Weekly WP Vulnerabilities: 8/18/25 – 8/24/25

via Wordfence Email

Last week, there were 134 vulnerabilities disclosed in 110 WordPress Plugins and 16 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 47 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched66
Unpatched68

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity97
High Severity26
Critical Severity11

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)46
Cross-Site Request Forgery (CSRF)26
Missing Authorization16
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)9
Deserialization of Untrusted Data7
Authentication Bypass Using an Alternate Path or Channel4
Exposure of Sensitive Information to an Unauthorized Actor4
Incorrect Privilege Assignment4
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)3
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)3
Server-Side Request Forgery (SSRF)3
Improper Control of Generation of Code (‘Code Injection’)2
Improper Privilege Management2
Authorization Bypass Through User-Controlled Key1
External Control of File Name or Path1
Improper Authorization1
Insertion of Sensitive Information into Log File1
Unrestricted Upload of File with Dangerous Type1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
BlogMarksblogmarks
ColorMagcolormag
Eximious Magazineeximious-magazine
Glamerglamer
Houzezhouzez
Inspiroinspiro
JobZilla – Job Board WordPress Themejobzilla
Kalium 3 | Creative WordPress & WooCommerce Themekalium
Kipso – Education LMS WordPress Themekipso
Kitring – A Beauty & Hair Salon WordPress Themekitring
Magazine Elitemagazine-elite
Noo JobMonsternoo-jobmonster
organic-beautyorganic-beauty
Real Spaces – WordPress Properties Directory Themereal-spaces
Sala – Startup & SaaS WordPress Themesala
Spaciousspacious

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Admin Menu Groupsadmin-menu-groups
ads.txt Guru Connectadstxt-guru-connect
Advance Food Menuadvance-food-menu
ATT YouTube Widgetatt-youtube
AutoWP – AI Content Writer & Rewriterautowp-ai-content-writer-rewriter
Backup Boltbackup-bolt
Better Post & Filter Widgets for Elementorbetter-post-filter-widgets-for-elementor
Bible SuperSearchbiblesupersearch
Bravis Userbravis-user
bxSlider integration for WordPressbxslider-integration
Case Theme Usercase-theme-user
Century ToolKitcentury-toolkit
Church Adminchurch-admin
Clickbank WordPress Plugin (Niche Storefront)clickbank-niche-storefronts
Cloudflare Image Resizing – Optimize & Accelerate Your Imagescf-image-resizing
Comments Capcha Boxcomments-capcha-box
Contact Managercontact-manager
Cookie Warningcookie-warning
CubeWP – All-in-One Dynamic Content Frameworkcubewp-framework
Custom Commentcustomcomment
Custom Query Shortcodecustom-query-shortcode
e-Boekhouden.nle-boekhoudennl-connector
Easy Digital Downloads – eCommerce Payments and Subscriptions made easyeasy-digital-downloads
Equalize Digital Accessibility Checker – Audit Your Website for WCAG, ADA, and Section 508 Accessibility Errorsaccessibility-checker
Essential Doo Components for Visual Composeranimated-icon-banner-for-visual-composer
Eventin – AI Powered Event Manager, Events Calendar, Booking and Tickets Pluginwp-event-solution
Flexible Mapwp-flexible-map
Fluent Support – Helpdesk & Customer Support Ticket Systemfluent-support
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommercewp-marketing-automations
FunnelKit – Funnel Builder for WooCommerce Checkoutfunnel-builder
GiveWP – Donation Plugin and Fundraising Platformgive
Global DNSglobal-dns
Greenshift – animation and page builder blocksgreenshift-animation-and-page-builder-blocks
Hesabfa Accountinghesabfa-accounting
iFrame Blockiframe-block
iframe Wrapperiframe-wrapper
JobWP – Job Board, Job Listing, Career Page and Recruitment Pluginjobwp
JS Archive Listjquery-archive-list-widget
Kanpresskanpress
Kento Splash Screenkento-splash-screen
LifePresslifepress
Link Viewlink-view
Listeo-Core – Directory Plugin by Purethemeslisteo-core
Markup Markdownmarkup-markdown
MDTF – Meta Data and Taxonomies Filterwp-meta-data-filter-and-taxonomy-filter
Media Library Assistantmedia-library-assistant
Mesa Mesa Reservation Widgetmesa-mesa-reservation-widget
miraculouscoremiraculouscore
NEX-Forms – Ultimate Forms Plugin for WordPressnex-forms-express-wp-form-builder
Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templatesthe-plus-addons-for-block-editor
Ni WooCommerce Customer Product Reportni-woocommerce-customer-product-report
Notice Barnotice-bar
Ogulo – 360° Tourogulo-360-tour
Ovatheme Eventsova-events
Page Transitionpage-transition
Popup for CF7 with Sweet Alertcf7-sweet-alert-popup
Portfolio Manager Pro – WordPress Responsive Portfolio & Galleryotw-portfolio-manager
PressApps Knowledge Base Contextual Sidebar Addonpressapps-knowledge-base
ProveSource Social Proofprovesource
rajcerajce
Raptive Adsadthrive-ads
Recurring PayPal Donationsrecurring-donation
Redirection for Contact Form 7wpcf7-redirect
Restore Permanently delete Post or Page Datarestore-permanently-delete-post-or-page-data
Risk Free Cash On Delivery (COD) – WooCommercerisk-free-cash-on-delivery-cod-woocommerce
SensorPresssensorpress-uptime-monitoring
Sertifier Certificate & Badge Maker for WordPress – Tutor LMSsertifier-certificates-open-badges
Sessionssessions
ShortcodeHub – MultiPurpose Shortcode Buildershortcodehub
Sign-up Sheetssign-up-sheets
Silencesoft RSS Readerexternal-rss-reader
Simple Business Directory Prosimple-business-directory-pro
Simple Statistics for Feedssimple-feed-stats
Simpler Checkoutsimpler-checkout
Site Offline Or Coming Soon Or Maintenance Modesite-offline
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)slingblocks
Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templatessastra-essential-addons-for-elementor
Statify Widgetstatify-widget
Super Store Findersuperstorefinder-wp
Support Ticketsupport-ticket
TC Testimonialstc-testimonial
Templately – Elementor & Gutenberg Template Library: 5500+ Free & Pro Ready Templates And Cloud!templately
Terms of Service & Privacy Policy Generatorterms-of-service-and-privacy-policy
ThemeMakers Visual Content Composertmm_content_composer
Themify Audio Dockthemify-audio-dock
Themify Builderthemify-builder
Themify Iconsthemify-icons
tli.tl auto Twitter postertlitl-auto-twitter-poster
Ultimate twitter profile widgetultimate-twitter-profile-widget
Varnish/Nginx Proxy Cachingvcaching
Video Gallery – Vimeo and YouTube Gallerysmart-grid-gallery
WC Pluswc-plus
WP Admin Themewp-admin-theme
WP Colorboxwp-colorbox
WP Crontrolwp-crontrol
WP Fast Total Search – The Power of Indexed Searchfulltext-search
WP Filter & Combine RSS Feedswp-filter-combine-rss-feeds
WP Funnel Managerwp-funnel-manager
WP Mailgun SMTPwp-mailgun-smtp
WP Visitor Statistics (Real Time Traffic)wp-stats-manager
WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPresswp-webhooks
WPC Smart Compare for WooCommercewoo-smart-compare
WPC Smart Quick View for WooCommercewoo-smart-quick-view
WPMU Ldap Authenticationwpmuldap
WPPizza – A Restaurant Pluginwppizza
Wptobe-membershipswptobe-memberships
WS Theme Addonsws-theme-addons
Яндекс.ПДС Пингер / Yandex Site search pingeryandex-pinger
多说社会化评论框duoshuo
百度分享按钮baidushare-wp

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *