Weekly WP Vulnerabilities: 9/29/25 – 10/5/25

via Wordfence Email

Table of Contents

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched27
Unpatched66

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity1
Medium Severity73
High Severity11
Critical Severity8

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)42
Cross-Site Request Forgery (CSRF)17
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)6
Missing Authorization5
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)3
Unrestricted Upload of File with Dangerous Type3
Authentication Bypass Using an Alternate Path or Channel2
Exposure of Sensitive Information to an Unauthorized Actor2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
External Control of File Name or Path1
Improper Access Control1
Improper Authorization1
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)1
Improper Neutralization of Directives in Statically Saved Code (‘Static Code Injection’)1
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)1
Improper Verification of Cryptographic Signature1
Missing Authentication for Critical Function1
Server-Side Request Forgery (SSRF)1
Unverified Password Change1
Use of Hard-coded Cryptographic Key1
Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Constructorconstructor
Customifycustomify

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
A Simple Multilanguage Plugina-simple-multilanguage
AffiliateWPaffiliate-wp
All in One Music Playerall-in-one-music-player
All Social Share Optionsall-social-share-options
Any News Tickerany-news-ticker
AP Backgroundap-background
Appy Pie Connect for WooCommerceappy-pie-connect-for-woocommerce
Auto Bulb Finder for WordPressauto-bulb-finder-for-wp-wc
Backup Boltbackup-bolt
Bei Fen – WordPress Backup Pluginbei-fen
Big Post Shipping for WooCommercewoo-bigpost-shipping
Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android Appyournewsapp
Block For Mailchimp – Easy Mailchimp Form Integrationblock-for-mailchimp
BP Direct Menusbp-direct-menus
Chat by Chatweechatwee
Comment Info Detectorcomment-info-detector
ContentMX Content Publishercontentmx-content-publisher
Contest Gallery – Upload, Vote & Sell with PayPal and Stripecontest-gallery
Copypress Rest APIcopypress-rest-api
Cost Calculator Buildercost-calculator-builder
dbviewdbview
Easy Elementor Addons – Addons Pack for Elementor Page Buildereasy-elementor-addons
Epic Bootstrap Buttonsepic-bootstrap-buttons
Eulerpool Research Systemsalleaktien-quantitativ
Event Tickets, RSVPs, Calendarticket-spot
FancyTabsfancytabs
File Manager, Code Editor, and Backup by Managefysoftdiscover-db-file-manager
Fintelligence Calculatorfintelligence-calculator
Flexi – Guest Submitflexi
Generic Elementsgeneric-elements-for-elementor
GiveWP – Donation Plugin and Fundraising Platformgive
GutenBee – Gutenberg Blocksgutenbee
Integrate Dynamics 365 CRMintegrate-dynamics-365-crm
Interactive Human Anatomy with Clickable Body Partsinteractive-medical-drawing-of-human-body
Ird Sliderird-slider
JoomSport – for Sports: Team & League, Football, Hockey & morejoomsport-sports-league-results-management
LatePoint – Calendar Booking Plugin for Appointments and Eventslatepoint
Layerslayers
LockerPress – WordPress Security Pluginlockerpress-wordpress-security
Majestic Before After Imagemajestic-before-after-image
Meks Easy Mapsmeks-easy-maps
Mihdan: Elementor Yandex Mapsmihdan-elementor-yandex-maps
Mobile Site Redirectmobile-site-redirect
MPWizard – Create Mercado Pago Payment Linksmpwizard
My AskAImy-askai
Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSEnexa-blocks
Notification Barsimple-bar
OAuth Single Sign On – SSO (OAuth Client)miniorange-login-with-eve-online-google-facebook
Optimize More! – CSSoptimize-more-css
PayPal Formspaypal-forms
planetcalcplanetcalc
Post By Emailpost-by-email
Qyrr – simply and modern QR-Code creationqyrr-code
Restrict User Registrationrestrict-user-registration
RestroPress – Online Food Ordering Systemrestropress
Schema Plugin For Divi, Gutenberg & Shortcodeswp-structured-data-schema
SiteAlert (Formerly WP Health)my-wp-health-check
Smart Docssmart-docs
SmartCrawl SEO checker, analyzer & optimizersmartcrawl-seo
Spirit Frameworkspirit-framework
Survey Anyplacesurveyanyplace
TableGen – Data Table Generatortable-creator
TextBuildertextbuilder
The Pack Elementor addonthe-pack-addon
Tiny Bootstrap Elements Lighttiny-bootstrap-elements-light
Trinity Audio – Text to Speech AI audio player to convert content into audiotrinity-audio
Ultimate Multi Design Video Carouselultimate-multi-design-video-carousel
Ultimate Viral Quizultimate-viral-quiz
Ultra Addons Lite for Elementorut-elementor-addons-lite
Unifyunify
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builderwdesignkit
WeedMaps Menu for WordPressweedmaps-menu-embed
Woo superb slideshow transition gallery with random effectwoo-superb-slideshow-transition-gallery-with-random-effect
Wp cycle text announcementwp-cycle-text-announcement
WP Dispatcherwp-dispatcher
WP Photo Album Pluswp-photo-album-plus
WP Photo Effectswp-photo-effects
WP SinoTypewp-sinotype
WPRecoverywprecovery
X Addons for Elementorx-addons-elementor
Yoast SEO Premiumwordpress-seo-premium
Yoga Schedule Momoyogamomoyoga-integration
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patternszoloblocks

Have ServiceNow & WordPress?

Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *