Weekly WP Vulnerabilities: 8/04/25 – 8/10/25

via Wordfence Email

Last week, there were 52 vulnerabilities disclosed in 47 WordPress Plugins and 6 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 28 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-862 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-863 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched39
Unpatched13

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity32
High Severity17
Critical Severity3

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)23
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)6
Missing Authorization6
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)4
Unrestricted Upload of File with Dangerous Type4
Deserialization of Untrusted Data2
Improper Control of Generation of Code (‘Code Injection’)2
Authorization Bypass Through User-Controlled Key1
Exposure of Sensitive Information to an Unauthorized Actor1
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)1
Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’)1
Improper Privilege Management1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Bethemebetheme
Shoposhopo
The7 — Website and eCommerce Builder for WordPressdt-the7
Urna – All-in-one WooCommerce WordPress Themeurna
Xinterio – Interior Design WordPress Theme + RTLxinterio
Zakrazakra

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
BaiduXZH Submit(百度熊掌号)i3geek-baiduxzh
Campus Directory – Faculty, Staff & Student Directory Plugin for WordPresscampus-directory
CleverReach® WPcleverreach-wp
Code Enginecode-engine
Cost Calculatorql-cost-calculator
Coupon Affiliates – Affiliate Plugin for WooCommercewoo-coupon-usage
Customer Support Ticket System & Helpdesk Plugin for WordPresswp-ticket
Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Stylercf7-styler
Download Counterdownload-counter
Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form buildereasy-form-builder
Element Pack Elementor Addons and Templatesbdthemes-element-pack-lite
Employee Directory – Staff Listing & Team Directory Plugin for WordPressemployee-directory
esri-map-viewesri-map-view
Eventer – WordPress Event & Booking Manager Plugineventer
Eventin – Event Manager, Events Calendar, Booking, Tickets and Registrationwp-event-solution
Exclusive Addons for Elementorexclusive-addons-for-elementor
FileBird – WordPress Media Library Folders & File Managerfilebird
Flex Guten – Multile Blocksflex-guten
Form Blockform-block
FundEngine – Donation and Crowdfunding Platformwp-fundraising-donation
GiveWP – Donation Plugin and Fundraising Platformgive
Global Gallery – WordPress Responsive Galleryglobal-gallery
GravityWP – Merge Tagsgravitywp-merge-tags
Groundhogg — CRM, Newsletters, and Marketing Automationgroundhogg
Gutenverse – Ultimate Block Addons and Page Builder for Site Editorgutenverse
IDonatePro – Blood Donation, Request And Donor Management WordPress Pluginidonate-pro
MapSVGmapsvg
Multimedia Playlist Slider Addon for WPBakery Page Builderlbg_vp_youtube_vimeo_addon_visual_composer
Porn Videos Embedporn-videos-embed
Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonrypost-grid
Prevent files / folders accessprevent-file-access
Project Management, Bug and Issue Tracking Plugin – Software Issue Managersoftware-issue-manager
RentSyst – CRM solution for fleet managementrentsyst
Request a Quote Form Plugin – Price Quote Request Management Made Easyrequest-a-quote
Reveal Listingreveal-listing
Simple Contact Form Plugin for WordPress – WP Easy Contactwp-easy-contact
SMM APIsmm-api
Use-your-Drive | Google Drive plugin for WordPressuse-your-drive
User Language Switchuser-language-switch
Visit Countervisit-counter
WP Import Export Litewp-import-export-lite
WP Lead Capturing Pages – WordPress Pluginleadcapture
WP Tournament Registrationwp-tournament-registration
WP-jScrollPanewp-jscrollpane
WPBakery Page Builderjs_composer
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patternszoloblocks
多说社会化评论框duoshuo

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *