Weekly WP Vulnerabilities: 7/14/25 – 7/20/25

via Wordfence Email

Last week, there were 140 vulnerabilities disclosed in 120 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 41 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-859 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched106
Unpatched34

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity112
High Severity15
Critical Severity13

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)55
Missing Authorization24
Cross-Site Request Forgery (CSRF)17
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)11
Exposure of Sensitive Information to an Unauthorized Actor9
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)6
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)5
Deserialization of Untrusted Data4
Unrestricted Upload of File with Dangerous Type3
Authentication Bypass Using an Alternate Path or Channel1
Authorization Bypass Through User-Controlled Key1
External Control of File Name or Path1
Improper Control of Generation of Code (‘Code Injection’)1
Improper Privilege Management1
Server-Side Request Forgery (SSRF)1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Alone – Charity Multipurpose Non-profit WordPress Themealone
GymBase Theme Classesgymbase_classes
Hestiahestia
Houzezhouzez
Visual Art | Gallery WordPress Themevisual-arts

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
aapanel WP Toolkitaapanel-wp-toolkit
Affiliate Reviewsaffiliate-reviews
Alike – WordPress Custom Post Comparisonalike
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)azon-addon-js-composer
Animator – Scroll Triggered Animationsscroll-triggered-animations
AntiSpam for Contact Form 7cf7-antispam
Apollo – Sticky Full Width HTML5 Audio Playerlbg-audio5-html5-shoutcast-sticky
Appointment Booking & Scheduling Plugin — Webba Booking Calendarwebba-booking-lite
Attachment Managerattachment-manager
Avada (Fusion) Builderfusion-builder
Avishi WP PayPal Payment Buttonavishi-wp-paypal-payment-button
B1.ltb1-accounting
Bears Backupbears-backup
Block Editor Gallery Sliderblock-editor-gallery-slider
Bold Page Builderbold-page-builder
Brandfolder – Digital Asset Management Simplified.brandfolder
Chatbox Managerwa-chatbox-manager
Cloud SAML SSO – Single Sign On Logincloud-sso-single-sign-on
CM Pop-Up – Create engaging popups to capture attention and boost interactioncm-pop-up-banners
Companion Auto Updatecompanion-auto-update
Copymatic – AI Content Writer & Generatorcopymatic
Cost Calculatorql-cost-calculator
Counter live visitors for WooCommercecounter-visitor-for-woocommerce
Coupon Affiliates – Affiliate Plugin for WooCommercewoo-coupon-usage
Crowdfunding for WooCommercecrowdfunding-for-woocommerce
Custom API for WPcustom-api-for-wp
DB Backupdb-backup
Easy Elementor Addonseasy-elementor-addons
ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic)elex-bulk-edit-products-prices-attributes-for-woocommerce-basic
EPay.bg Paymentsepaybg-payments
FG Drupal to WordPressfg-drupal-to-wp
FluentSnippets – The High-Performance file based Custom Code Snippets Plugineasy-code-manager
FoodMenu – WP Creative Restaurant Menu Showcase WooCommercedzs-restaurantmenu
Formalityformality
Forminator Forms – Contact Form, Payment Form & Custom Form Builderforminator
Ghost Kit – Page Builder Blocks, Motion Effects & Extensionsghostkit
GSheetConnector for WCwc-gsheetconnector
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editorgutentor
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder.ht-contactform
HTML5 Radio Player – WPBakery Page Builder Addonlbg_radio_player_addon_visual_composer
IDonatePro – Blood Donation, Request And Donor Management WordPress Pluginidonate-pro
Image Wallimage-wall
Import CDN-Remote Imagesimport-cdn-remote-images
Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Formsintegration-for-contact-form-7-and-google-sheets
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Formsintegration-for-contact-form-7-and-pipedrive
JetBlocks for Elementorjet-blocks
JetElementsjet-elements
JetEnginejet-engine
JetFormBuilder — Dynamic Blocks Form Builderjetformbuilder
JetMenujet-menu
JetPopupjet-popup
JetSearchjet-search
JetSmartFiltersjet-smart-filters
JetTabsjet-tabs
JetTricksjet-tricks
JetWooBuilderjet-woo-builder
Knowledge Baseknowledgebase
lbg-audio4-html5-shoutcastlbg-audio4-html5-shoutcast
LightBox Block – Gutenberg block for creating fully functional lightboxlightbox-block
Listly: Listicles For WordPresslistly
Live Stream Badgerlive-stream-badger
LoginPress Prologinpress-pro
Madara – Coremadara-core
Malcure Malware Scanner — #1 Toolset for Malware Removalwp-malware-removal
Map My Locationsmap-my-locations
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animationsmaster-addons
MasterStudy LMS Promasterstudy-lms-learning-management-system-pro
Maya Business Pluginpaymaya-checkout-for-woocommerce
Media Library Assistantmedia-library-assistant
Mediabay – WordPress Media Library Foldersmediabay
MORKVA Vchasno Kasa Integrationmrkv-vchasno-kasa
Multimedia Playlist Slider Addon for WPBakery Page Builderlbg_vp_youtube_vimeo_addon_visual_composer
News Kit Elementor Addonsnews-kit-elementor-addons
Newslettersnewsletters-lite
Partnerský systém Martinusmartinus-partnersky-system
Pinterest Automaticwp-pinterest-automatic
Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteshipbiteship
ProfileGrid – User Profiles, Groups and Communitiesprofilegrid-user-profiles-groups-and-communities
Real Estate Property 2025 Create Your Own Fields and Search Barreal-estate-right-now
Residential Address Detectionresidential-address-detection
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templatesresponsive-addons-for-elementor
Restaurant Menu and Food Orderingmp-restaurant-menu
Restrict File Accessrestrict-file-access
Revolution Video Player With Bottom Playlist WordPress Plugin – YouTube/Vimeo/Self-Hosted Supportrevolution_video_player
Ruven Themes: Shortcodesruven-themes-shortcodes
School Management System for WordPressschool-management
SHOUT – HTML5 Radio Player With Ads – ShoutCast and IceCast Supportlbg-audio8-html5-radio-ads
Simple Link Directory Proqc-simple-link-directory
SMTP for Amazon SES – YaySMTPsmtp-amazon-ses
SMTP for SendGrid – YaySMTPsmtp-sendgrid
SMTP for Sendinblue – YaySMTPsmtp-sendinblue
SMTP2GO for WordPress – Email Made Easysmtp2go
Stop and Block bots plugin Anti botsantibots
Strong Testimonialsstrong-testimonials
Temporarily Hidden Contenttemporarily-hidden-content
Terms descriptionsterms-descriptions
Testimonial Post typetestimonial-post-type
The Plus Addons for Elementor Page Builder Protheplus_elementor_addon
Theme Builder For Elementortheme-builder-for-elementor
ThemeREX Addonstrx_addons
Ultimate WP Mailultimate-wp-mail
Universal Video Player – Addon for WPBakery Page Builderlbg-universal-video-player-addon-visual-composer
Universal Video Player – Addon for WPBakery Page Builderlbg_universal_video_player_addon_visual_composer
URL Shortener Plugin For WordPressexact-links
Useful Tab Block – Responsive & AMP-Compatibleuseful-tab-block-responsive-amp-compatible
Vertical scroll image slideshow galleryvertical-scroll-image-slideshow-gallery
Videopackvideo-embed-thumbnail-generator
Wallet System for WooCommercewallet-system-for-woocommerce
Welcart e-Commerceusc-e-shop
Widget for Google Reviewsbusiness-reviews-wp
WooCommerce Refund And Exchange with RMA – Warranty Management, Refund Policy, Manage User Walletwoocommerce-refund-and-exchange
WooCommerce Shop Page Builderdzs-wootable
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)delicious-recipes
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommercewp-event-manager
WP Post Hidewp-post-hide
WP Shortcodes Plugin — Shortcodes Ultimateshortcodes-ultimate
WPAdverts – Classifieds Pluginwpadverts
YayExtra – WooCommerce Extra Product Optionsyayextra
Youtube Vimeo Video Player and Slider WP Pluginvideo_player_youtube_vimeo
Zuppler Online Orderingzuppler-online-ordering

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *