Weekly WP Vulnerabilities: 6/30/25 – 7/6/25

via Wordfence Email

Last week, there were 127 vulnerabilities disclosed in 120 WordPress Plugins and 16 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-858 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched56
Unpatched71

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity1
Medium Severity64
High Severity50
Critical Severity12

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)35
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)21
Missing Authorization15
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)13
Unrestricted Upload of File with Dangerous Type9
Cross-Site Request Forgery (CSRF)7
Deserialization of Untrusted Data5
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)4
Server-Side Request Forgery (SSRF)4
Improper Control of Generation of Code (‘Code Injection’)3
Incorrect Privilege Assignment3
Authorization Bypass Through User-Controlled Key1
Exposure of Sensitive Information to an Unauthorized Actor1
External Control of File Name or Path1
Improper Access Control1
Improper Authentication1
Improper Authorization1
Improper Privilege Management1
URL Redirection to Untrusted Site (‘Open Redirect’)1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Amely – Fashion Shop WordPress Theme for WooCommerceamely
Blogbyteblogbyte
Blogmineblogmine
Blogpriseblogprise
Blogtyblogty
Blogvyblogvy
CityGov – City Government & Municipal WordPress Themecitygov
Constructorconstructor
Domnoo – Pizza & Restaurant WordPress Themedomnoo
DWT – Directory & Listing WordPress Themedwt-listing
Elessi – WooCommerce AJAX WordPress Theme – RTL supportelessi-theme
GreenMart – Organic & Food WooCommerce WordPress Themegreenmart
Homeyhomey
Katerio – Magazine & Blog WordPress Themekaterio
LMS – Education WordPress Themelms
MagOnemagone
Magtymagty
Magwaysmagways
Magzemagze
MBStore – Digital WooCommerce WordPress Themembstore
Nuss – Hotel Booking WordPressnuss
Pressroom – News Magazine WordPress Themepressroom
PrintXtore – Printing Services & Design Online WordPress WooCommerce Themebw-printxtore
Puca – Optimized Mobile WooCommerce Themepuca
RealtyElite – Real Estate & Property Sales WordPress Themerealtyelite
Red Art | Artist Portfolio WordPressredart
Sala – Startup & SaaS WordPress Themesala
Samex – Clean, Minimal Shop WooCommerce WordPress Themesamex
Seven Stars – Modern Responsive MultiPurpose Themesevenstars
SNS Vicky – Cosmetic WooCommerce WordPress Themesnsvicky
Sofass – Elementor WooCommerce WordPress Themesofass
Zenny – Jewelry, Watches & Glasses Elementor WooCommerce WordPress Themebw-zenny
Zitazita
Software NameSoftware Slug
Fitness Parkfitness-park
Hello FSE Bloghello-fse-blog
HYDRO – One Page Portfolio WordPress Themehydro
OceanWPoceanwp
Spark Multipurposespark-multipurpose

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
(Simply) Guest Author Nameguest-author-name
Ads Pro Plugin – Multi-Purpose WordPress Advertising Managerap-plugin-scripteo
AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4oaibuddy-openai-chatgpt
AI Engineai-engine
All-in-One Addons for Elementor – WidgetKitwidgetkit-for-elementor
Allmartallmart-core
Amazon Products to WooCommerceimport-products-to-wc
Auto Thickboxauto-thickbox
Aviation Weather from NOAAaviation-weather-from-noaa
Awesome Galleryawesome-gallery
Awesome Wp Image Galleryawesome-wp-image-gallery
Backwpbackwp
Beautiful Cookie Consent Bannerbeautiful-and-responsive-cookie-consent
BlossomThemes Social Feedblossomthemes-instagram-feed
Bold Page Builderbold-page-builder
Booking Calendar Contact Formbooking-calendar-contact-form
Booking calendar, Appointment Booking Systembooking-calendar
Booking X – Appointment and Reservation Availability Calendarbooking-x
bSecure – Your Universal Checkoutbsecure
Bulk Featured Imagebulk-featured-image
Card flip image slideshowcard-flip-image-slideshow
Carousel Slidercarousel-slider
Case Theme Usercase-theme-user
CF7 7 Mailchimp Add-onCF7-mailchimp-addon
Chatra Live Chat + ChatBot + Cart Saverchatra-live-chat
Click & Pledge Connectclick-pledge-connect
CMSMasters Content Composercmsmasters-content-composer
Contact Form 7 Database Addon – CFDB7contact-form-cfdb7
Contact Form 7 reCAPTCHAcontact-form-7-recaptcha
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builderbit-form
Contact Form by Everest Forms – Simple Contact Form to Advanced Contact Form, Quiz, Survey, & Custom Contact Form Builder for WordPresseverest-forms
Contact Us Page – Contact Peoplecontact-us-page-contact-people
Cool fade popupcool-fade-popup
CouponXxL Custom Post Typescouponxxl-cpt
CSS3 Vertical Web Pricing Tablescss3_vertical_web_pricing_tables
Custom Login And Signup Widgetcustom-login-and-signup-widget
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer3d-flipbook-dflip-lite
Divi Builderdivi-builder
Divi Torque – Plugin for Divi Theme and Builderaddons-for-divi
DocCheck Logindoccheck-login
Download Manager and Payment Form WordPress Plugin – WP SmartPaysmartpay
Download Plugindownload-plugin
Drag and Drop Multiple File Upload (Pro) – WooCommercedrag-and-drop-file-uploads-wc-pro
Easy 3D Viewerwoo-3d-viewer
Easy Elements Hidereasy-elements-hider
Easy Image Galleryeasy-image-gallery
Easy restaurant menu managereasy-pdf-restaurant-menu-upload
Easy Stripe – Tips, Payments, and Donationseasy-stripe
Element Pack Elementor Addons and Templatesbdthemes-element-pack-lite
Email Address Security by WebEmailProtectorwebemailprotector
Essential Addons for Elementor – Popular Elementor Templates & Widgetsessential-addons-for-elementor-lite
Event Listeventlist
EventON (Pro) – WordPress Virtual Event Calendar PlugineventON
fluXtore Funnel Builder for WordPress – Earn More with Highly Converting Sales Funnelsfluxtore
Forminator Forms – Contact Form, Payment Form & Custom Form Builderforminator
Frontend File Manager Pluginnmedia-user-file-uploader
FW Gallery – Photo, video, audio media presentation and management system with players and slideshowfw-gallery
Gallery Widgetgallery-widget
GoZen Formsgozen-forms
Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocksadvanced-gutenberg
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editorgutentor
Happy Addons for Elementorhappy-elementor-addons
iFrame Images Gallerywp-iframe-images-gallery
JKDEVKITjkdevkit
Lead Form Data Collection to CRMwp-leads-builder-any-crm
Leykaleyka
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzeslifterlms
LMSACE Connect – WooCommerce Moodle™ LMS Integrationlmsace-connect
Magic Buttons for Elementormagic-buttons-for-elementor
Masteriyo LMS PROlearning-management-system-pro
Melapress File Monitorwebsite-file-changes-monitor
MF Plus WPMLmf-plus-wpml
Migration, Backup, Staging – WPvivid Backup & Migrationwpvivid-backuprestore
MobiLoud – WordPress Mobile Apps – Convert your WordPress Website to Native Mobile Appsmobiloud-mobile-app-plugin
NGG Smart Image Searchngg-smart-image-search
Opal Estate Pro – Property Management and Submissionopal-estate-pro
OwnerRezownerrez
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restrictionpaid-member-subscriptions
PayMaster for WooCommercewoocommerce-paymaster-gateway-019
Paytiko for WooCommercepaytiko
PeepSo Core: Groupspeepso-groups
Photo Gallery, Images, Slider in Rbs Image Galleryrobo-gallery
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallerynextgen-gallery
Pixelating image slideshow gallerypixelating-image-slideshow-gallery
Portfolio for Elementor & Image Gallery | PowerFolioportfolio-elementor
Posts Slider Shortcodeposts-slider-shortcode
Premium Addons for Elementorpremium-addons-for-elementor
Printcart Web to Print Product Designer for WooCommerceprintcart-integration
PrivateContent – Mail Actionsprivate-content-mail-actions
ProcessingJS for WordPressprocessingjs-for-wp
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!radio-station
RD Contactord-wapp
Service Finder Bookingssf-booking
Smart Docssmart-docs
Soumettre.frsoumettre-fr
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Buildersupreme-modules-for-divi
Testimonials Showcasetestimonials-showcase
Trust Payments Gateway for WooCommerce (JavaScript Library)trust-payments-gateway-3ds2
Ultra Addons for Contact Form 7ultimate-addons-for-contact-form-7
Uncode Coreuncode-core
URL Shortener Plugin For WordPressexact-links
Video Gallery Block – Display your videos as a gallery in a professional wayvideo-gallery-block
Video List Managervideo-list-manager
VikRentCar Car Rental Management Systemvikrentcar
WC Pickup Storewc-pickup-store
WooCommerce Product Multi-ActionWoo-product-multiaction
WooCommerce Shop Page Builderdzs-wootable
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogggroundhogg
WP Compress – Instant Performance & Speed Optimizationwp-compress-image-optimizer
WP fancyboxwp-fancybox
WP Firebase Push Notificationwp-push-notification-firebase
WP Front-end login and registerwp-front-end-login-and-register
WP Human Resource Managementhrm
WP Shortcodes Plugin — Shortcodes Ultimateshortcodes-ultimate
WP Travel Gutenberg Blockswp-travel-blocks
WP Video Lightboxwp-video-lightbox
WP Visitor Statistics (Real Time Traffic)wp-stats-manager
WPQuizwpquiz
yContributorsycontributors
YouTube Embed, Playlist and Popup by WpDevArtyoutube-video-player

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *