Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, and webhook integration are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can utilize the vulnerability Database API to receive a complete dump of our database of over 40,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-957 – Data redacted while we work with the vendor on a patch.
- WordPress Core <= 7.1 – Unauthenticated Stored Cross-Site Scripting via wpautop() Blockquote Handling
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
| Patch Status | Number of Vulnerabilities |
|---|---|
| Patched | 311 |
| Unpatched | 47 |
Total Vulnerabilities by CVSS Severity Last Week
| Severity Rating | Number of Vulnerabilities |
|---|---|
| Low Severity | 4 |
| Medium Severity | 262 |
| High Severity | 74 |
| Critical Severity | 18 |
Total Vulnerabilities by CWE Type Last Week
| Vulnerability Type by CWE | Number of Vulnerabilities |
|---|---|
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 94 |
| Missing Authorization | 68 |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 35 |
| Authorization Bypass Through User-Controlled Key | 27 |
| Exposure of Sensitive Information to an Unauthorized Actor | 26 |
| Improper Privilege Management | 19 |
| Improper Control of Generation of Code ('Code Injection') | 13 |
| Unrestricted Upload of File with Dangerous Type | 12 |
| Cross-Site Request Forgery (CSRF) | 8 |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 8 |
| Client-Side Enforcement of Server-Side Security | 7 |
| Server-Side Request Forgery (SSRF) | 6 |
| Deserialization of Untrusted Data | 4 |
| Improper Authentication | 4 |
| Incorrect Authorization | 3 |
| Protection Mechanism Failure | 3 |
| URL Redirection to Untrusted Site ('Open Redirect') | 3 |
| Authentication Bypass Using an Alternate Path or Channel | 2 |
| Improper Input Validation | 2 |
| Insufficient Verification of Data Authenticity | 2 |
| Uncontrolled Resource Consumption | 2 |
| Authentication Bypass by Spoofing | 1 |
| Embedded Malicious Code | 1 |
| External Control of File Name or Path | 1 |
| Guessable CAPTCHA | 1 |
| Improper Authorization | 1 |
| Improper Encoding or Escaping of Output | 1 |
| Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 1 |
| Improper Restriction of Rendered UI Layers or Frames | 1 |
| Improper Verification of Cryptographic Signature | 1 |
| Insufficiently Protected Credentials | 1 |
Researchers That Contributed to WordPress Security Last Week
| Researcher Name | Number of Vulnerabilities |
|---|---|
| 25 | |
| 17 | |
| 13 | |
| 12 | |
| 11 | |
| 11 | |
| 11 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery | interactive-3d-flipbook-powered-physics-engine |
| Active Woot Products Tables for WooCommerce. 100% FREE | profit-products-tables-for-woocommerce |
| Ad Inserter – Ad Manager & AdSense Ads | ad-inserter |
| Add User Autocomplete | add-user-autocomplete |
| Admin Menu Editor Pro | admin-menu-editor-pro |
| Advanced Custom Fields: Extended PRO | acf-extended-pro |
| Advanced Popups | advanced-popups |
| AF Companion – Starter Sites, Speed Booster & Growth Suite for Professional Publishing | af-companion |
| AI Engine – The Chatbot, AI Framework & MCP for WordPress | ai-engine |
| Album Cover Finder | album-cover-finder |
| All Bootstrap Blocks | all-bootstrap-blocks |
| All-in-One WP Migration and Backup | all-in-one-wp-migration |
| AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) | appmysite |
| Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | latepoint |
| Appointment Hour Booking – Booking Calendar | appointment-hour-booking |
| Asset CleanUp: Page Speed Booster | wp-asset-clean-up |
| Auto Upload Images | auto-upload-images |
| Autopay | platnosci-online-blue-media |
| aVideo | avideo |
| BE REST Endpoints | be-rest-endpoints |
| BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS & JavaScript | searchpro |
| Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | bp-better-messages |
| BlockSpare – Gutenberg Blocks, AI Content Generator & Site Builder for News, Magazine & Blogs | blockspare |
| Blog2Social: Social Media Auto Post & Scheduler | blog2social |
| Bold Page Builder | bold-page-builder |
| Booking Calendar | booking |
| Booking for Appointments and Events Calendar – Amelia | ameliabooking |
| Bookit — Booking & Appointment Calendar | bookit |
| Botiga Pro | botiga-pro |
| Bread | bread |
| Breeze Cache | breeze |
| Brizy – Page Builder | brizy |
| Business Name Generator | designbro-business-name-generator |
| Checkout Field Manager (Checkout Manager) for WooCommerce | woocommerce-checkout-manager |
| Choose User Role at Registration for WooCommerce | choose-user-role-at-registration |
| Clean Login | clean-login |
| Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors | publishpress-authors |
| Comments Import & Export | comments-import-export-woocommerce |
| Complianz GDPR/CCPA Cookie Consent Banner | complianz-gdpr |
| Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | contest-gallery |
| Cooked – Recipe Management | cooked |
| Create | mediavine-create |
| CSS & JavaScript Toolbox | css-javascript-toolbox |
| Custom Field Template | custom-field-template |
| Custom Twitter Feeds – A Tweets Widget or X Feed Widget | custom-twitter-feeds |
| Datalogics Ecommerce Delivery – Datalogics | datalogics |
| design-scuole-wordpress-theme | design-scuole-wordpress-theme |
| Dewa Kirim – WooCommerce Gojek / Gosend | dewa-kirim-woocommerce-gojek |
| Dictionary | dictionary |
| Divi Essentials | divi-essential |
| Download Manager | download-manager |
| DS Ad Rotator | ds-adrotator |
| Easy Appointments | easy-appointments |
| Easy Form Builder by WhiteStudio – Drag & Drop Form Builder | easy-form-builder |
| Easy Invoice – Invoice Generator, PDF Quotes & Payments | easy-invoice |
| EduAdmin Booking | eduadmin-booking |
| Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons | bdthemes-element-pack-lite |
| EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents | embedpress |
| Empik for Woocommerce | empik-for-woocommerce |
| Estatik Real Estate Plugin | estatik |
| Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar | mage-eventpress |
| Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | wp-event-solution |
| EWWW Image Optimizer | ewww-image-optimizer |
| Export & Import WPBakery Page Builder | vc-templates-import-export |
| FileBird – WordPress Media Library Folders & File Manager | filebird |
| Filter Gallery | filter-gallery |
| Flex Import | flex-import |
| FluentAuth – Login Security, Two-Factor Authentication, Passkeys & Social Login | fluent-security |
| FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration | fluent-boards |
| Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More | formidable |
| Forminator Forms – Contact Form, Payment Form & Custom Form Builder | forminator |
| Foxtool All-in-One: Contact chat button, Custom login, Media optimize images | foxtool |
| Generate PDF using Contact Form 7 | generate-pdf-using-contact-form-7 |
| GenieWords | geniewords |
| Geo Mashup | geo-mashup |
| Getwid – Gutenberg Blocks | getwid |
| GiveWP – Donation Plugin and Fundraising Platform | give |
| GoPay for WooCommerce | gopay-gateway |
| GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI | gptranslate |
| Gravity Forms | gravityforms |
| Gum Addon for Elementor | gum-elementor-addon |
| Headless SSO Plugin for WP | headless-single-sign-on |
| Hide My WP Ghost – Security & Firewall | hide-my-wp |
| Hoo Companion | [Article truncated — read full content at source]
Source Attribution
This intelligence summary is sourced from Wordfence Blog and curated by CyberHawk Threat Intel for the security community. Full article content is displayed with attribution under fair use for security research and education. Read original at Wordfence Blog → Accelerate Your Security OperationsCyberHawk Threat Intel is a complete Cyber Intelligence Platform — one place for every tool a security professional needs. Built by Rudra Verma, Senior Security Architect and Researcher, CyberHawk Consultancy. IOC Scanner — scan any domain, IP, hash, URL
Live IOC Feed — 3.6M+ indicators, filterable
Infostealer Intelligence — live compromised creds
Live Threat Map — real-time global attack vectors
MISP Threat Feeds — CIRCL, Feodo, Botvrij, more
GitHub Arsenal — curated security tools and scripts
Security Blog — CVE advisories and threat research
Video Courses — cybersecurity training and education
SOPs and Playbooks — SecOps procedures
Analyst Library — references and toolkits
Scan Reports — historical threat intelligence
Cyber News — this feed, aggregated in-platform
|