Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, and webhook integration are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can utilize the vulnerability Database API to receive a complete dump of our database of over 40,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 311
Unpatched 47


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 4
Medium Severity 262
High Severity 74
Critical Severity 18


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 94
Missing Authorization 68
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 35
Authorization Bypass Through User-Controlled Key 27
Exposure of Sensitive Information to an Unauthorized Actor 26
Improper Privilege Management 19
Improper Control of Generation of Code ('Code Injection') 13
Unrestricted Upload of File with Dangerous Type 12
Cross-Site Request Forgery (CSRF) 8
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 8
Client-Side Enforcement of Server-Side Security 7
Server-Side Request Forgery (SSRF) 6
Deserialization of Untrusted Data 4
Improper Authentication 4
Incorrect Authorization 3
Protection Mechanism Failure 3
URL Redirection to Untrusted Site ('Open Redirect') 3
Authentication Bypass Using an Alternate Path or Channel 2
Improper Input Validation 2
Insufficient Verification of Data Authenticity 2
Uncontrolled Resource Consumption 2
Authentication Bypass by Spoofing 1
Embedded Malicious Code 1
External Control of File Name or Path 1
Guessable CAPTCHA 1
Improper Authorization 1
Improper Encoding or Escaping of Output 1
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
Improper Restriction of Rendered UI Layers or Frames 1
Improper Verification of Cryptographic Signature 1
Insufficiently Protected Credentials 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
25
17
13
12
11
11
11
8
7
6
6
6
6
6
5
5
5
5
5
5
4
4
4
4
4
4
4
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
UKO
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine
Active Woot Products Tables for WooCommerce. 100% FREE  profit-products-tables-for-woocommerce
Ad Inserter – Ad Manager & AdSense Ads ad-inserter
Add User Autocomplete add-user-autocomplete
Admin Menu Editor Pro admin-menu-editor-pro
Advanced Custom Fields: Extended PRO acf-extended-pro
Advanced Popups advanced-popups
AF Companion – Starter Sites, Speed Booster & Growth Suite for Professional Publishing af-companion
AI Engine – The Chatbot, AI Framework & MCP for WordPress ai-engine
Album Cover Finder album-cover-finder
All Bootstrap Blocks all-bootstrap-blocks
All-in-One WP Migration and Backup all-in-one-wp-migration
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) appmysite
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress latepoint
Appointment Hour Booking – Booking Calendar appointment-hour-booking
Asset CleanUp: Page Speed Booster wp-asset-clean-up
Auto Upload Images auto-upload-images
Autopay platnosci-online-blue-media
aVideo avideo
BE REST Endpoints be-rest-endpoints
BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS & JavaScript searchpro
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots bp-better-messages
BlockSpare – Gutenberg Blocks, AI Content Generator & Site Builder for News, Magazine & Blogs blockspare
Blog2Social: Social Media Auto Post & Scheduler blog2social
Bold Page Builder bold-page-builder
Booking Calendar booking
Booking for Appointments and Events Calendar – Amelia ameliabooking
Bookit — Booking & Appointment Calendar bookit
Botiga Pro botiga-pro
Bread bread
Breeze Cache breeze
Brizy – Page Builder brizy
Business Name Generator designbro-business-name-generator
Checkout Field Manager (Checkout Manager) for WooCommerce woocommerce-checkout-manager
Choose User Role at Registration for WooCommerce choose-user-role-at-registration
Clean Login clean-login
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors publishpress-authors
Comments Import & Export comments-import-export-woocommerce
Complianz GDPR/CCPA Cookie Consent Banner complianz-gdpr
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery
Cooked – Recipe Management cooked
Create mediavine-create
CSS & JavaScript Toolbox css-javascript-toolbox
Custom Field Template custom-field-template
Custom Twitter Feeds – A Tweets Widget or X Feed Widget custom-twitter-feeds
Datalogics Ecommerce Delivery – Datalogics datalogics
design-scuole-wordpress-theme design-scuole-wordpress-theme
Dewa Kirim – WooCommerce Gojek / Gosend dewa-kirim-woocommerce-gojek
Dictionary dictionary
Divi Essentials divi-essential
Download Manager download-manager
DS Ad Rotator ds-adrotator
Easy Appointments easy-appointments
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder easy-form-builder
Easy Invoice – Invoice Generator, PDF Quotes & Payments easy-invoice
EduAdmin Booking eduadmin-booking
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons bdthemes-element-pack-lite
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents embedpress
Empik for Woocommerce empik-for-woocommerce
Estatik Real Estate Plugin estatik
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar mage-eventpress
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce wp-event-solution
EWWW Image Optimizer ewww-image-optimizer
Export & Import WPBakery Page Builder vc-templates-import-export
FileBird – WordPress Media Library Folders & File Manager filebird
Filter Gallery filter-gallery
Flex Import flex-import
FluentAuth – Login Security, Two-Factor Authentication, Passkeys & Social Login fluent-security
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration fluent-boards
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More formidable
Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images foxtool
Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7
GenieWords geniewords
Geo Mashup geo-mashup
Getwid – Gutenberg Blocks getwid
GiveWP – Donation Plugin and Fundraising Platform give
GoPay for WooCommerce gopay-gateway
GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI gptranslate
Gravity Forms gravityforms
Gum Addon for Elementor gum-elementor-addon
Headless SSO Plugin for WP headless-single-sign-on
Hide My WP Ghost – Security & Firewall hide-my-wp
Hoo Companion

[Article truncated — read full content at source]

Source Attribution
This intelligence summary is sourced from Wordfence Blog and curated by CyberHawk Threat Intel for the security community. Full article content is displayed with attribution under fair use for security research and education.

Read original at Wordfence Blog →

Accelerate Your Security Operations

CyberHawk Threat Intel is a complete Cyber Intelligence Platform — one place for every tool a security professional needs. Built by Rudra Verma, Senior Security Architect and Researcher, CyberHawk Consultancy.

IOC Scanner — scan any domain, IP, hash, URL
Live IOC Feed — 3.6M+ indicators, filterable
Infostealer Intelligence — live compromised creds
Live Threat Map — real-time global attack vectors
MISP Threat Feeds — CIRCL, Feodo, Botvrij, more
GitHub Arsenal — curated security tools and scripts
Security Blog — CVE advisories and threat research
Video Courses — cybersecurity training and education
SOPs and Playbooks — SecOps procedures
Analyst Library — references and toolkits
Scan Reports — historical threat intelligence
Cyber News — this feed, aggregated in-platform