Weekly WP Vulnerabilities: 8/25/25 – 8/31/25

via Wordfence Email

Last week, there were 116 vulnerabilities disclosed in 102 WordPress Plugins and 13 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched75
Unpatched41

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity86
High Severity28
Critical Severity2

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)42
Cross-Site Request Forgery (CSRF)14
Missing Authorization13
Deserialization of Untrusted Data8
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)8
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)8
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)6
Unrestricted Upload of File with Dangerous Type4
Exposure of Sensitive Information to an Unauthorized Actor2
Improper Privilege Management2
Server-Side Request Forgery (SSRF)2
Improper Authentication1
Improper Authorization1
Improper Control of Generation of Code (‘Code Injection’)1
Improper Handling of Insufficient Permissions or Privileges1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
Incorrect Authorization1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
AI Hub – Startup & Technology WordPress Themeaihub
ArcHub – Architecture and Interior Design WordPress Themearchub
Cars4Rent | Auto Rental & Taxi WordPress Theme + RTLcars4rent
Golo – City Travel Guide WordPress Themegolo
Houzezhouzez
Hub – Responsive Multi-Purpose WordPress Themehub
Ireca – Car Rental Boat, Bike, Vehicle, Calendar WordPress Themeireca
Jannah – Newspaper Magazine News BuddyPress AMPjannah
Magazine Sagamagazine-saga
Makeaholic – Beauty Cosmetics WordPress Thememakeaholic
Neresa – Elementor WordPress Themeneresa-wp
Nuss – Hotel Booking WordPressnuss
Pin = Pinterest Style / Personal Masonry Blog / Front-end Submissionpin-wp

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
140+ Widgets | Xpro Addons For Elementor – FREExpro-elementor-addons
Add Code To Headadd-code-to-head
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)aftership-woocommerce-tracking
Ajax Search Lite – Live Search & Filterajax-search-lite
All Bootstrap Blocksall-bootstrap-blocks
All-in-One WP Migration and Backupall-in-one-wp-migration
Amministrazione Trasparenteamministrazione-trasparente
B Slider – Responsive Image Sliderb-slider
Beaver Builder – WordPress Page Builderbeaver-builder-lite-version
BetPressbetpress
bidorbuy Store Integratorbidorbuystoreintegrator
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protectionstopbadbots
Bold Page Builderbold-page-builder
Booking Calendarbooking
Booking System Trafftbooking-system-trafft
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Toolswoocommerce-jetpack
Captcha.eucaptcha-eu
Chartbeatchartbeat
Chatbox Managerwa-chatbox-manager
Customer Support Ticket System & Helpdesk Plugin for WordPresswp-ticket
Dokan Prodokan-pro
Drag and Drop File Upload for Elementor Formsdrag-and-drop-file-upload-for-elementor-forms
Dynamic AJAX Product Filters for WooCommercedynamic-ajax-product-filters-for-woocommerce
ElementInvader Addons for Elementorelementinvader-addons-for-elementor
Employee Directory – Staff Listing & Team Directory Plugin for WordPressemployee-directory
Employee Spotlight – Team Member Showcase & Meet the Team Pluginemployee-spotlight
Epeken All Kurir Plugin for Woocommerce Full Versionepeken-all-kurir
Event Booking Manager for WooCommerce – WpEventlymage-eventpress
Event Listeventlist
Events Addon for Elementorevents-addon-for-elementor
Exertio Frameworkexertio-framework
Feeds For TikTok – Show TikTok Videos in Grid or Feed Layoutb-tiktok-feed
File Manager, Code Editor, and Backup by Managefysoftdiscover-db-file-manager
Goal Tracker for Patreongoal-tracker-for-patreon
Google XML News Sitemap plugingn-xml-sitemap
Gutenify – Visual Site Builder Blocks & Site Templates.gutenify
Houzez CRMhouzez-crm
iATS Online Formsiats-online-forms
Instant Breaking Newsinstant-breaking-news
Invisible Optininvisible-optin
JS Archive Listjquery-archive-list-widget
Lazy Load for Videoslazy-load-for-videos
Link Viewlink-view
List Subpageslist-sub-pages
LWSCachelwscache
Nest Addonsnest-addons
Newsletter subscription optin modulenewsletter-subscription-widget-for-sendblaster
NextGEN Gallery Searchnextgen-gallery-search-galleries
Ocean Extraocean-extra
OSM Map Widget for Elementorosm-map-elementor
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSEotter-blocks
Page Manager for Elementorpage-manager-for-elementor
PDF for Elementor Forms + Drag And Drop Template Builderpdf-for-elementor-forms
Podlove Podcast Publisherpodlove-podcasting-plugin-for-wordpress
Poll, Survey & Quiz Maker Plugin by Opinion Stagesocial-polls-by-opinionstage
Post Type Converterpost-type-converter
PPWP – Password Protect WordPress | #1 Most-Reviewed Password Pluginpassword-protect-page
Premium Age Verification / Restriction for WordPressage-restriction
Printeers Print & Shipinvition-print-ship
Pro Bulk Watermark Plugin for WordPresspro-watermark
Pronamic Google Mapspronamic-google-maps
Related Posts Literelated-posts-lite
Responsive Mobile-Friendly Tooltipresponsive-mobile-friendly-tooltip
Responsive YouTube Video Gallery Plugin for WordPress – YouTube Showcaseyoutube-showcase
RingCentral Communications Plugin – FREErccp-free
Savyour Affiliate Partnersavyour-affiliate-partner
SEO For Imagesseo-for-images
Simple Contact Form Plugin for WordPress – WP Easy Contactwp-easy-contact
Simple Download Monitorsimple-download-monitor
Simple Page Access Restrictionsimple-page-access-restriction
SiteSEO – SEO Simplifiedsiteseo
Slider Revolutionrevslider
Small Package Quotes – USPS Editionsmall-package-quotes-usps-edition
Solace Extrasolace-extra
Table Editorwp-table-editor
TablePress – Tables in WordPress made easytablepress
Theme Blvd Widget Areastheme-blvd-widget-areas
Theme Switcher Reloadedtheme-switcher-reloaded
Transcodertranscoder
Tripadvisor Shortcodetripadvisor-shortcode
UiCore Elements – Free Elementor widgets and templatesuicore-elements
Ultimate Tag Warrior Importerutw-importer
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Pluginuncanny-automator
Unlimited Elements For Elementorunlimited-elements-for-elementor
UPC/EAN/GTIN Code Generatorupc-ean-barcode-generator
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPuserswp
Vibesvibes
Video Share VOD – Turnkey Video Site Builder Scriptvideo-share-vod
WooCommerce csv import exportextendons-eo-wooimport-export
WooCommerce Payment Gateway for Saferpaywoocommerce-payment-gateway-for-saferpay
WordPress Automatic Pluginwp-automatic
WordPress HTMLcustom-html-bodyhead
WP Bulk Deletewp-bulk-delete
WP Thumbtack Review Sliderwp-thumbtack-review-slider
WP ULike Prowp-ulike-pro
WPAvatarwpavatar
Xagio SEO – AI Powered SEOxagio-seo
XM-Backupxm-backup
XmasB Quotesxmasb-quotes
Xpro Theme Builder For Elementor – FREExpro-theme-builder
Yahoo! WebPlayeryahoo-media-player
Zephyr Project Managerzephyr-project-manager

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *