Weekly WP Vulnerabilities: 6/9/25 – 6/15/25

via Wordfence Email

Last week, there were 137 vulnerabilities disclosed in 101 WordPress Plugins and 32 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 52 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • PayU CommercePro Plugin <= 3.8.5 – Authentication Bypass
  • WAF-RULE-845 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-846 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-847 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-848 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-852 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched74
Unpatched63

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity72
High Severity30
Critical Severity35

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)42
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)29
Cross-Site Request Forgery (CSRF)12
Missing Authorization11
Unrestricted Upload of File with Dangerous Type11
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)10
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)6
Deserialization of Untrusted Data5
Improper Privilege Management4
Absolute Path Traversal1
Authentication Bypass Using an Alternate Path or Channel1
Exposure of Sensitive Information to an Unauthorized Actor1
Improper Control of Generation of Code (‘Code Injection’)1
Incorrect Authorization1
Server-Side Request Forgery (SSRF)1
URL Redirection to Untrusted Site (‘Open Redirect’)1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Aora – Home & Lifestyle Elementor WooCommerce Themeaora
Besa – Elementor Marketplace WooCommerce Themebesa
BodyCenter – Gym, Fitness WooCommerce WordPress Themebodycenter
CozyStay – Hotel Booking WordPress Themecozystay
CraftXtore – Handmade, Ceramics and Pottery Shop WooCommerce Themebw-craftxtore
Diza – Pharmacy Store Elementor WooCommerce Themediza
edminedmin
Evon – Bag Store WooCommerce WordPress Themesnsevon
Fana – Fashion Shop WordPress Themefana
Fitrush – Fitness and Health Supplements WordPress Themebw-fitrush
Flozen – WooCommerce AJAX WordPress RTL Themeflozen-theme
GiftXtore – Luxury Jewelry & Gift Store Elementor WooCommerce WordPress Themebw-giftxtore
GrandPrix – Motorcycle WordPress Themegrandprix
Hara – Beauty and Cosmetics Shop WooCommerce Themehara
Inset – Digital Agency & IT Services WordPress Themeinset
Lasa – Creative Minimal WooCommerce WordPress Themelasa
Maia – Jewelry Shop WordPress Thememaia
MediClinic – Medical Healthcare WordPress Thememediclinic
Nika – Medical Elementor WooCommerce Themenika
Nitan – Fashion WooCommerce WordPress Themesnsnitan
Petito – Animals and Pets Store WooCommerce Themebw-petito
Photographyphotography
RH – Real Estate WordPress Themerealhomes
Ruza – Beauty Cosmetics Shop WordPress Themeruza
Sapa – Product Landing Page WooCommerce Themesapa
Simen – MultiPurpose WooCommerce WordPress Themesnssimen
SNS Anton – Furniture WooCommerce WordPress Themesnsanton
Spare – Ultimate MultiPurpose LESS Themespare
TinySalt – Personal Food Blog WordPress Themetinysalt
Valen – Sport, Fashion WooCommerce WordPress Themevalen
Zagg – Electronics & Accessories WooCommerce WordPress Themebw-zagg
Zota – Elementor Multi-Purpose WooCommerce Themezota

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Abandoned Cart Pro for WooCommercewoocommerce-abandon-cart-pro
ACF Onyx Pollacf-onyx-poll
Advanced Sermonsadvanced-sermons
Advanced Settings 3advanced-settings
Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Galleryaeroscroll-gallery
AFS Analyticsaddfreestats
AI Image Lab – Free AI Image Generatorai-image-generator-lab
Appointment Booking Calendar — Simply Schedule Appointments Booking Pluginsimply-schedule-appointments
Arconix FAQarconix-faq
Arconix Shortcodesarconix-shortcodes
Auto Attachmentsauto-attachments
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPressautomatorwp
Axle Demo Importeraxle-demo-importer
Bunny’s Print CSSbunnys-print-css
CLEVER – HTML5 Radio Player With History – Shoutcast and Icecast – WordPress Pluginlbg-audio11-html5-shoutcast_history
Click to Chat – HoliThemesclick-to-chat-for-whatsapp
Color Palettecolor-palette
Contact Us Page – Contact Peoplecontact-us-page-contact-people
CubeWP Forms – All-in-One Form Buildercubewp-forms
CubeWP – All-in-One Dynamic Content Frameworkcubewp-framework
Digital Marketing and Agency Templates Addons for Elementordigital-marketing-agency-templates-for-elementor
DIOT SCADA with MQTTecava-diot-scada
Easy Flashcardseasy-flashcards
Ebook Storeebook-store
eForm – WordPress Form Builderwp-fsqm-pro
Elementor Website Builder Proelementor-pro
Elite Video Playerelite-video-player
File Manager Pro – Filesterfilester
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommercewp-marketing-automations
FW Food Menu – Responsive food menu with ordering & delivery solutionsfw-food-menu
FW Gallery – Photo, video, audio media presentation and management system with players and slideshowfw-gallery
Game Review Blockgame-review-block
If-So Dynamic Content Personalizationif-so
Image Resizer On The Flyimage-resizer-on-the-fly
IndieBlocksindieblocks
IRM Newsroomirm-newsroom
Kama Click Counterkama-clic-counter
kk Youtube Videokk-youtube-video
Link Shieldlink-shield
Majestic Support – The Leading-Edge Help Desk & Customer Support Pluginmajestic-support
Malcure Malware Scanner — #1 Toolset for WordPress Malware Removalwp-malware-removal
MapSVGmapsvg
Meks Flexible Shortcodesmeks-flexible-shortcodes
Membership For WooCommercemembership-for-woocommerce
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.mycred
Nasa Corenasa-core
One-Loginone-login
Ovatheme Events Managerova-events-manager
PostaPanduripostapanduri
Premium Addons for Elementorpremium-addons-for-elementor
ProfileGrid – User Profiles, Groups and Communitiesprofilegrid-user-profiles-groups-and-communities
ReFormer – Multichannel Contact Form for Elementorreformer-elementor
Responsive Blocks – WordPress Gutenberg Blocksresponsive-block-editor-addons
Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme.responsive-add-ons
REST API | Custom API Generator For Cross Platform And Import Export In WPimport-export-with-custom-rest-api
Restrict File Accessrestrict-file-access
School Management System for WordPressschool-management
Simple Newsletter Plugin – Noptinnewsletter-optin-box
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Sliderml-slider
Slim SEO – Fast & Automated WordPress SEO Pluginslim-seo
Smart Notification WordPress Plugin. Web & Mobile Push, FB Messenger, FB Notifications & Newsletter.smio-push-notification
Smash Balloon Social Post Feed – Simple Social Feeds for WordPresscustom-facebook-feed
StreamWeasels Kick Integrationstreamweasels-kick-integration
Telegram for WPtelegram-for-wp
The Events Calendarthe-events-calendar
TicketBAI Facturas para WooCommercewp-ticketbai
Track, Analyze & Optimize by WP Taowp-tao
Traffic Monitortraffic-monitor
Ultimate Blocks – WordPress Blocks Pluginultimate-blocks
Ultimate Reviewsultimate-reviews
UserPro – Community and User Profile WordPress Pluginuserpro
Widget Logicwidget-logic
WidgetKit Prowidgetkit-pro
Woocommerce Partial Shipmentwc-partial-shipment
WordPress Automatic Pluginwp-automatic
WordPress Single Sign-On (SSO) – Multisite All-Inclusiveminiorange-oauth-oidc-single-sign-on
WordPress Single Sign-On (SSO) – Multisite Enterpriseminiorange-oauth-oidc-single-sign-on
WordPress Single Sign-On (SSO) – Multisite Premiumminiorange-oauth-oidc-single-sign-on
WordPress Single Sign-On (SSO) – Single Site All-Inclusiveminiorange-oauth-oidc-single-sign-on
WordPress Single Sign-On (SSO) – Single Site Enterpriseminiorange-oauth-oidc-single-sign-on
WordPress Single Sign-On (SSO) – Single Site Premiumminiorange-oauth-oidc-single-sign-on
WordPress Single Sign-On (SSO) – Single Site Standardminiorange-oauth-oidc-single-sign-on
Workreapworkreap
WP Employee Attendance Systemwp-employee-attendance-system
WP Job Portal – A Complete Recruitment System for Company or Job Board websitewp-job-portal
WP Sliding Login/Dashboard Panelwp-sliding-logindashboard-panel
WP Travel Engine – Tour Booking Plugin – Tour Operator Softwarewp-travel-engine
WP URL Shortenerwp-url-shortener
WP Views Counterwpecounter
WP VR – 360 Panorama and Free Virtual Tour Builder For WordPresswpvr
WP-DownloadManagerwp-downloadmanager
WP2HTMLwp2html
WPAdverts – Classifieds Pluginwpadverts
WPCRM – CRM for Contact form CF7 & WooCommercewpcrm
WPGYM – WordPress Gym Management Systemgym-management
Xagio SEO – AI Powered SEOxagio-seo
XiSearch barxisearch-bar
YITH WooCommerce Wishlistyith-woocommerce-wishlist
Yougler Blogger Profile Pageyougler-blogger-profile-page
Zen Sticky Socialzen-social-sticky
Zotpresszotpress

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *