Weekly WP Vulnerabilities: 11/03/25 – 11/09/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • None

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched88
Unpatched44

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity105
High Severity18
Critical Severity9

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Missing Authorization33
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)32
Cross-Site Request Forgery (CSRF)18
Exposure of Sensitive Information to an Unauthorized Actor10
Unrestricted Upload of File with Dangerous Type7
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)5
Deserialization of Untrusted Data3
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)3
Server-Side Request Forgery (SSRF)3
Authorization Bypass Through User-Controlled Key2
Improper Authorization2
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
Improper Control of Generation of Code (‘Code Injection’)1
Incorrect Authorization1
Incorrect Comparison1
Insertion of Sensitive Information into Log File1
Missing Authentication for Critical Function1
Protection Mechanism Failure1
Reliance on Untrusted Inputs in a Security Decision1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Use of Hard-coded Cryptographic Key1
Use of Hard-coded Password1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software Slug
NO THEMES THIS WEEK

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Academy LMS Proacademy-pro
Academy LMS – WordPress LMS Plugin for Complete eLearning Solutionacademy
Ad Inserter – Ad Manager & AdSense Adsad-inserter
Ai Auto Tool Content Writing Assistant All in Oneai-auto-tool
AI Engineai-engine
Alex Reservations: Smart Restaurant Bookingalex-reservations
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easieraio-time-clock-lite
Asgaros Forumasgaros-forum
Associados Amazon Pluginbrzon
aThemes Addons for Elementorathemes-addons-for-elementor-lite
Auto Prune Postsauto-prune-posts
Backup Migrationbackup-backup
Better Find and Replace – AI-Powered Suggestionsreal-time-auto-find-and-replace
Blog2Social: Social Media Auto Post & Schedulerblog2social
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendarbooking-manager
Bootstrap Multi-language Responsive Portfoliobootstrap-multi-language-responsive-portfolio
Broken Link Managerbroken-link-manager
Carousel Block – Responsive Image and Content Carouselb-carousel-block
CE21 Suitece21-suite
Centangle-Teamcentangle-team
clubmemberclubmember
Connector Wizard (formerly LC Wizard)ghl-wizard
Contact Form 7 AWeber Extensionintegrate-contact-form-7-and-aweber
Content Locker for Elementorcontent-locker-for-elementor
Content Pilot – Autoblogging & Affiliate Marketing Suitewp-content-pilot
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consentgdpr-cookie-consent
CoSchedulecoschedule-by-todaymade
Course Booking Systemcourse-booking-system
Crypto Payment Gateway with Payeer for WooCommercecrypto-payment-gateway-with-payeer-for-woocommerce
CYAN Backupcyan-backup
Depicter — Popup & Slider Builderdepicter
Document Embedder – Embed PDFs, Word, Excel, and Other Filesdocument-emberdder
DominoKitdominokit
Download Managerdownload-manager
Easy Digital Downloads – eCommerce Payments and Subscriptions made easyeasy-digital-downloads
Easy Email Subscriptionemail-subscription-with-secure-captcha
Easy Upload Files During Checkouteasy-upload-files-during-checkout
Easy WordPress Funnel Builder To Collect Leads And Increase Sales – WPFunnelswpfunnels
Elegance Menuelegance-menu
EM Beer Managerem-beer-manager
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerceemail-subscribers
EventPrime – Events Calendar, Bookings and Ticketseventprime-event-calendar-management
Everest Forms Proeverest-forms-pro
Extensions for Leaflet Mapextensions-leaflet-map
Featuresfeatures
File Manager for Google Drive – Integrate Google Driveintegrate-google-drive
Flexible Refund and Return Order for WooCommerceflexible-refund-and-return-order-for-woocommerce
Footnotes Made Easyfootnotes-made-easy
Free Quotationfree-quotation
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommercewp-marketing-automations
Gallery Plugin for WordPress – Envira Photo Galleryenvira-gallery-lite
Graphina – Charts and Graphs For Elementorgraphina-elementor-charts-and-graphs
Gravity Formsgravityforms
Greenshift – animation and page builder blocksgreenshift-animation-and-page-builder-blocks
Groupsgroups
Guest posting / Frontend Posting / Front Editor – WP Front User Submitfront-editor
HTML Forms – Simple WordPress Forms Pluginhtml-forms
Hubbub Lite – Fast, free social sharing and follow buttonssocial-pug
IDonate – Blood Donation, Request And Donor Management Systemidonate
Image Comparison Addon for Elementorimage-comparison-elementor-addon
Image Hover Effects for Elementorimage-hover-effects-elementor-addon
Import Export For WooCommerceimport-export-for-woocommerce
Insert Headers and Footers Code – HT Scriptinsert-headers-and-footers-script
KiotViet Synckiotvietsync
Label Pluginslabel-plugins
LearnPress – WordPress LMS Pluginlearnpress
LinkedIn Resumelinkedin-resume
LMB^Box Smileyslmbbox-smileys
Mail Mint – Newsletters, Email Marketing, Automation, WooCommerce Emails, Post Notification, and moremail-mint
Mang Board WPmangboard
MapMapmapmap
Master Blocks – Ultimate Gutenberg Blocks for Marketersultimate-blocks-for-gutenberg
MeetingListmeeting-list
Nari Accountantnari-accountant
New User Approvenew-user-approve
Ohio Extraohio-extra
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & Morethemeisle-companion
Ovatheme Events Managerova-events-manager
Page & Post Notespage-post-notes
Pagerank toolspagerank-tools
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restrictionpaid-member-subscriptions
Posts Navigation Links for Sections and Headings – Free by WP Mastersposts-navigation-links-for-sections-and-headings-free-by-wp-masters
Premium Portfolio Features for Phlox themeauxin-portfolio
Quick Featured Imagesquick-featured-images
Reuse Builderreuse-builder
Rey CoreRey-Core
Saphali LiqPay for donatesaphali-liqpay-for-donate
Seriously Simple Podcastingseriously-simple-podcasting
SH Contextual Helpsh-contextual-help
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor)woolentor-addons
Simple Downloads Listsimple-downloads-list
Simple User Capabilitiessimple-user-capabilities
Smart Auto Upload Images – Import External Imagessmart-auto-upload-images
SMS for WordPresssms4wp
Spectra Gutenberg Blocks – Website Builder for the Block Editorultimate-addons-for-gutenberg
Strong Testimonialsstrong-testimonials
SUMO Affiliates Proaffs
TablePress – Tables in WordPress made easytablepress
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAIsimple-tags
TAX SERVICE Electronic HDMvirtual-hdm-for-taxservice-am
The Events Calendarthe-events-calendar
Top Bar Notificationtop-bar-notification
Travelers’ Maptravelers-map
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Pluginuncanny-automator
ViaAdsviaads
Visit Countervisit-counter
Visual Link Previewvisual-link-preview
WooCommerce Ultimate Points And Rewardswoocommerce-ultimate-points-and-rewards
WordPress eCommerce Plugin – Studiocartstudiocart
WP 2FA – Two-factor authentication for WordPresswp-2fa
WP Airbnb Review Sliderwp-airbnb-review-slider
WP Carticonwp-carticon
WP Global Screen Optionswp-global-screen-options
WP Hotel Bookingwp-hotel-booking
WP Snow Effectwp-snow-effect
WP2Social Auto Publishfacebook-auto-publish
WPCF7 Stop wordswpcf7-stop-words
WPeMatico RSS Feed Fetcherwpematico
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patternszoloblocks

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *