Weekly WP Vulnerabilities: 11/10/25 – 11/16/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched70
Unpatched53

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity104
High Severity15
Critical Severity4

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)44
Missing Authorization27
Cross-Site Request Forgery (CSRF)9
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)8
Authorization Bypass Through User-Controlled Key7
Exposure of Sensitive Information to an Unauthorized Actor4
Improper Control of Generation of Code (‘Code Injection’)3
Improper Privilege Management3
Improper Authorization2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
Unrestricted Upload of File with Dangerous Type2
Client-Side Enforcement of Server-Side Security1
Deserialization of Untrusted Data1
Exposure of Private Personal Information to an Unauthorized Actor1
External Control of File Name or Path1
Improper Access Control1
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)1
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)1
Insecure Storage of Sensitive Information1
Insertion of Sensitive Information into Externally-Accessible File or Directory1
Missing Authentication for Critical Function1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Use of Insufficiently Random Values1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Angel – Fashion Model Agency WordPress CMS Themeangel
Lobo – WordPress Portfolio for Freelancers & Agencieslobo

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
0 Day Analytics0-day-analytics
Add Multiple Markeradd-multiple-marker
AI Engineai-engine
AI-Powered Project Management & Task Manager with Kanban Board & Gantt Chart – WP Project Managerwedevs-project-manager
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Trafficall-in-one-seo-pack
Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Imagesalt-text-generator
Appointment Booking Calendarappointment-booking-calendar
Asgaros Forumasgaros-forum
Astra Security Suite – Firewall & Malware Scangetastra
Authors Listauthors-list
Auto Amazon Links – Amazon Associates Affiliate Pluginamazon-auto-links
Blocksy Companionblocksy-companion
Booking Calendarbooking
Booking Calendar | Appointment Booking | Bookitbookit
Booking for Appointments and Events Calendar – Ameliaameliabooking
Chart Expertchart-expert
Chat Help – Click to Chat Button & Formchat-help
Classified Listing – AI-Powered Classified ads & Business Directory Pluginclassified-listing
Comment Edit Core – Simple Comment Editingsimple-comment-editing
Contact Form Emailcontact-form-to-email
Contest Gallery – Upload, Vote & Sell with PayPal and Stripecontest-gallery
Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeedquicq
Coon Google Mapscoon-google-maps
Crypto Toolcrypto
CTL Arcade Litectl-arcade-lite
Data Tables Generator by Supsysticdata-tables-generator-by-supsystic
db-accessdb-access
Document Pro Elementor – Documentation & Knowledge Basedocument-pro-elementor
donationdonation
Double the Donation – A workplace giving tooldouble-the-donation
Easy Email Subscriptionemail-subscription-with-secure-captcha
Easy WordPress Funnel Builder To Collect Leads And Increase Sales – WPFunnelswpfunnels
EasyCommerce – AI-Powered Ecommerce To Sell Physical & Digital Productseasycommerce
Elastic Theme Editorelastic-theme-editor
Eventbee Ticketing Widgeteventbee-ticketing-widget
Featured Imagefeatured-image
Find Unused Imagesfind-unused-images
Five9 Live Chatfive9
Fleet Managerfleet
Flickr Showwp-flickrshow
Gallery Plugin for WordPress – Envira Photo Galleryenvira-gallery-lite
GeoDirectory – WP Business Directory Plugin and Classified Listings Directorygeodirectory
Geopostgeopost
GitHub Gist Shortcode Plugingithub-gist-shortcode
Holiday class post calendarholiday-class-post-calendar
Hydra Booking — Appointment Scheduling & Booking Calendarhydra-booking
Image Gallery – Photo Grid & Video Gallerymodula-best-grid-gallery
Import any XML, CSV or Excel File to WordPresswp-all-import
Include Fussball.de Widgetsinclude-fussball-de-widgets
Jeba Cute forkitjeba-cute-forkit
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzeslifterlms
Live Photos on WordPresslive-photos
Magazine Companionbnm-blocks
MembershipWorks – Membership, Events & Directorymemberfindme
Mementor Coremementor-core
My Geo Posts Freemy-geo-posts-free
Ninja Countdown | Fastest Countdown Builderninja-countdown
Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPressnonaki-email-template-customizer
Online Booking & Scheduling Calendar for WordPress by vcitameeting-scheduler-by-vcita
Page Builder: Pagelayer – Drag and Drop website builderpagelayer
Payment Plugins Braintree For WooCommercewoo-payment-gateway
Paypal Donation Shortcodepaypal-donation-shortcode
PDF Builder for WooCommerce. Create invoices,packing slips and morewoo-pdf-invoice-builder
Poll Maker – Versus Polls, Anonymous Polls, Image Pollspoll-maker
Precise Columnsprecise-columns
Preload Current Imagespreload-current-images
Private Google Calendarsprivate-google-calendars
Progress Bar Blocks for Gutenbergprogressmatify-blocks
Qi Blocksqi-blocks
RandomQuotrrandomquotr
Save as PDF Buttonsave-as-pdf
School Management System – WPSchoolPresswpschoolpress
Select Coreselect-core
Seriously Simple Podcastingseriously-simple-podcasting
Share to Google Classroomshare-to-google-classroom
Shopkeeper Extendershopkeeper-extender
Simple Donatesimple-donate
Skip to Timestampskip-to-timestamp
SKT Skill Barskt-skill-bar
Slippy Slider – Responsive Touch Navigation Sliderslippy-slider-responsive-touch-navigation-slider
SNORDIAN’s H5PxAPIkatchuh5pxapikatchu
Specific Content For Mobile – Customize the mobile version without redirectionsspecific-content-for-mobile
Squirrels Auto Inventorysquirrels-auto-inventory
Stock Management for WooCommerce by Shelf Plannershelf-planner
Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimatorstylish-cost-calculator
SureForms – Contact Form, Payment Form & Other Custom Form Buildersureforms
Survey Makersurvey-maker
The Total Book Projectthe-total-book-project
Theater for WordPresstheatre
Thumbnail Slider With Lightboxwp-responsive-slider-with-lightbox
Timetable and Event Schedule by MotoPressmp-timetable
TNC Toolbox: Web Performancetnc-toolbox
Twitter Feedot-twitter-feed
Ungapped Widgetsungapped-widgets
USB Qr Code Scanner For Woocommerceusb-qr-code-scanner-for-woocommerce
Welcart e-Commerceusc-e-shop
Wishlist and Save for later for Woocommerceaco-wishlist-for-woocommerce
Wislywisly
Woffice Corewoffice-core
Woocommerce – Products By Custom Taxwoocommerce-products-by-custom-tax
WordPress Content Flipperwp-flipper
WP BBCodewp-bbcode
WP Bootstrap Tabswp-bootstrap-tabs
WP Count Down Timerwp-count-down-timer
WP Custom Admin Login Page Logowp-custom-login-page-logo
WP Google Review Sliderwp-google-places-review-slider
WP Import – Ultimate CSV XML Importer for WordPresswp-ultimate-csv-importer
WP Plugin Manager – Deactivate plugins per pagewp-plugin-manager
WP YouTube Lytewp-youtube-lyte
WP-Iconicswp-iconics
WP-OAuthwp-oauth
WP-Wallawp-walla
WP移行専用プラグイン for CPIcpi-wp-migration
YSlideryslider

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *