Calling all Vulnerability Researchers and Bug Bounty Hunters!
Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!
Last week, there were 257 vulnerabilities disclosed in 233 WordPress Plugins and 13 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 66 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 27,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-844 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 103 |
Unpatched | 154 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 2 |
Medium Severity | 216 |
High Severity | 26 |
Critical Severity | 13 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 94 |
Missing Authorization | 53 |
Cross-Site Request Forgery (CSRF) | 47 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 21 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 10 |
Deserialization of Untrusted Data | 5 |
Exposure of Sensitive Information to an Unauthorized Actor | 4 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 3 |
Server-Side Request Forgery (SSRF) | 3 |
Unrestricted Upload of File with Dangerous Type | 3 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 3 |
Authentication Bypass Using an Alternate Path or Channel | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
Improper Control of Generation of Code (‘Code Injection’) | 1 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
Improper Restriction of XML External Entity Reference | 1 |
Improper Validation of Specified Quantity in Input | 1 |
Insertion of Sensitive Information into Log File | 1 |
Insertion of Sensitive Information Into Sent Data | 1 |
Plaintext Storage of a Password | 1 |
Unverified Password Change | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
25 | |
19 | |
19 | |
18 | |
16 | |
14 | |
13 | |
9 | |
9 | |
7 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
404 Page by SeedProd | 404-page |
6Storage Rentals | 6storage-rentals |
Abbie Expander | abbie-expander |
Accessibility Suite by Ability, Inc | online-accessibility |
ACF: Yandex Maps Field | acf-yandex-maps-field |
Activity Plus Reloaded for BuddyPress | bp-activity-plus-reloaded |
Admin Notes | admin-note |
Advanced Post List | advanced-post-list |
AI Mortgage Calculator | ai-mortgage-calculator |
All Currencies for WooCommerce | woocommerce-all-currencies |
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant | gdpr-compliant-recaptcha-for-all-forms |
Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms | stop-spammer-registrations-plugin |
AppBanners | appbanners |
Atelier Create CV | atelier-create-cv |
Backup and Staging by WP Time Capsule | wp-time-capsule |
Backwp | backwp |
Bacon Ipsum | bacon-ipsum |
Bang tinh vay | bang-tinh-lai-suat |
bbPress API | bbp-api |
Behance Portfolio Manager | portfolio-manager-powered-by-behance |
Bellows Accordion Menu | bellows-accordion-menu |
Bg Orthodox Calendar | bg-orthodox-calendar |
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress | file-manager |
Bitly URL Shortener | codehaveli-bitly-url-shortener |
BlockStrap Page Builder – Bootstrap Blocks | blockstrap-page-builder-blocks |
BM Content Builder | bm-builder |
BNS Featured Category | bns-featured-category |
Booking Ultra Pro Appointments Booking Calendar Plugin | booking-ultra-pro |
Booqable Rental Plugin | booqable-rental-reservations |
BP Profile as Homepage | bp-profile-as-homepage |
Broadly for WordPress | broadly |
Broken Link Checker | broken-link-checker |
BRW – Booking Rental Plugin WooCommerce | ova-brw |
Calculated Fields Form | calculated-fields-form |
Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress | campus-directory |
Category Icon | category-icon |
Complete Google Seo Scan | complete-google-seo-scan |
Contact Form | contact-form-ready |
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent | gdpr-cookie-consent |
Crawlomatic Multipage Scraper Post Generator | crawlomatic-multipage-scraper-post-generator |
CubePoints | cubepoints |
CubeWP – All-in-One Dynamic Content Framework | cubewp-framework |
Custom Bulk/Quick Edit | custom-bulkquick-edit |
Custom Category Post Order | custom-post-order-category |
Developer Formatter | devformatter |
Direct Checkout for WooCommerce Lite | woo-direct-checkout-lite |
DocsPress – Online Documentation | docspress |
Domain For Sale, Domain appraisal, Domain auction, Domain marketplace – Best Domain For sale Plugin for WordPress | domain-for-sale |
Easy Mega Menu Plugin for WordPress – ThemeHunk | themehunk-megamenu-plus |
Elastic Email Subscribe Form | elastic-email-subscribe-form |
Elegant Visitor Counter | elegant-visitor-counter |
elfsight-contact-form | elfsight-contact-form |
Elite Video Player | elite-video-player |
Employee Directory – Staff Listing & Team Directory Plugin for WordPress | employee-directory |
Epicwin Plugin | epicwin-subscribers |
Essential Addons for Elementor – Popular Elementor Templates and Widgets | essential-addons-for-elementor-lite |
ESV Bible Shortcode for WordPress | esv-bible-shortcode-for-wordpress |
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin | mage-eventpress |
Event post | event-post |
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin | everest-backup |
FastBook – Responsive Appointment Booking and Scheduling System | fastbook-responsive-appointment-booking-and-scheduling-system |
Forminator Forms – Contact Form, Payment Form & Custom Form Builder | forminator |
Foxit eSign for WordPress | esign-genie-for-wp |
FraudLabs Pro for WooCommerce | fraudlabs-pro-for-woocommerce |
Free WP Mail SMTP (Official – 2019) | free-wp-mail-smtp |
Freemind Viewer | wp-freemind |
Frontend Dashboard | frontend-dashboard |
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | gamipress |
Global Translator | global-translator |
GPP Slideshow | gpp-slideshow |
Greenshift – animation and page builder blocks | greenshift-animation-and-page-builder-blocks |
Hide It | hide-it |
Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress | hive-support |
HR Management Lite | hr-management-lite |
Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | hydra-booking |
HyperComments | hypercomments |
Icegram Collect – Easy Form, Lead Collection and Subscription plugin | icegram-rainmaker |
IFrame Widget | iframe-widget |
Image Hover Effects Block | image-hover-effects-block |
Interactive Regional Map of Africa | interactive-map-of-africa |
Interactive Regional Map of Florida | interactive-map-of-florida |
Interactive UK Regional Map | interactive-uk-regional-map |
InWave Jobs | iwjob |
Job Board Manager | job-board-manager |
KI Live Video Conferences | ki-live-video-conferences |
Knowledge Base | knowledgebase |
Konami Easter Egg | konami-easter-egg |
Layouts for Elementor | layouts-for-elementor |
Libro de Reclamaciones y Quejas | libro-de-reclamaciones-y-quejas |
LTL Freight Quotes – Day & Ross Edition | ltl-freight-quotes-day-ross-edition |
LTL Freight Quotes – Daylight Edition | ltl-freight-quotes-daylight-edition |
LTL Freight Quotes – Freightview Edition | ltl-freight-quotes-freightview-edition |
Market Exporter | market-exporter |
Mediabay – WordPress Media Library Folders | mediabay |
Melipayamak | melipayamak |
Modern Events Calendar Lite | modern-events-calendar-lite |
Motors – Events | stm-motors-events |
Multi CryptoCurrency Payments | multi-crypto-currency-payment |
MultiVendorX – WooCommerce Multivendor Marketplace Solutions | dc-woocommerce-multi-vendor |
Music Player for Elementor – Audio Player & Podcast Player | music-player-for-elementor |
MyStyle Custom Product Designer | mystyle-custom-product-designer |
Nasa Core | nasa-core |
Newspack Newsletters | newspack-newsletters |
Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | nexa-blocks |
Next Event Calendar | next-event-calendar |
Ninja Tables – Easy Data Table Builder | ninja-tables |
No Spam At All | no-spam-at-all |
oik | oik |
Paged Gallery | paged-gallery |
Password Policy Manager | Password Manager | password-policy-manager |
Pay with Contact Form 7 | pay-with-contact-form-7 |
Payment QR WooCommerce | payment-qr-woo |
PayU CommercePro Plugin | payu-india |
PDF for WPForms + Drag and Drop Template Builder | pdf-for-wpforms |
Personal Favicon | personal-favicon |
Pinterest Verify Meta Tag | pinterest-verify-meta-tag |
POEditor | poeditor |
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder | popup-maker |
Post Author | post-author |
Post Custom Templates Lite | post-custom-templates-lite |
Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder | ajax-filter-posts |
Powie’s Uptime Robot Plugin | powies-uptime-robot |
Premium Packages – Sell Digital Products Securely | wpdm-premium-packages |
Product Catalog Simple | post-type-x |
Product Feed for WooCommerce – Google Shopping Feed, Pinterest Feed, TikTok Ads & More | webtoffee-product-feed |
Profiler – What Slowing Down Your WP | profiler-what-slowing-down |
Quick Event Calendar | quick-event-calendar |
Raychat | raychat |
Read More Login | read-more-login |
Recent Posts Slider Responsive | recent-posts-slider-responsive |
Recover abandoned cart for WooCommerce | recover-wc-abandoned-cart |
Responsify WP | responsify-wp |
Responsive Flipbooks | responsive-flipbooks |
Revolution Video Player With Bottom Playlist WordPress Plugin – YouTube/Vimeo/Self-Hosted Support | revolution_video_player |
RTMKit Addons for Elementor | rometheme-for-elementor |
Runners Log | runners-log |
Search with Typesense | search-with-typesense |
Seofy Core | seofy-core |
SEPA Girocode | sepa-girocode |
Shared Files – Frontend File Upload Form & Secure File Sharing | shared-files |
ShiftNav – Responsive Mobile Menu | shiftnav-responsive-mobile-menu |
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing | shortlinkspro |
SHOUT | lbg-audio8-html5-radio_ads |
Simple Contact Form Plugin for WordPress – WP Easy Contact | wp-easy-contact |
Simple Google Static Map | simple-google-static-map |
Simple History – Track, Log, and Audit WordPress Changes | simple-history |
Simple Keyword to Link | simple-keyword-to-link |
Simple Membership | simple-membership |
Simple Nested Menu | simple-nested-menu |
Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) | sina-extension-for-elementor |
Slack Notifications by dorzki | dorzki-notifications-to-slack |
Social Sharing Plugin – Sassy Social Share | sassy-social-share |
SocialMark – Easy Watermark/Logo on Social Media Post Link Share Preview | socialmark |
Sola Support Tickets | sola-support-tickets |
Spice Blocks | spice-blocks |
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | excel-like-price-change-for-woocommerce-and-wp-e-commerce-light |
StageShow | stageshow |
Sticky Radio Player | lbg-audio5-html5-shoutcast_sticky |
Stock Locations for WooCommerce | stock-locations-for-woocommerce |
Store Locator WordPress | agile-store-locator |
Subscription Renewal Reminders for WooCommerce | subscriptions-renewal-reminders |
Sunshine Photo Cart: Free Client Photo Galleries for Photographers | sunshine-photo-cart |
Taskbuilder – WordPress Project & Task Management plugin | taskbuilder |
Team Builder — Meet The Team WordPress Plugin | a-team-showcase |
Team Showcase | team-showcase-cm |
Testimonials Showcase | testimonials-showcase |
The Events Calendar Countdown Addon | countdown-for-the-events-calendar |
The Holiday Calendar | the-holiday-calendar |
TicketBAI Facturas para WooCommerce | wp-ticketbai |
Trinity Audio – Text to Speech AI audio player to convert content into audio | trinity-audio |
Ultimate Gift Cards for WooCommerce | woo-gift-cards-lite |
Ultimate WP Mail | ultimate-wp-mail |
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | uncanny-automator |
Universal Video Player | universal_video_player |
Universal Video Player – WordPress Plugin | elementor_widget_universal_video_player |
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | profile-builder |
Vayu Blocks – Website Builder for the Block Editor | vayu-blocks |
Verge3D Publishing and E-Commerce | verge3d |
Video Embeds | video-embeds |
Viral Loops WP Integration | viral-loops-wp-integration |
WC MyParcel Belgium | wc-myparcel-belgium |
WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | wc-vendors |
WebHotelier for WordPress | webhotelier |
Welcart e-Commerce | usc-e-shop |
Wishlist | wishlist |
WooCommerce Photo Reviews Premium | woocommerce-photo-reviews |
WooCommerce Product Filter | woofilter-pro |
WooCommerce Ultimate Gift Card | woocommerce-ultimate-gift-card |
WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) | smart-wishlist-for-more-convert |
Wordapp | wordapp |
WordLift – AI powered SEO – Schema | wordlift |
WordPress Ajax Load More and Infinite Scroll | cpt-ajax-load-more |
WordPress Comments Import & Export | comments-import-export-woocommerce |
WordPress Contact Forms by Cimatti | contact-forms |
WordPress CRM Plugin – WP-CRM System | wp-crm-system |
WP AutoKeyword | wp-autokeyword |
WP Biographia | wp-biographia |
WP Compress for MainWP | wp-compress-mainwp |
WP Email Debug | wp-email-debug |
WP Featured Content Slider | wp-featured-content-slider |
WP Gravity Forms Constant Contact Plugin | gf-constant-contact |
WP Gravity Forms Salesforce | gf-salesforce-crmperks |
WP Lead Capturing Pages – WordPress Plugin | leadcapture |
WP Live Chat + Chatbots Plugin for WordPress – Chaport | chaport |
WP Mail Options | wp-mail-options |
WP Maintenance Mode & Site Under Construction | wp-maintenance-mode-site-under-construction |
WP Media File Type Manager | wp-media-file-type-manager |
WP Multilang – Translation and Multilingual Plugin | wp-multilang |
WP Online Users Stats | wp-online-users-stats |
WP Page Loading | wp-page-loading |
WP Plugin Info Card | wp-plugin-info-card |
WP Post Corrector | wp-post-corrector |
WP Security Master | wp-security-master |
WP Shopify | wp-shopify |
WP Shortcodes Plugin — Shortcodes Ultimate | shortcodes-ultimate |
WP Social Widget | wp-social-widget |
WP Table Builder – WordPress Table Plugin | wp-table-builder |
WP Team – WordPress Team Member Plugin | ht-team-member |
WP Text Expander | wp-text-expander |
WP Time Slots Booking Form | wp-time-slots-booking-form |
WP Tools Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log | wptools |
WP Travel Engine – Tour Booking Plugin – Tour Operator Software | wp-travel-engine |
WP User Frontend Pro | wp-user-frontend-pro |
WP-Addpub | wp-addpub |
WP-Recall – Registration, Profile, Commerce & More | wp-recall |
WPCHURCH – Church Management System for WordPress | church-management |
wpForo + wpForo Advanced Attachments | wpforo-advanced-attachments |
WPtouch – Make your WordPress Website Mobile-Friendly | wptouch |
YouTube Simple Gallery | youtube-simple-gallery |
ZoomSounds – WordPress Wave Audio Player with Playlist | dzs-zoomsounds |
«Подсказки» от DaData.ru | dadata-ru |
افزونه پیامک ووکامرس Persian WooCommerce SMS | persian-woocommerce-sms |
診断ジェネレータ作成プラグイン | os-diagnosis-generator |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Arlo | Portfolio WordPress Theme | arlo |
Art Theme | art-theme |
Car Repair Services & Auto Mechanic WordPress Theme + RTL | car-repair-services |
FLAP – Business WordPress Theme | flap |
FlatNews – Responsive Magazine WordPress Theme | flatnews |
Golo – City Travel Guide WordPress Theme | golo |
Krowd – Crowdfunding & Charity WordPress Theme | krowd |
PIMP – Creative MultiPurpose Theme | pimp |
PressGrid – Frontend Publish Reaction & Multimedia Theme | press-grid |
Revo – Multipurpose Elementor WooCommerce WordPress Theme (25+ Homepages & 5+ Mobile Layouts) | revo |
Soho Hotel Booking Calendar For WordPress | soho-hotel |
Spare – Ultimate MultiPurpose LESS Theme | spare |
Sweet Dessert | Candy Shop & Cafe WordPress Theme | sweet-dessert |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 2, 2025 to June 8, 2025) appeared first on Wordfence.