Weekly WP Vulnerabilities: 8/11/25 – 8/17/25

via Wordfence Email

Last week, there were 168 vulnerabilities disclosed in 142 WordPress Plugins and 11 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 69 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched81
Unpatched87

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity1
Medium Severity133
High Severity27
Critical Severity7

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)64
Missing Authorization26
Cross-Site Request Forgery (CSRF)22
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)9
Exposure of Sensitive Information to an Unauthorized Actor7
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)7
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)7
Improper Control of Generation of Code (‘Code Injection’)5
Unrestricted Upload of File with Dangerous Type5
Deserialization of Untrusted Data4
Server-Side Request Forgery (SSRF)3
Improper Input Validation2
Authorization Bypass Through User-Controlled Key1
Client-Side Enforcement of Server-Side Security1
Improper Authorization1
Improper Neutralization of Formula Elements in a CSV File1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
Improper Privilege Management1
Relative Path Traversal1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
App, SaaS & Software Startup Tech Theme – Stratusstratus
Blocksyblocksy
Findgo – Directory Listing WordPress Themefindgo
Kalium 3 | Creative WordPress & WooCommerce Themekalium
Makeaholic – Beauty Cosmetics WordPress Thememakeaholic
Modernize – Flexibility of WordPressmodernize
OceanWPoceanwp
Savoysavoy
Soledadsoledad
unicampunicamp
WP Rentals – Booking Accommodation WordPress Themewprentals

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
12 Step Meeting List12-step-meeting-list
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascriptadd-custom-codes
Add User Metaadd-user-meta
Advanced File Manager – Ultimate WP File Manager And Document Library Solutionfile-manager-advanced
Advanced iFrameadvanced-iframe
AL Packalpack
Alobaidi Captchaalobaidi-captcha
Anber Elementor Addonanber-elementor-addon
AnWP Football Leaguesfootball-leagues-by-anwppro
Appointment Booking & Scheduling Plugin — Webba Booking Calendarwebba-booking-lite
Assistant for NextGEN Galleryassistant-for-nextgen-gallery
Authentication and xmlrpc log writerauthentication-and-xmlrpc-log-writer
Awesome Support – WordPress HelpDesk & Support Pluginawesome-support
AWStats Scriptawstats-script
B Blocks – Essential Gutenberg Blocks & Patterns Collectionb-blocks
B Slider – Responsive Image Sliderb-slider
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answersbetterdocs
Billplz Addon for Contact Form 7billplz-for-contact-form-7
Bit Form – Custom Contact Form, Multi Step, Conversational, Payment & Quiz Form builderbit-form
BizCalendar Webbizcalendar-web
Blog Designer PRO for WordPressblog-designer-pro
Build App Onlinebuild-app-online
CF7 Spreadsheetscf7-spreadsheets
CM Search And Replace – Optimize content edits with a powerful search and replace toolcm-on-demand-search-and-replace
CodeablePress: Simple Frontend Profile Picture Uploadcodeablepress-simple-frontend-profile-picture-upload
Contact Info Widgetsimple-contact-info-widget
Custom Commentcustomcomment
Custom Menucustom-menu
Database for Contact Form 7, WPforms, Elementor formscontact-form-entries
DigitalOcean Spaces Syncdo-spaces-sync
Drag and Drop Multiple File Upload for Contact Form 7drag-and-drop-multiple-file-upload-contact-form-7
Dropshixdropshipping-xox
Dynamic Pricing With Discount Rules for WooCommerceaco-woo-dynamic-pricing
E-cab Taxi Booking Manager for Woocommerceecab-taxi-booking-manager
Earnware Connectearnware-connect
Easy Elementor Addonseasy-elementor-addons
Easy restaurant menu managereasy-pdf-restaurant-menu-upload
Elementor Website Builder – More Than Just a Page Builderelementor
elink – Embed Contentelink-embed-content
Elizaibotselizaibot-chatbots
Embed Bokunembed-bokun
Embedder for Google Reviewsembedder-for-google-reviews
Essential Addons for Elementor – Popular Elementor Templates & Widgetsessential-addons-for-elementor-lite
Eventin – AI Powered Event Manager, Events Calendar, Booking and Tickets Pluginwp-event-solution
EventON – Events Calendareventon-lite
File Manager Prowp-file-manager-pro
File Manager Pro – Filesterfilester
flexo-social-galleryflexo-social-gallery
Formsforms-by-made-it
Frontend Admin by DynamiAppsacf-frontend-form-element
Gestion de tarifsgestion-tarifs
GMap Generatorgmap-venturit
Graphina – Elementor Charts and Graphsgraphina-elementor-charts-and-graphs
Hide Text Shortcodehide-text-shortcode
Icons Factoryicons-factory
Infility Globalinfility-global
Inline Stock Quotesinline-stock-quotes
Inpersttion For Themeerr-our-team
Inspectlet – User Session Recording and Heatmapsinspectlet-heatmaps-and-user-session-recording
Intl DateTime Calendarintl-datetime-calendar
JetElementsjet-elements
JetProductGalleryjet-woo-product-gallery
JobSearch WP Job Boardwp-jobsearch
Kadence WooCommerce Email Designerkadence-woocommerce-email-designer
Laposta WooCommercelaposta-woocommerce
Last.fm Recent Album Artworklastfm-recent-album-artwork
LatestCheckinslatestcheckins
Linux Promotional Pluginlinux-promotional-plugin
Master Addons – Elementor Addons with White Label, Free Widgetsmaster-addons
Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Content Drippingmembership-for-woocommerce
Mosaic Generatormosaic-generator
Neon Channel Product Customizer Freeneon-channel-product-customizer-free
Netease Musicnetease-music
NetInsight Analytics Implementation Pluginnetinsight-analytics-implementation-plugin
Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templatesthe-plus-addons-for-block-editor
oikoik
Online Booking & Scheduling Calendar for WordPress by vcitameeting-scheduler-by-vcita
Order Tip for WooCommerceorder-tip-woo
OTP Login With Phone Number, OTP Verificationlogin-with-phone-number
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePresswp-user-avatar
Pending Order Botpending-order-bot
Plugin README Parserwp-readme-parser
Poll Maker – Versus Polls, Anonymous Polls, Image Pollspoll-maker
Premium Addons for KingComposerpremium-addons-for-kingcomposer
Premium Packages – Sell Digital Products Securelywpdm-premium-packages
Primer MyData for Woocommerceprimer-mydata
Print My Blog – Print, PDF, & eBook Converter WordPress Pluginprint-my-blog
Project Cost Calculatorproject-cost-calculator
Project Management, Bug and Issue Tracking Plugin – Software Issue Managersoftware-issue-manager
Quiz and Survey Master (QSM) – Easy Quiz and Survey Makerquiz-master-next
Quttera Web Malware Scannerquttera-web-malware-scanner
Radius Blocks – WordPress Gutenberg Blocksradius-blocks
Real Estate Manager Proreal-estate-manager-pro
Responsive Posts Carousel WordPress Pluginresponsive-posts-carousel-pro
RSS Feed Prorss-feed-pro
RT Easy Builder – Advanced addons for Elementorrt-easy-builder-advanced-addons-for-elementor
School Management System for WordPressschool-management
ServerBuddy by PluginBuddy.comserverbuddy-by-pluginbuddy
Shortcode Redirectshortcode-redirect
Simple Local Avatarssimple-local-avatars
Simple Login Logsimple-login-log
Simple Pollsimple-poll
Simple Responsive Slideraddi-simple-slider
Simplified Pluginsimplified
SoundSt SEO Searchsoundst-seo-search
StoryChiefstory-chief
Surbma | Recent Comments Shortcodesurbma-recent-comments-shortcode
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAIsimple-tags
Templateratemplatera
Thank You Page Customizer for WooCommerce – Increase Your Saleswoo-thank-you-page-customizer
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommercethe-plus-addons-for-elementor-page-builder
Thim Corethim-core
Time Sheetstime-sheets
Translate This gTranslate Shortcodetranslate-this-google-translate-web-element-shortcode
Tutor LMS Protutor-pro
UiCore Elements – Free Elementor widgets and templatesuicore-elements
Ultimate Video Player WordPress & WooCommerce Pluginfwduvp
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editorprofile-builder
Vertical scroll slideshow gallery v2vertical-scroll-slideshow-gallery-v2
Video Expandervideo-expander
Visual Composer Website Buildervisualcomposer
weichuncai(WP伪春菜)weichuncai
Welcart e-Commerceusc-e-shop
Woocommerce Blocks – Woolookwoolook
WooCommerce Purchase Orderswc-purchase-orders
WordLift – AI powered SEO – Schemawordlift
WordPress Event Manager, Event Calendar and Booking Plugineventin-pro
WordPress StoryMap Pluginwp-storymap
WP Airdrop Managerairdrop
Wp chart generatorwp-chart-generator
WP Discord Post Plus – Supports Unlimited Channelswp-discord-post-plus
WP Dynamic Linkswp-dynamic-links
WP Emmetwp-emmet
WP Membershipwp-membership
WP Pipeswp-pipes
WP Private Content Pluswp-private-content-plus
WP Statistics – Simple, privacy-friendly Google Analytics alternativewp-statistics
WP Table Builder – Drag & Drop Table Builderwp-table-builder
WP Votingwp-voting
WP-Database-Optimizer-Toolswp-database-optimizer-tools
WPGYM – WordPress Gym Management Systemgym-management

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *