Weekly WP Vulnerabilities: 7/7/25 – 7/13/25

via Wordfence Email

Last week, there were 88 vulnerabilities disclosed in 61 WordPress Plugins and 13 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 41 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • None

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched49
Unpatched39

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity55
High Severity25
Critical Severity8

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)29
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)15
Missing Authorization12
Deserialization of Untrusted Data8
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)4
Unrestricted Upload of File with Dangerous Type4
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)3
Exposure of Sensitive Information to an Unauthorized Actor2
Improper Control of Generation of Code (‘Code Injection’)2
Improper Privilege Management2
Authentication Bypass Using an Alternate Path or Channel1
Authorization Bypass Through User-Controlled Key1
External Control of File Name or Path1
Improper Neutralization of Formula Elements in a CSV File1
Server-Side Request Forgery (SSRF)1
Unverified Password Change1
Use of Hard-coded Credentials1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
electricianelectrician
fwdevpfwdevp
Hillter – Responsive Hotel Booking for WordPresshillter
Invico – WordPress Consulting Business Themeinvico
ListingEasy – Directory Listing WordPress Themelistingeasy
Noisanoisa
Nokri – Job Board WordPress Themenokri
Nuss – Hotel Booking WordPressnuss
Ofiz – WordPress Business Consulting Themeofiz
Sala – Startup & SaaS WordPress Themesala
Travel Booking WordPress Themetraveler
Woodmartwoodmart
Yogi – Health Beauty & Yoga WordPress Themeyogi

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
AI Engineai-engine
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)azon-addon-js-composer
BeeTeam368 Extensionsbeeteam368-extensions
Broken Link Notifierbroken-link-notifier
Contact Form 7 Editor Buttoncf7-editor-button
CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Onlinecoschool
CSS3 Compare Pricing Tables for WordPresscss3_web_pricing_tables_grids
Dot html,php,xml etc pagesdot-htmlphpxml-etc-pages
Essential Addons for Elementor – Popular Elementor Templates & Widgetsessential-addons-for-elementor-lite
Events Manager – Calendar, Bookings, Tickets, and more!events-manager
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carouselfoogallery
Friendsfriends
FunnelKit – Funnel Builder for WooCommerce Checkoutfunnel-builder
GB Forms DBgb-forms-db
Guest Support – Complete customer support ticket system for WordPressguest-support
Gutenberg Blocks with AI by Kadence WP – Page Builder Featureskadence-blocks
Gwolle Guestbookgwolle-gb
HTML5 Radio Player – WPBakery Page Builder Addonlbg-cleverbakery
Infility Globalinfility-global
Internal Linking of Related Contentsinternal-linking-of-related-contents
Lana Downloads Managerlana-downloads-manager
Lightbox & Modal Popup WordPress Plugin – FooBoxfoobox-image-lightbox
LoginWP – Prologinwp-pro
Media Foldermedia-folder
Modern Events Calendar Litemodern-events-calendar-lite
Multi-language Responsive Contact Formresponsive-contact-form
Pakke Envíospakke
Pay with Contact Form 7pay-with-contact-form-7
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAIcontest-gallery
Premium Age Verification / Restriction for WordPressage-restriction
Premium SEO Pack – WP SEO Pluginpremium-seo-pack
Pro Bulk Watermark Plugin for WordPresspro-watermark
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & Moreproduct-xml-feeds-for-woocommerce
ProfileGrid – User Profiles, Groups and Communitiesprofilegrid-user-profiles-groups-and-communities
Profiler – What Slowing Down Your WPprofiler-what-slowing-down
PW WooCommerce On Sale!pw-woocommerce-on-sale
RSFirewall!rsfirewall
Simple Featured Imagesimple-featured-image
Site Chat on Telegramsite-chat-on-telegram
SmartSEO | SEO & Marketing Services WordPress Themesmartseo
SMu Manual DoFollowmanuall-dofollow
Super Store Findersuperstorefinder-wp
Support Boardsupportboard
SureForms – Drag and Drop Form Builder for WordPresssureforms
Tennis Court Bookingstennis-court-bookings
The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysisprofitori
Torod – The smart shipping and delivery portal for e-shops and retailerstorod
Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many Moreultimate-push-notifications
URL Shortener Plugin For WordPressexact-links
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatiblewc-frontend-manager
Widget for Google Reviewsbusiness-reviews-wp
Wishlist for WooCommerce: Multi Wishlists Per Customerwish-list-for-woocommerce
WordPress Auto Spinnerwp-auto-spinner
wordpress-flat-countdownwordpress-flat-countdown
WP Pipeswp-pipes
WP Register Profile With Shortcodewp-register-profile-with-shortcode
WP-BusinessDirectory – Business directory plugin for WordPresswp-businessdirectory
WPBookitwpbookit
WPC Smart Compare for WooCommercewoo-smart-compare
wpForo Forumwpforo
WPGYM – WordPress Gym Management Systemgym-management

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *