
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)3
Improper Privilege Management3
Authorization Bypass Through User-Controlled Key2
Deserialization of Untrusted Data2
Authentication Bypass Using an Alternate Path or Channel1
External Control of File Name or Path1
Improper Control of Generation of Code (‘Code Injection’)1
Improper Neutralization of Formula Elements in a CSV File1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
Incorrect Authorization1
Incorrect Privilege Assignment1
Insertion of Sensitive Information into Log File1
Missing Authentication for Critical Function1
Protection Mechanism Failure1
Relative Path Traversal1
Server-Side Request Forgery (SSRF)1
Unrestricted Upload of File with Dangerous Type1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Bethemebetheme
Enzy – Multipurpose WooCommerce WordPress Themeenzy
Grevo – Electric Vehicle Charging WordPress Themegrevo
HomerRoferhomeroofer
Joly – Hairdresser & Beauty Salon WordPress Themejoly
Karzokarzo
Neuronet – AI Business & Startup WordPress Themeneuronet
Newsupnewsup
Noisanoisa
Search & Go – Directory WordPress Themesearch-and-go
Sonaarsonaar
TheGem – Creative Multi-Purpose & WooCommerce WordPress Themethegem-elementor
Togo – Travel & Tour Booking WordPress Themetogo
Woodmartwoodmart
Xcare – Medical and Health Care WordPress Themexcare
xSmart – App Landing Page WordPress Theme in Tech Presentation, Promo Marketing & Advertising Agencyxsmart

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Activity Plus Reloaded for BuddyPressbp-activity-plus-reloaded
Advanced Scrollbar – Custom Scrollbar Styling and Behavioradvanced-scrollbar
AI ChatBot with ChatGPT and Content Generator by AYSays-chatgpt-assistant
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.change-wp-admin-login
AnyCommentanycomment
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Appsappexperts
Awesome Testimonialsawesome-testimonials
Blocksy Companionblocksy-companion
Blox Liteblox-lite
Chartify – WordPress Chart Pluginchart-builder
CM Registration – Tailored tool for seamless login and invitation-based registrationscm-invitation-codes
Code Quality Control Toolcode-quality-control-tool
Colibri Page Buildercolibri-page-builder
Community Eventscommunity-events
Contest Gallery – Upload, Vote & Sell with PayPal and Stripecontest-gallery
Cookie Notice & Consentcookie-notice-consent
Course Redirects for Learndash Plugincourse-redirects-for-learndash
Custom 404 Procustom-404-pro
Custom CSScustom-css-editor
Date counterdate-counter
Did Prestashop Display – Show Prestashop products in your WordPressdid-prestashop-display
Doppler Formsdoppler-form
Draft Listsimple-draft-list
Easy Plugin Statseasy-plugin-stats
Emails Catch Allemails-catch-all
Enable Media Replaceenable-media-replace
Error Log Viewer by BestWebSofterror-log-viewer
Events Maker by dFactoryevents-maker
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugineverest-backup
Featured Image from URL (FIFU)featured-image-from-url
Fix Multiple Redirectsfix-multiple-redirects
GSheetConnector For Gravity Formsgsheetconnector-gravity-forms
Lisfinity Core – Lisfinity Core plugin used for pebas® Lisfinity WordPress themelisfinity-core
MapSVG – Vector maps, Image maps, Google Mapsmapsvg-lite-interactive-vector-maps
Masterstudy Elementor Widgetsmasterstudy-elementor-widgets
MasterStudy LMS Promasterstudy-lms-learning-management-system-pro
MeetingHub for Zoom Meeting, Google Meet, Jitsi Meet, Webex, & Microsoft Teams | The All-in-One Webinar & Video Conference Solutionmeetinghub
Motors – Car Dealership & Classified Listings Pluginmotors-car-dealership-classified-listings
MSN Partner Hubmicrosoft-start
MSTW CSV EXPORTERmstw-csv-exporter
My auctions allegromy-auctions-allegro-free-edition
NEX-Forms – Ultimate Forms Plugin for WordPressnex-forms-express-wp-form-builder
Next Page, Not Next Postnext-page-not-next-post
Open Close Store for WooCommerce – Business Hours Schedules Managerwoc-open-close
Open Currency Converterartiss-currency-converter
Ovatheme Events Managerova-events-manager
Page Blockspage-blocks
Password only loginpassword-only-login
Plugin Name: WP Business Hourswp-business-hours
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers popup-builder-block
Post List Featured Imagepost-list-featured-image
Progress Plannerprogress-planner
Publitiopublitio
RealPress – Real Estate Pluginrealpress
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Logincustom-registration-form-builder-with-submission-manager
Reoon Email Verifierreoon-email-verifier
Search & Filtersearch-filter
Simple Finance Calculatorsimple-finance-calculator
Slider Revolutionrevslider
Smash Balloon Social Post Feed – Simple Social Feeds for WordPresscustom-facebook-feed
Stock History & Reports Manager for WooCommercestock-snapshot-for-woocommerce
Survey Makersurvey-maker
Table Block by RioVizual – Comparison Table, Pricing Table, and Pros & Cons Box for Gutenberg riovizual
tagDiv Composertd-composer
Trinity Audio – Text to Speech AI audio player to convert content into audiotrinity-audio
Ultimate Addons for WPBakeryUltimate_VC_Addons
Web Accessibility by accessiBeaccessibe
Welcart e-Commerceusc-e-shop
WidgetPack Comment Systemwidgetpack-comment-system
WooCommerce Designer Prowc-designer-pro
WordPress Live Webcam Widget & Shortcodewp-webcam-widget-shortcode
WP Easy Toggleswp-easy-toggles
WP Freeiowp-freeio
WP Gmail SMTPwp-gmail-smtp
WP Go Maps (formerly WP Google Maps)wp-google-maps
WP JobHuntwp-jobhunt
WP Links Pagewp-links-page
WP Mapbox GL JS Mapswp-mapbox-gl-js
WP Resetwp-reset
WP Scraperwp-scraper
WP Travel Engine – Tour Booking Plugin – Tour Operator Softwarewp-travel-engine
WPC Smart Wishlist for WooCommercewoo-smart-wishlist
WSAnalytics – Google Analytics And Dashboardswsanalytics-google-analytics-and-dashboards
YOP Pollyop-poll

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *