Weekly WP Vulnerabilities: 7/28/25 – 8/03/25

via Wordfence Email

Last week, there were 140 vulnerabilities disclosed in 120 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 43 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • None

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched88
Unpatched20

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity75
High Severity26
Critical Severity7

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)43
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)12
Missing Authorization12
Cross-Site Request Forgery (CSRF)9
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)5
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)4
Deserialization of Untrusted Data3
Exposure of Sensitive Information to an Unauthorized Actor3
Unrestricted Upload of File with Dangerous Type3
Authorization Bypass Through User-Controlled Key2
Improper Privilege Management2
Incorrect Privilege Assignment2
Absolute Path Traversal1
Authentication Bypass Using an Alternate Path or Channel1
Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’)1
Improper Authorization1
Improper Control of Generation of Code (‘Code Injection’)1
Incorrect Authorization1
Server-Side Request Forgery (SSRF)1
URL Redirection to Untrusted Site (‘Open Redirect’)1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Appzendappzend
Blogger Buzzblogger-buzz
Bricksbricks
Cook&Meal – Food Blog & Recipe WordPress Themecookandmeal
Druco – Elementor WooCommerce WordPress Themedruco
Exertio – Freelance Marketplace WordPress Themeexertio
MediCenter – Health Medical Clinic WordPress Thememedicenter
News Magazine Xnews-magazine-x
UpStore – Multi-Purpose WooCommerce WordPress Themeupstore

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
360 Photo Spheres360-sphere-images
Advanced Google Universal Analyticsadvanced-google-universal-analytics
AI Engineai-engine
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easieraio-time-clock-lite
Appointment Booking Plugin for WordPress | Efficient Booking, Calendar & Client Scheduling – Bookifybookify
BeeTeam368 Extensionsbeeteam368-extensions
BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScriptsearchpro
BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Securitybitfire
BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Neededblockspare
Bonanza – WooCommerce Free Gifts Litebonanza-woocommerce-free-gifts-lite
Brave Conversion Engine (PRO)bravepopup-pro
Brizy – Page Builderbrizy
BuddyPress XProfile Custom Image Fieldbuddypress-xprofile-image-field
Button Block – Design Stylish, Interactive, and Multi-Functional Buttonsbutton-block
Chartify – WordPress Chart Pluginchart-builder
Classified Listing – AI-Powered Classified ads & Business Directory Pluginclassified-listing
Connector for Gravity Forms and Google Sheetswp-gravity-forms-spreadsheets
Content Eggcontent-egg
Custom API for WPcustom-api-for-wp
Custom Word Cloudcustom-word-cloud
Customer Reviews for WooCommercecustomer-reviews-woocommerce
DELUCKS SEOdelucks-seo
Easy Elementor Addonseasy-elementor-addons
Ebook Storeebook-store
Elementor Website Builder – More Than Just a Page Builderelementor
Event Booking Manager for WooCommerce – WpEventlymage-eventpress
Fan Pagefan-page
File Manager for Google Drive – Integrate Google Drive with WordPressintegrate-google-drive
GiveWP – Donation Plugin and Fundraising Platformgive
Google Map Targetinggmap-targeting
Graphina – Elementor Charts and Graphsgraphina-elementor-charts-and-graphs
Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocksadvanced-gutenberg
HT Mega – Absolute Addons For Elementorht-mega-for-elementor
Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookingshydra-booking
IDonate – Blood Donation, Request And Donor Management Systemidonate
Image Gallerybee-quick-gallery
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Formscf7-constant-contact
JetEnginejet-engine
JetTabsjet-tabs
Leads & Sales Funnel Builder For WordPress & WooCommerce, Specialized For Digital Creators – WPFunnelswpfunnels
Magic Edge – Litemagic-edge-lite-image-background-remover
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )magical-addons-for-elementor
Magical Posts Display – Elementor Advanced Posts widgetsmagical-posts-display
Masteriyo LMS – Online Course Builder for eLearning, LMS & Educationlearning-management-system
Medical Addon for Elementormedical-addon-for-elementor
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementormetform
Mmm Unity Loadermmm-unity-loader
Motors – Car Dealership & Classified Listings Pluginmotors-car-dealership-classified-listings
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.mycred
Newslettersnewsletters-lite
NinjaScanner – Virus & Malware scanninjascanner
Ocean Social Sharingocean-social-sharing
oikoik
Online Booking & Scheduling Calendar for WordPress by vcitameeting-scheduler-by-vcita
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restrictionpaid-member-subscriptions
Photo Engine (Media Organizer & Lightroom)wplr-sync
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAIcontest-gallery
PressForwardpressforward
Product Configurator for WooCommerceproduct-configurator-for-woocommerce
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & Moreproduct-xml-feeds-for-woocommerce
Qi Addons For Elementorqi-addons-for-elementor
Realtyna Organic IDX plugin + WPL Real Estatereal-estate-listing-realtyna-wpl
RT-Theme 18 Responsive WordPress Themert18-extensions
SEO Metricsseo-metrics-helper
Service Finder Bookingssf-booking
Service Finder SMS Systemaone-sms
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimizationshortpixel-adaptive-images
Simple File Listsimple-file-list
Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates)sina-extension-for-elementor
Sky Addons – Elementor Addons with Widgets & Templatessky-elementor-addons
Smart Slider 3smart-slider-3
StoreKeeper for WooCommercestorekeeper-for-woocommerce
Stratum – Elementor Widgetsstratum
StreamWeasels Kick Integrationstreamweasels-kick-integration
StreamWeasels Twitch Integrationstreamweasels-twitch-integration
StreamWeasels YouTube Integrationstreamweasels-youtube-integration
Super Store Findersuperstorefinder-wp
Supermalinksupermalink
SureDashsuredash
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommercethe-plus-addons-for-elementor-page-builder
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder)header-footer-elementor
Woffice Corewoffice-core
woozone-contextualwoozone-contextual
WordPress Booking Plugin – TheBookingthebooking
WordPress Image Gallery Plugin – WordPress Photo Gallerycubeportfolio
WP CTAeasy-sticky-sidebar
WP LOL Rotationleague-of-legends-rotation
WP Modal Popup with Cookie Integrationwp-modal-popup-with-cookie-integration
WP REST Cachewp-rest-cache
YITH WooCommerce Popupyith-woocommerce-popup
YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Pluginyouram-youtube-embed

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *